Public record
Software health reportschema 0.27.0 · metrics 1.13.0 · 2026-07-25 23:11 UTC

clay-good / OpenLore

Deterministic, local-first memory and guardrails for AI coding agents with no LLM in the hot path.

TypeScriptMIT★ 207 stars⑂ 31 forkssince Jan 2026View on GitHub ↗

clay-good/OpenLore holds a health index of 78 out of 100, placing it in the Good band. It scores highest on Vitality (88/100) and lowest on Community & Adoption (68/100). It was last updated today. 2 contributors account for most of its recent work.

78
overall / 100
Good

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

78
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

Clay GoodPersonal account
19 followers39 public repossince Oct 2025

This repository is owned by a personal account. A single-owner project carries more continuity risk than an organization-backed one.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publishTags
npmopenlore2.1.63,645276 days agoarchitectural-memorystructural-analysiscode-analysiscall-graphstatic-analysisai-coding-agentsmcpclipi-package

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

88Excellent · 22% of overall
How it's scored
36/36Push recency — last push 0 days ago
15.9/36Commit cadence — 23/52 weeks with commits
18/18Commit volume — 1,437 commits in the last year
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 4 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year1,437
human_commit_share0.88
days_since_last_push0
active_weeks_last_year23

Release discipline

100Excellent
How it's scored
27/27Ships releases — 43 releases published
36/36Release recency — latest release 6 days ago
27/27Release cadence — a release every ~4.2 days
0/10OpenSSF Scorecard: Signed-Releases — no data
Inputs used
releases_count43
latest_release_tagv2.1.6
releases_from_tagsno
days_since_latest_release6
mean_days_between_releases4.2
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

68Moderate · 18% of overall
How it's scored
37.5/60Stars — 207 stars
12.3/25Forks — 31 forks
1.7/15Watchers — 3 watchers
Inputs used
forks31
stars207
watchers3
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

Community health

92Excellent
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (MIT)
18/18CONTRIBUTING guide
13.5/13.5Code of conduct
0/7.2Issue template
6.3/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingyes
has_issue_templateno
has_code_of_conductyes
has_pull_request_templateyes
How it's scored
47.5/80Monthly downloads — 3,645 downloads/month across npm
0/20Registry dependents — not reported by this ecosystem
Inputs used
packagesopenlore
dependents
ecosystemsnpm
total_downloads
monthly_downloads3,645
Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

69Moderate · 24% of overall
How it's scored
25.2/54Bus factor — 2 contributor(s) cover half of all commits
11.2/22.5Commit distribution — top contributor authored 50% of commits
13.5/13.5Contributor breadth — 10 contributors
10/10OpenSSF Scorecard: Contributors — project has 9 contributing companies or organizations
Inputs used
bus_factor2
contributors_sampled10
top_contributor_share0.5
How it's scored
46.8/46.8Issue resolution — 100% of issues closed
36.7/38.3PR acceptance — 254/265 decided PRs merged
0/15OpenSSF Scorecard: Code-Review — Found 1/18 approved changesets -- score normalized to 0
Inputs used
merged_prs254
open_issues0
closed_issues17
issue_closed_ratio1
closed_unmerged_prs11
How it's scored
10/30Ownership backing — personal (user) account
0/20Verified domain — not applicable to user accounts
9.4/25Owner reach — 19 followers of clay-good
13.2/25Track record — 39 public repos, account ~0 yr old
Inputs used
followers19
owner_typeUser
is_verified
owner_loginclay-good
public_repos39
account_age_days287
Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.
How it's scored
25/25Published & resolvable — 1 package(s) on npm
35/35Publish recency — latest publish 6 days ago
20/20Version history — 27 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packagesopenlore
ecosystemsnpm
any_deprecatedno
min_days_since_publish6

Engineering Quality

Are baseline engineering and documentation practices in place?

88Excellent · 20% of overall
How it's scored
24/24CI workflows — 4 workflow(s)
24/24Tests present
16/16Linter config — eslint.config.js
0/9.6Pre-commit hooks
0/6.4.editorconfig
16/20OpenSSF Scorecard: CI-Tests — 26 out of 29 merged PRs checked by a CI test -- score normalized to 8
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configyes
has_precommit_configno

Documentation

100Excellent
How it's scored
30/30README
25/25Documentation directory
15/15Documentation / homepage site — https://www.npmjs.com/package/openlore
10/10Repository description
10/10Topics — 20 topics
10/10Wiki
Inputs used
topicsdeveloper-tools, software-architecture, static-analysis, adr, agentic-workflows, ai-agents, call-graph, codebase-analysis, knowledge-graph, living-documentation, llm-tools, mcp-server, model-context-protocol, code-navigation, coding-agents, dead-code-detection, infrastructure-as-code, scip, test-impact-analysis, tree-sitter
has_wikiyes
homepagehttps://www.npmjs.com/package/openlore
has_readmeyes
has_docs_diryes
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

77Good · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
2.2/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2/2.5CI-Tests — 26 out of 29 merged PRs checked by a CI test -- score normalized to 8
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 1/18 approved changesets -- score normalized to 0
2.5/2.5Contributors — project has 9 contributing companies or organizations
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
7.5/7.5Maintained — 30 commit(s) and 4 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
3/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 6
4/5SAST — SAST tool detected but not run on all commits
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — no data
7.5/7.5Token-Permissions — GitHub workflow tokens follow principle of least privilege
6.8/7.5Vulnerabilities — 1 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate7.5
Excluded from scoring (no data or not applicable): signed_releases. Remaining weights renormalized.
How it's scored
35/35Direct dependencies free of known advisories — no direct dependency carries a known advisory
9.1/25Indirect dependencies free of known advisories — 2 affected: sharp 0.34.5 (high 7.3), @hono/node-server 1.19.15 (moderate 5.9)
40/40No advisories left outstanding — no advisory has been public longer than 90 days
Inputs used
sourceosv
advisories2
affected_packages2
assessed_packages361
unassessed_packages0
affected_by_severityhigh 1, moderate 1
direct_affected_packages0
Matched the npm:openlore@2.1.6 runtime dependency closure — what installing the published package pulls in — 361 packages. Reachability is not analyzed.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

87Excellent · 0% of overall
How it's scored
45/45Agent instructions — AGENTS.md, CLAUDE.md
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 87 of 88 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share0.989
agent_instruction_filesAGENTS.md, CLAUDE.md
agent_instruction_max_bytes25,853
How it's scored
0/18One-command bootstrap
22/22Automated tests
11/11Lint / format config — eslint.config.js
11/11Static type checking — examples/drift-demo/tsconfig.json, tsconfig.json
10/10Reproducible environment — Dockerfile, Nix, lockfile
10/10Demonstrated agent practice — 86 of the last 100 commits agent-authored or agent-credited
8/8Automated maintenance — 12 of the last 100 commits are automated dependency updates
6/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 6
Inputs used
has_nixyes
has_testsyes
lockfilespackage-lock.json
has_dockerfileyes
typed_languageyes
bootstrap_files
has_devcontainerno
has_linter_configyes
typecheck_configsexamples/drift-demo/tsconfig.json, tsconfig.json
agent_commit_share0.86
toolchain_manifests
dependency_bot_commit_share0.12
How it's scored
45/45Type-checkable code — TypeScript (statically typed)
53.9/55Manageable file sizes — 15/757 source files over 60KB
Inputs used
primary_languageTypeScript
largest_source_bytes228,745
source_files_sampled757
oversized_source_files15
How it's scored
40/40API schema (OpenAPI/GraphQL/proto) — src/core/scip/vendor/scip.proto
20/20MCP server
40/40Runnable examples — examples
Inputs used
example_dirsexamples
has_mcp_signalyes
api_schema_filessrc/core/scip/vendor/scip.proto

Key facts

207GitHub stars
10contributors
1,437commits, last 12 months
0days since last push
43releases
2bus factor
0open issues
npmpackage ecosystems

Data collection warnings

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

More detail

Star and fork history 0 ★ / 31 ⇿
0Stars
31Forks
43Releases

When each star and fork was added, collected from GitHub and bucketed by day. Cumulative growth sits directly above the daily additions it is made of, so the two read against each other: steady organic accretion looks nothing like an abrupt, short-lived burst. Where that difference is measurable, it is reported as growth authenticity.

0510152025303022026-022026-042026-07
Major 1Minor 3Patch 39
OpenSSF Scorecard 7.5 / 10
7.5aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-25 23:11 UTC

10Binary-Artifactsno binaries found in the repo
3Branch-Protectionbranch protection is not maximal on development and all release branches
8CI-Tests26 out of 29 merged PRs checked by a CI test -- score normalized to 8
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 1/18 approved changesets -- score normalized to 0
10Contributorsproject has 9 contributing companies or organizations
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 4 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
6Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 6
8SASTSAST tool detected but not run on all commits
10Security-Policysecurity policy file detected
n/aSigned-Releasesno releases found
10Token-PermissionsGitHub workflow tokens follow principle of least privilege
9Vulnerabilities1 existing vulnerabilities detected
Direct dependencies 17
RegistryPackageVersion constraintManifest
npm@inquirer/prompts^8.5.2package.json
npm@modelcontextprotocol/sdk^1.27.1package.json
npm@modelcontextprotocol/server-memory^2026.1.26package.json
npm@vitejs/plugin-react^6.0.4package.json
npmchalk^5.3.0package.json
npmchokidar^5.0.0package.json
npmcommander^12.1.0package.json
npmglob^13.0.6package.json
npmignore^7.0.6package.json
npmjsonc-parser^3.3.1package.json
npmora^8.1.1package.json
npmreact^19.1.1package.json
npmreact-dom^19.1.1package.json
npmtree-sitter-wasms0.1.13package.json
npmvite^8.0.16package.json
npmweb-tree-sitter0.25.0package.json
npmyaml^2.6.1package.json
All dependencies 626

Full resolved dependency set from the GitHub dependency graph: 19 direct and 607 indirect (transitive) packages. The transitive closure is complete when the repository commits a lockfile.

RegistryPackageVersionRelation
npm@inquirer/prompts8.5.2direct
npm@modelcontextprotocol/sdk1.29.0direct
npm@modelcontextprotocol/server-memory2026.7.4direct
npm@vitejs/plugin-react6.0.4direct
npmchalk5.6.2direct
npmchokidar5.0.0direct
npmcommander12.1.0direct
npmglob13.0.6direct
npmignore5.3.2direct
npmignore7.0.5direct
npmignore7.0.6direct
npmjsonc-parser3.3.1direct
npmora8.2.0direct
npmreact19.2.8direct
npmreact-dom19.2.8direct
npmtree-sitter-wasms0.1.13direct
npmvite8.1.5direct
npmweb-tree-sitter0.25.0direct
npmyaml2.9.0direct
npm@anthropic-ai/sdk0.91.1indirect
npm@aws-crypto/crc325.2.0indirect
npm@aws-crypto/sha256-browser5.2.0indirect
npm@aws-crypto/sha256-js5.2.0indirect
npm@aws-crypto/supports-web-crypto5.2.0indirect
npm@aws-crypto/util5.2.0indirect
npm@aws-sdk/client-bedrock-runtime3.1048.0indirect
npm@aws-sdk/core3.974.11indirect
npm@aws-sdk/core3.977.1indirect
npm@aws-sdk/credential-provider-env3.972.37indirect
npm@aws-sdk/credential-provider-env3.972.61indirect
npm@aws-sdk/credential-provider-http3.972.39indirect
npm@aws-sdk/credential-provider-http3.972.63indirect
npm@aws-sdk/credential-provider-ini3.972.41indirect
npm@aws-sdk/credential-provider-ini3.973.6indirect
npm@aws-sdk/credential-provider-login3.972.41indirect
npm@aws-sdk/credential-provider-login3.972.68indirect
npm@aws-sdk/credential-provider-node3.972.42indirect
npm@aws-sdk/credential-provider-node3.972.72indirect
npm@aws-sdk/credential-provider-process3.972.37indirect
npm@aws-sdk/credential-provider-process3.972.61indirect
npm@aws-sdk/credential-provider-sso3.972.41indirect
npm@aws-sdk/credential-provider-sso3.973.5indirect
npm@aws-sdk/credential-provider-web-identity3.972.41indirect
npm@aws-sdk/credential-provider-web-identity3.972.67indirect
npm@aws-sdk/eventstream-handler-node3.972.16indirect
npm@aws-sdk/eventstream-handler-node3.972.30indirect
npm@aws-sdk/middleware-eventstream3.972.12indirect
npm@aws-sdk/middleware-eventstream3.972.25indirect
npm@aws-sdk/middleware-websocket3.972.19indirect
npm@aws-sdk/middleware-websocket3.972.43indirect
npm@aws-sdk/nested-clients3.997.35indirect
npm@aws-sdk/nested-clients3.997.9indirect
npm@aws-sdk/signature-v4-multi-region3.996.27indirect
npm@aws-sdk/signature-v4-multi-region3.996.42indirect
npm@aws-sdk/token-providers3.1048.0indirect
npm@aws-sdk/token-providers3.1095.0indirect
npm@aws-sdk/types3.973.8indirect
npm@aws-sdk/types3.974.2indirect
npm@aws-sdk/util-locate-window3.965.5indirect
npm@aws-sdk/util-locate-window3.965.8indirect
npm@aws-sdk/xml-builder3.972.24indirect
npm@aws-sdk/xml-builder3.972.37indirect
npm@aws/lambda-invoke-store0.2.4indirect
npm@aws/lambda-invoke-store0.3.0indirect
npm@babel/helper-string-parser7.29.7indirect
npm@babel/helper-validator-identifier7.29.7indirect
npm@babel/parser7.29.7indirect
npm@babel/runtime7.29.2indirect
npm@babel/runtime7.29.7indirect
npm@babel/types7.29.7indirect
npm@bcoe/v8-coverage1.0.2indirect
npm@earendil-works/pi-agent-core0.82.1indirect
npm@earendil-works/pi-ai0.82.1indirect
npm@earendil-works/pi-coding-agent0.82.1indirect
npm@earendil-works/pi-tui0.82.1indirect
npm@emnapi/core1.11.1indirect
npm@emnapi/runtime1.11.1indirect
npm@emnapi/runtime1.11.3indirect
npm@emnapi/wasi-threads1.2.2indirect
npm@esbuild/aix-ppc640.28.1indirect
npm@esbuild/android-arm0.28.1indirect
npm@esbuild/android-arm640.28.1indirect
npm@esbuild/android-x640.28.1indirect
npm@esbuild/darwin-arm640.28.1indirect
npm@esbuild/darwin-x640.28.1indirect
npm@esbuild/freebsd-arm640.28.1indirect
npm@esbuild/freebsd-x640.28.1indirect
npm@esbuild/linux-arm0.28.1indirect
npm@esbuild/linux-arm640.28.1indirect
npm@esbuild/linux-ia320.28.1indirect
npm@esbuild/linux-loong640.28.1indirect
npm@esbuild/linux-mips64el0.28.1indirect
npm@esbuild/linux-ppc640.28.1indirect
npm@esbuild/linux-riscv640.28.1indirect
npm@esbuild/linux-s390x0.28.1indirect
npm@esbuild/linux-x640.28.1indirect
npm@esbuild/netbsd-arm640.28.1indirect
npm@esbuild/netbsd-x640.28.1indirect
npm@esbuild/openbsd-arm640.28.1indirect
npm@esbuild/openbsd-x640.28.1indirect
npm@esbuild/openharmony-arm640.28.1indirect
npm@esbuild/sunos-x640.28.1indirect
npm@esbuild/win32-arm640.28.1indirect
npm@esbuild/win32-ia320.28.1indirect
npm@esbuild/win32-x640.28.1indirect
npm@eslint-community/eslint-utils4.10.1indirect
npm@eslint-community/regexpp4.12.2indirect
npm@eslint/config-array0.23.5indirect
npm@eslint/config-helpers0.7.0indirect
npm@eslint/core1.2.1indirect
npm@eslint/js10.0.1indirect
npm@eslint/object-schema3.0.5indirect
npm@eslint/plugin-kit0.7.2indirect
npm@google/genai1.52.0indirect
npm@hono/node-server2.0.11indirect
npm@huggingface/jinja0.5.9indirect
npm@huggingface/transformers3.8.1indirect
npm@humanfs/core0.19.2indirect
npm@humanfs/node0.16.8indirect
npm@humanfs/types0.15.0indirect
npm@humanwhocodes/module-importer1.0.1indirect
npm@humanwhocodes/retry0.4.3indirect
npm@img/colour1.1.0indirect
npm@img/sharp-darwin-arm640.35.3indirect
npm@img/sharp-darwin-x640.35.3indirect
npm@img/sharp-freebsd-wasm320.35.3indirect
npm@img/sharp-libvips-darwin-arm641.3.2indirect
npm@img/sharp-libvips-darwin-x641.3.2indirect
npm@img/sharp-libvips-linux-arm1.3.2indirect
npm@img/sharp-libvips-linux-arm641.3.2indirect
npm@img/sharp-libvips-linux-ppc641.3.2indirect
npm@img/sharp-libvips-linux-riscv641.3.2indirect
npm@img/sharp-libvips-linux-s390x1.3.2indirect
npm@img/sharp-libvips-linux-x641.3.2indirect
npm@img/sharp-libvips-linuxmusl-arm641.3.2indirect
npm@img/sharp-libvips-linuxmusl-x641.3.2indirect
npm@img/sharp-linux-arm0.35.3indirect
npm@img/sharp-linux-arm640.35.3indirect
npm@img/sharp-linux-ppc640.35.3indirect
npm@img/sharp-linux-riscv640.35.3indirect
npm@img/sharp-linux-s390x0.35.3indirect
npm@img/sharp-linux-x640.35.3indirect
npm@img/sharp-linuxmusl-arm640.35.3indirect
npm@img/sharp-linuxmusl-x640.35.3indirect
npm@img/sharp-wasm320.35.3indirect
npm@img/sharp-webcontainers-wasm320.35.3indirect
npm@img/sharp-win32-arm640.35.3indirect
npm@img/sharp-win32-ia320.35.3indirect
npm@img/sharp-win32-x640.35.3indirect
npm@inquirer/ansi2.0.7indirect
npm@inquirer/checkbox5.2.1indirect
npm@inquirer/confirm6.1.1indirect
npm@inquirer/core11.2.1indirect
npm@inquirer/editor5.2.2indirect
npm@inquirer/expand5.1.1indirect
npm@inquirer/external-editor3.0.3indirect
npm@inquirer/figures2.0.7indirect
npm@inquirer/input5.1.2indirect
npm@inquirer/number4.1.1indirect
npm@inquirer/password5.1.1indirect
npm@inquirer/rawlist5.3.1indirect
npm@inquirer/search4.2.1indirect
npm@inquirer/select5.2.1indirect
npm@inquirer/type4.0.7indirect
npm@isaacs/fs-minipass4.0.1indirect
npm@jridgewell/resolve-uri3.1.2indirect
npm@jridgewell/sourcemap-codec1.5.5indirect
npm@jridgewell/trace-mapping0.3.31indirect
npm@jsonjoy.com/base641.1.2indirect
npm@jsonjoy.com/base6417.67.0indirect
npm@jsonjoy.com/buffers1.2.1indirect
npm@jsonjoy.com/buffers17.67.0indirect
npm@jsonjoy.com/codegen1.0.0indirect
npm@jsonjoy.com/codegen17.67.0indirect
npm@jsonjoy.com/fs-core4.64.0indirect
npm@jsonjoy.com/fs-fsa4.64.0indirect
npm@jsonjoy.com/fs-node4.64.0indirect
npm@jsonjoy.com/fs-node-builtins4.64.0indirect
npm@jsonjoy.com/fs-node-to-fsa4.64.0indirect
npm@jsonjoy.com/fs-node-utils4.64.0indirect
npm@jsonjoy.com/fs-print4.64.0indirect
npm@jsonjoy.com/fs-snapshot4.64.0indirect
npm@jsonjoy.com/json-pack1.21.0indirect
npm@jsonjoy.com/json-pack17.67.0indirect
npm@jsonjoy.com/json-pointer1.0.2indirect
npm@jsonjoy.com/json-pointer17.67.0indirect
npm@jsonjoy.com/util1.9.0indirect
npm@jsonjoy.com/util17.67.0indirect
npm@lancedb/lancedb0.22.4-beta.3indirect
npm@lancedb/lancedb-darwin-arm640.22.4-beta.3indirect
npm@lancedb/lancedb-darwin-x640.22.4-beta.3indirect
npm@lancedb/lancedb-linux-arm64-gnu0.22.4-beta.3indirect
npm@lancedb/lancedb-linux-arm64-musl0.22.4-beta.3indirect
npm@lancedb/lancedb-linux-x64-gnu0.22.4-beta.3indirect
npm@lancedb/lancedb-linux-x64-musl0.22.4-beta.3indirect
npm@lancedb/lancedb-win32-arm64-msvc0.22.4-beta.3indirect
npm@lancedb/lancedb-win32-x64-msvc0.22.4-beta.3indirect
npm@mariozechner/clipboard0.3.9indirect
npm@mariozechner/clipboard-darwin-arm640.3.9indirect
npm@mariozechner/clipboard-darwin-universal0.3.9indirect
npm@mariozechner/clipboard-darwin-x640.3.9indirect
npm@mariozechner/clipboard-linux-arm64-gnu0.3.9indirect
npm@mariozechner/clipboard-linux-arm64-musl0.3.9indirect
npm@mariozechner/clipboard-linux-riscv64-gnu0.3.9indirect
npm@mariozechner/clipboard-linux-x64-gnu0.3.9indirect
npm@mariozechner/clipboard-linux-x64-musl0.3.9indirect
npm@mariozechner/clipboard-win32-arm64-msvc0.3.9indirect
npm@mariozechner/clipboard-win32-x64-msvc0.3.9indirect
npm@mistralai/mistralai2.2.6indirect
npm@napi-rs/wasm-runtime1.1.6indirect
npm@nodable/entities2.1.0indirect
npm@opentelemetry/api1.9.0indirect
npm@opentelemetry/semantic-conventions1.41.1indirect
npm@opentelemetry/semantic-conventions1.43.0indirect
npm@oxc-project/types0.139.0indirect
npm@protobufjs/aspromise1.1.2indirect
npm@protobufjs/base641.1.2indirect
npm@protobufjs/codegen2.0.5indirect
npm@protobufjs/eventemitter1.1.1indirect
npm@protobufjs/fetch1.1.1indirect
npm@protobufjs/float1.0.2indirect
npm@protobufjs/path1.1.2indirect
npm@protobufjs/pool1.1.0indirect
npm@protobufjs/utf81.1.1indirect
npm@protobufjs/utf81.1.2indirect
npm@rolldown/binding-android-arm641.1.5indirect
npm@rolldown/binding-darwin-arm641.1.5indirect
npm@rolldown/binding-darwin-x641.1.5indirect
npm@rolldown/binding-freebsd-x641.1.5indirect
npm@rolldown/binding-linux-arm-gnueabihf1.1.5indirect
npm@rolldown/binding-linux-arm64-gnu1.1.5indirect
npm@rolldown/binding-linux-arm64-musl1.1.5indirect
npm@rolldown/binding-linux-ppc64-gnu1.1.5indirect
npm@rolldown/binding-linux-s390x-gnu1.1.5indirect
npm@rolldown/binding-linux-x64-gnu1.1.5indirect
npm@rolldown/binding-linux-x64-musl1.1.5indirect
npm@rolldown/binding-openharmony-arm641.1.5indirect
npm@rolldown/binding-wasm32-wasi1.1.5indirect
npm@rolldown/binding-win32-arm64-msvc1.1.5indirect
npm@rolldown/binding-win32-x64-msvc1.1.5indirect
npm@rolldown/pluginutils1.0.1indirect
npm@silvia-odwyer/photon-node0.3.4indirect
npm@smithy/core3.24.3indirect
npm@smithy/core3.30.0indirect
npm@smithy/credential-provider-imds4.3.3indirect
npm@smithy/credential-provider-imds4.4.14indirect
npm@smithy/fetch-http-handler5.4.3indirect
npm@smithy/fetch-http-handler5.6.11indirect
npm@smithy/is-array-buffer2.2.0indirect
npm@smithy/node-http-handler4.7.3indirect
npm@smithy/node-http-handler4.9.11indirect
npm@smithy/signature-v45.4.3indirect
npm@smithy/signature-v45.6.10indirect
npm@smithy/types4.14.2indirect
npm@smithy/types4.16.1indirect
npm@smithy/util-buffer-from2.2.0indirect
npm@smithy/util-utf82.3.0indirect
npm@standard-schema/spec1.1.0indirect
npm@tybys/wasm-util0.10.3indirect
npm@types/chai5.2.3indirect
npm@types/deep-eql4.0.2indirect
npm@types/esrecurse4.3.1indirect
npm@types/estree1.0.9indirect
npm@types/json-schema7.0.15indirect
npm@types/node22.19.19indirect
npm@types/node25.9.5indirect
npm@types/node26.1.1indirect
npm@types/retry0.12.0indirect
npm@typescript-eslint/eslint-plugin8.65.0indirect
npm@typescript-eslint/parser8.65.0indirect
npm@typescript-eslint/project-service8.65.0indirect
npm@typescript-eslint/scope-manager8.65.0indirect
npm@typescript-eslint/tsconfig-utils8.65.0indirect
npm@typescript-eslint/type-utils8.65.0indirect
npm@typescript-eslint/types8.65.0indirect
npm@typescript-eslint/typescript-estree8.65.0indirect
npm@typescript-eslint/utils8.65.0indirect
npm@typescript-eslint/visitor-keys8.65.0indirect
npm@vitest/coverage-v84.1.10indirect
npm@vitest/expect4.1.10indirect
npm@vitest/mocker4.1.10indirect
npm@vitest/pretty-format4.1.10indirect
npm@vitest/runner4.1.10indirect
npm@vitest/snapshot4.1.10indirect
npm@vitest/spy4.1.10indirect
npm@vitest/utils4.1.10indirect
npmaccepts2.0.0indirect
npmacorn8.17.0indirect
npmacorn-jsx5.3.2indirect
npmagent-base7.1.4indirect
npmajv6.15.0indirect
npmajv8.20.0indirect
npmajv-formats3.0.1indirect
npmansi-regex6.2.2indirect
npmapache-arrow21.2.0indirect
npmassertion-error2.0.1indirect
npmast-v8-to-istanbul1.0.5indirect
npmbalanced-match4.0.4indirect
npmbase64-js1.5.1indirect
npmbcrypt^5.1.0indirect
npmbignumber.js9.3.1indirect
npmbody-parser2.3.0indirect
npmboolean3.2.0indirect
npmbowser2.14.1indirect
npmbrace-expansion5.0.7indirect
npmbrace-expansion5.0.8indirect
npmbuffer-equal-constant-time1.0.1indirect
npmbytes3.1.2indirect
npmcall-bind-apply-helpers1.0.2indirect
npmcall-bound1.0.4indirect
npmchai6.2.2indirect
npmchardet2.2.0indirect
npmchownr3.0.0indirect
npmcli-cursor5.0.0indirect
npmcli-spinners2.9.2indirect
npmcli-width4.1.0indirect
npmcontent-disposition1.1.0indirect
npmcontent-type1.0.5indirect
npmcontent-type2.0.0indirect
npmconvert-source-map2.0.0indirect
npmcookie0.7.2indirect
npmcookie-signature1.2.2indirect
npmcors2.8.6indirect
npmcross-spawn7.0.6indirect
npmdata-uri-to-buffer4.0.1indirect
npmdebug4.4.3indirect
npmdeep-is0.1.4indirect
npmdefine-data-property1.1.4indirect
npmdefine-properties1.2.1indirect
npmdepd2.0.0indirect
npmdetect-libc2.1.2indirect
npmdetect-node2.1.0indirect
npmdiff8.0.4indirect
npmdunder-proto1.0.1indirect
npmecdsa-sig-formatter1.0.11indirect
npmee-first1.1.1indirect
npmemoji-regex10.6.0indirect
npmencodeurl2.0.0indirect
npmes-define-property1.0.1indirect
npmes-errors1.3.0indirect
npmes-module-lexer2.3.1indirect
npmes-object-atoms1.1.2indirect
npmes6-error4.1.1indirect
npmesbuild0.28.1indirect
npmescape-html1.0.3indirect
npmescape-string-regexp4.0.0indirect
npmeslint10.8.0indirect
npmeslint-scope9.1.2indirect
npmeslint-visitor-keys3.4.3indirect
npmeslint-visitor-keys5.0.1indirect
npmespree11.2.0indirect
npmesquery1.7.0indirect
npmesrecurse4.3.0indirect
npmestraverse5.3.0indirect
npmestree-walker3.0.3indirect
npmesutils2.0.3indirect
npmetag1.8.1indirect
npmeventsource3.0.7indirect
npmeventsource-parser3.1.0indirect
npmexpect-type1.4.0indirect
npmexpress5.2.1indirect
npmexpress^4.18.2indirect
npmexpress-rate-limit8.6.0indirect
npmextend3.0.2indirect
npmfast-deep-equal3.1.3indirect
npmfast-json-stable-stringify2.1.0indirect
npmfast-levenshtein2.0.6indirect
npmfast-string-truncated-width3.0.3indirect
npmfast-string-width3.0.2indirect
npmfast-uri3.1.4indirect
npmfast-wrap-ansi0.2.2indirect
npmfast-xml-builder1.2.0indirect
npmfast-xml-parser5.7.3indirect
npmfdir6.5.0indirect
npmfetch-blob3.2.0indirect
npmfile-entry-cache8.0.0indirect
npmfinalhandler2.1.1indirect
npmfind-up5.0.0indirect
npmflat-cache4.0.1indirect
npmflatbuffers25.9.23indirect
npmflatted3.4.3indirect
npmformdata-polyfill4.0.10indirect
npmforwarded0.2.0indirect
npmfresh2.0.0indirect
npmfsevents2.3.3indirect
npmfunction-bind1.1.2indirect
npmgaxios7.1.4indirect
npmgaxios7.3.0indirect
npmgcp-metadata8.1.2indirect
npmget-east-asian-width1.6.0indirect
npmget-intrinsic1.3.0indirect
npmget-proto1.0.1indirect
npmglob-parent6.0.2indirect
npmglob-to-regex.js1.2.0indirect
npmglobal-agent3.0.0indirect
npmglobals17.7.0indirect
npmglobalthis1.0.4indirect
npmgoogle-auth-library10.6.2indirect
npmgoogle-auth-library10.9.1indirect
npmgoogle-logging-utils1.1.3indirect
npmgopd1.2.0indirect
npmgraceful-fs4.2.11indirect
npmguid-typescript1.0.9indirect
npmhas-flag4.0.0indirect
npmhas-property-descriptors1.0.2indirect
npmhas-symbols1.1.0indirect
npmhasown2.0.4indirect
npmhighlight.js10.7.3indirect
npmhono4.12.32indirect
npmhosted-git-info9.0.3indirect
npmhtml-escaper2.0.2indirect
npmhttp-errors2.0.1indirect
npmhttp-proxy-agent7.0.2indirect
npmhttps-proxy-agent7.0.6indirect
npmhyperdyperid1.2.0indirect
npmiconv-lite0.7.3indirect
npmimurmurhash0.1.4indirect
npminherits2.0.4indirect
npmip-address10.3.1indirect
npmipaddr.js1.9.1indirect
npmis-extglob2.1.1indirect
npmis-glob4.0.3indirect
npmis-interactive2.0.0indirect
npmis-promise4.0.0indirect
npmis-unicode-supported1.3.0indirect
npmis-unicode-supported2.1.0indirect
npmisexe2.0.0indirect
npmistanbul-lib-coverage3.2.2indirect
npmistanbul-lib-report3.0.1indirect
npmistanbul-reports3.2.0indirect
npmjiti2.7.0indirect
npmjose6.2.4indirect
npmjs-tokens10.0.0indirect
npmjson-bigint1.0.0indirect
npmjson-buffer3.0.1indirect
npmjson-schema-to-ts3.1.1indirect
npmjson-schema-traverse0.4.1indirect
npmjson-schema-traverse1.0.0indirect
npmjson-schema-typed8.0.2indirect
npmjson-stable-stringify-without-jsonify1.0.1indirect
npmjson-stringify-safe5.0.1indirect
npmjson-with-bigint3.5.10indirect
npmjsonwebtoken^9.0.0indirect
npmjwa2.0.1indirect
npmjws4.0.1indirect
npmkeyv4.5.4indirect
npmlevn0.4.1indirect
npmlightningcss1.33.0indirect
npmlightningcss-android-arm641.33.0indirect
npmlightningcss-darwin-arm641.33.0indirect
npmlightningcss-darwin-x641.33.0indirect
npmlightningcss-freebsd-x641.33.0indirect
npmlightningcss-linux-arm-gnueabihf1.33.0indirect
npmlightningcss-linux-arm64-gnu1.33.0indirect
npmlightningcss-linux-arm64-musl1.33.0indirect
npmlightningcss-linux-x64-gnu1.33.0indirect
npmlightningcss-linux-x64-musl1.33.0indirect
npmlightningcss-win32-arm64-msvc1.33.0indirect
npmlightningcss-win32-x64-msvc1.33.0indirect
npmlocate-path6.0.0indirect
npmlog-symbols6.0.0indirect
npmlong5.3.2indirect
npmlru-cache11.4.0indirect
npmlru-cache11.5.2indirect
npmmagic-string0.30.21indirect
npmmagicast0.5.3indirect
npmmake-dir4.0.0indirect
npmmarked18.0.5indirect
npmmatcher3.0.0indirect
npmmath-intrinsics1.1.0indirect
npmmedia-typer1.1.1indirect
npmmemfs4.64.0indirect
npmmerge-descriptors2.0.0indirect
npmmime-db1.54.0indirect
npmmime-types3.0.2indirect
npmmimic-function5.0.1indirect
npmminimatch10.2.5indirect
npmminipass7.1.3indirect
npmminizlib3.1.0indirect
npmms2.1.3indirect
npmmute-stream3.0.0indirect
npmnanoid3.3.16indirect
npmnatural-compare1.4.0indirect
npmnegotiator1.0.0indirect
npmnode-addon-api7.1.1indirect
npmnode-addon-api8.9.0indirect
npmnode-domexception1.0.0indirect
npmnode-fetch3.3.2indirect
npmnode-gyp-build4.8.4indirect
npmobject-assign4.1.1indirect
npmobject-inspect1.13.4indirect
npmobject-keys1.1.1indirect
npmobug2.1.4indirect
npmon-finished2.4.1indirect
npmonce1.4.0indirect
npmonetime7.0.0indirect
npmonnxruntime-common1.21.0indirect
npmonnxruntime-common1.22.0-dev.20250409-89f8206ba4indirect
npmonnxruntime-node1.21.0indirect
npmonnxruntime-web1.22.0-dev.20250409-89f8206ba4indirect
npmopenai6.26.0indirect
npmoptionator0.9.4indirect
npmp-limit3.1.0indirect
npmp-locate5.0.0indirect
npmp-retry4.6.2indirect
npmparseurl1.3.3indirect
npmpartial-json0.1.7indirect
npmpath-exists4.0.0indirect
npmpath-expression-matcher1.5.0indirect
npmpath-key3.1.1indirect
npmpath-scurry2.0.2indirect
npmpath-to-regexp8.4.2indirect
npmpathe2.0.3indirect
npmpg^8.11.0indirect
npmpicocolors1.1.1indirect
npmpicomatch4.0.5indirect
npmpkce-challenge5.0.1indirect
npmplatform1.3.6indirect
npmpostcss8.5.23indirect
npmprelude-ls1.2.1indirect
npmproper-lockfile4.1.2indirect
npmprotobufjs7.6.5indirect
npmprotobufjs8.7.1indirect
npmproxy-addr2.0.7indirect
npmpunycode2.3.1indirect
npmqs6.15.3indirect
npmrange-parser1.3.0indirect
npmraw-body3.0.2indirect
npmreaddirp5.0.0indirect
npmreflect-metadata0.2.2indirect
npmrequire-from-string2.0.2indirect
npmrestore-cursor5.1.0indirect
npmretry0.12.0indirect
npmretry0.13.1indirect
npmroarr2.15.4indirect
npmrolldown1.1.5indirect
npmrouter2.2.0indirect
npmsafe-buffer5.2.1indirect
npmsafer-buffer2.1.2indirect
npmscheduler0.27.0indirect
npmsemver7.8.0indirect
npmsemver7.8.5indirect
npmsemver-compare1.0.0indirect
npmsend1.2.1indirect
npmserialize-error7.0.1indirect
npmserve-static2.2.1indirect
npmsetprototypeof1.2.0indirect
npmsharp0.35.3indirect
npmshebang-command2.0.0indirect
npmshebang-regex3.0.0indirect
npmside-channel1.1.1indirect
npmside-channel-list1.0.1indirect
npmside-channel-map1.0.1indirect
npmside-channel-weakmap1.0.2indirect
npmsiginfo2.0.0indirect
npmsignal-exit3.0.7indirect
npmsignal-exit4.1.0indirect
npmsource-map-js1.2.1indirect
npmsprintf-js1.1.3indirect
npmstackback0.0.2indirect
npmstatuses2.0.2indirect
npmstd-env4.2.0indirect
npmstdin-discarder0.2.2indirect
npmstring-width7.2.0indirect
npmstrip-ansi7.2.0indirect
npmstrnum2.3.0indirect
npmsupports-color7.2.0indirect
npmtar7.5.22indirect
npmthingies2.6.0indirect
npmtinybench2.9.0indirect
npmtinyexec1.2.4indirect
npmtinyglobby0.2.17indirect
npmtinyrainbow3.1.0indirect
npmtoidentifier1.0.1indirect
npmtree-dump1.1.0indirect
npmtree-sitter0.22.4indirect
npmtree-sitter-bash0.23.3indirect
npmtree-sitter-c0.23.6indirect
npmtree-sitter-c-sharp0.21.3indirect
npmtree-sitter-cpp0.23.4indirect
npmtree-sitter-elixir0.3.5indirect
npmtree-sitter-go0.23.4indirect
npmtree-sitter-java0.23.5indirect
npmtree-sitter-javascript0.23.1indirect
npmtree-sitter-kotlin0.3.8indirect
npmtree-sitter-php0.23.12indirect
npmtree-sitter-python0.23.6indirect
npmtree-sitter-ruby0.23.1indirect
npmtree-sitter-rust0.24.0indirect
npmtree-sitter-scala0.24.0indirect
npmtree-sitter-swift0.7.1indirect
npmtree-sitter-typescript0.23.2indirect
npmts-algebra2.0.0indirect
npmts-api-utils2.5.0indirect
npmtslib2.8.1indirect
npmtsx4.23.1indirect
npmtype-check0.4.0indirect
npmtype-fest0.13.1indirect
npmtype-is2.1.0indirect
npmtypebox1.1.38indirect
npmtypebox1.3.8indirect
npmtypescript5.9.3indirect
npmtypescript^5.3.0indirect
npmtypescript-eslint8.65.0indirect
npmundici8.5.0indirect
npmundici-types6.21.0indirect
npmundici-types7.24.6indirect
npmundici-types8.3.0indirect
npmunpipe1.0.0indirect
npmuri-js4.4.1indirect
npmvary1.1.2indirect
npmvitest4.1.10indirect
npmvitest^4.1.8indirect
npmweb-streams-polyfill3.3.3indirect
npmwhich2.0.2indirect
npmwhy-is-node-running2.3.0indirect
npmword-wrap1.2.5indirect
npmwrappy1.0.2indirect
npmws8.21.0indirect
npmws8.21.1indirect
npmxml-naming0.1.0indirect
npmyallist5.0.0indirect
npmyocto-queue0.1.0indirect
npmzod3.25.76indirect
npmzod4.4.3indirect
npmzod-to-json-schema3.25.2indirect
Dependency advisories 2

Installing npm:openlore@2.1.6 pulls in 361 packages, direct and transitive: 2 carry known advisories, of which 0 are direct dependencies.

PackageVersionRelationSeverityAdvisoriesFixed in
sharp0.34.5indirecthigh10.35.0
@hono/node-server1.19.15indirectmoderate12.0.5

An advisory means the version recorded in the dependency graph falls inside an advisory’s affected range. Reachability is not analysed, and the graph includes development and test pins — a finding may concern tooling rather than shipped software.

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [
        "developer-tools",
        "software-architecture",
        "static-analysis",
        "adr",
        "agentic-workflows",
        "ai-agents",
        "call-graph",
        "codebase-analysis",
        "knowledge-graph",
        "living-documentation",
        "llm-tools",
        "mcp-server",
        "model-context-protocol",
        "code-navigation",
        "coding-agents",
        "dead-code-detection",
        "infrastructure-as-code",
        "scip",
        "test-impact-analysis",
        "tree-sitter"
      ],
      "is_fork": false,
      "size_kb": 15770,
      "has_wiki": true,
      "homepage": "https://www.npmjs.com/package/openlore",
      "languages": {
        "C": 188,
        "C#": 288,
        "Go": 719,
        "HCL": 847,
        "Lua": 265,
        "Nix": 3352,
        "PHP": 260,
        "Dart": 120,
        "HTML": 430,
        "Ruby": 1477,
        "Bicep": 2380,
        "Scala": 184,
        "Shell": 3309,
        "Elixir": 168,
        "Kotlin": 216,
        "Python": 418,
        "Dockerfile": 289,
        "JavaScript": 212682,
        "PowerShell": 1274,
        "TypeScript": 8677696,
        "Go Template": 171
      },
      "pushed_at": "2026-07-25T22:59:10Z",
      "created_at": "2026-01-31T16:15:38Z",
      "owner_type": "User",
      "updated_at": "2026-07-25T22:25:18Z",
      "description": "Deterministic, local-first memory and guardrails for AI coding agents with no LLM in the hot path.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": "claygood.com",
      "name": "Clay Good",
      "type": "User",
      "login": "clay-good",
      "company": null,
      "location": null,
      "followers": 19,
      "avatar_url": "https://avatars.githubusercontent.com/u/237345393?v=4",
      "created_at": "2025-10-10T23:46:58Z",
      "is_verified": null,
      "public_repos": 39,
      "account_age_days": 287
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v2.1.6",
          "kind": "patch",
          "published_at": "2026-07-19T23:07:09Z"
        },
        {
          "tag": "v2.1.5",
          "kind": "patch",
          "published_at": "2026-06-28T23:16:18Z"
        },
        {
          "tag": "v2.1.4",
          "kind": "patch",
          "published_at": "2026-06-27T15:57:15Z"
        },
        {
          "tag": "v2.1.3",
          "kind": "patch",
          "published_at": "2026-06-22T03:14:37Z"
        },
        {
          "tag": "v2.1.2",
          "kind": "patch",
          "published_at": "2026-06-20T20:24:48Z"
        },
        {
          "tag": "v2.1.1",
          "kind": "patch",
          "published_at": "2026-06-19T23:48:53Z"
        },
        {
          "tag": "v2.1.0",
          "kind": "minor",
          "published_at": "2026-06-18T17:38:57Z"
        },
        {
          "tag": "v2.0.19",
          "kind": "patch",
          "published_at": "2026-06-16T20:36:42Z"
        },
        {
          "tag": "v2.0.18",
          "kind": "patch",
          "published_at": "2026-06-14T01:14:57Z"
        },
        {
          "tag": "v2.0.17",
          "kind": "patch",
          "published_at": "2026-06-12T02:44:45Z"
        },
        {
          "tag": "v2.0.16",
          "kind": "patch",
          "published_at": "2026-06-10T11:34:33Z"
        },
        {
          "tag": "v2.0.15",
          "kind": "patch",
          "published_at": "2026-06-10T01:03:41Z"
        },
        {
          "tag": "v2.0.14",
          "kind": "patch",
          "published_at": "2026-06-09T01:36:30Z"
        },
        {
          "tag": "v2.0.13",
          "kind": "patch",
          "published_at": "2026-06-07T20:18:35Z"
        },
        {
          "tag": "v2.0.12",
          "kind": "patch",
          "published_at": "2026-06-07T19:06:36Z"
        },
        {
          "tag": "v2.0.11",
          "kind": "patch",
          "published_at": "2026-06-06T23:55:10Z"
        },
        {
          "tag": "v2.0.10",
          "kind": "patch",
          "published_at": "2026-06-05T02:00:57Z"
        },
        {
          "tag": "v2.0.9",
          "kind": "patch",
          "published_at": "2026-06-03T20:06:24Z"
        },
        {
          "tag": "v2.0.8",
          "kind": "patch",
          "published_at": "2026-06-02T22:27:25Z"
        },
        {
          "tag": "v2.0.7",
          "kind": "patch",
          "published_at": "2026-06-01T22:01:40Z"
        },
        {
          "tag": "v2.0.6",
          "kind": "patch",
          "published_at": "2026-06-01T18:50:41Z"
        },
        {
          "tag": "v2.0.5",
          "kind": "patch",
          "published_at": "2026-05-29T13:28:48Z"
        },
        {
          "tag": "v2.0.4",
          "kind": "patch",
          "published_at": "2026-05-27T21:14:18Z"
        },
        {
          "tag": "v2.0.3",
          "kind": "patch",
          "published_at": "2026-05-27T17:56:14Z"
        },
        {
          "tag": "v2.0.2",
          "kind": "patch",
          "published_at": "2026-05-26T22:21:38Z"
        },
        {
          "tag": "v2.0.1",
          "kind": "patch",
          "published_at": "2026-05-17T22:29:19Z"
        },
        {
          "tag": "v2.0.0",
          "kind": "major",
          "published_at": "2026-05-12T11:45:53Z"
        },
        {
          "tag": "v1.3.6",
          "kind": "patch",
          "published_at": "2026-05-09T16:32:13Z"
        },
        {
          "tag": "v1.3.5",
          "kind": "patch",
          "published_at": "2026-04-28T22:17:04Z"
        },
        {
          "tag": "v1.3.4",
          "kind": "patch",
          "published_at": "2026-04-25T19:32:01Z"
        },
        {
          "tag": "v1.3.3",
          "kind": "patch",
          "published_at": "2026-04-21T00:39:10Z"
        },
        {
          "tag": "v1.3.2",
          "kind": "patch",
          "published_at": "2026-04-17T23:36:38Z"
        },
        {
          "tag": "v1.3.1",
          "kind": "patch",
          "published_at": "2026-04-16T00:52:08Z"
        },
        {
          "tag": "v1.3.0",
          "kind": "minor",
          "published_at": "2026-04-14T23:00:01Z"
        },
        {
          "tag": "v1.2.8",
          "kind": "patch",
          "published_at": "2026-04-07T01:30:03Z"
        },
        {
          "tag": "v1.2.7",
          "kind": "patch",
          "published_at": "2026-04-03T21:51:35Z"
        },
        {
          "tag": "v1.2.6",
          "kind": "patch",
          "published_at": "2026-03-31T01:42:58Z"
        },
        {
          "tag": "v1.2.5",
          "kind": "patch",
          "published_at": "2026-03-26T21:02:41Z"
        },
        {
          "tag": "v1.2.4",
          "kind": "patch",
          "published_at": "2026-03-25T18:05:24Z"
        },
        {
          "tag": "v1.2.3",
          "kind": "patch",
          "published_at": "2026-03-16T23:41:08Z"
        },
        {
          "tag": "v1.2.2",
          "kind": "patch",
          "published_at": "2026-03-14T20:41:43Z"
        },
        {
          "tag": "v1.2.1",
          "kind": "patch",
          "published_at": "2026-03-14T19:38:35Z"
        },
        {
          "tag": "v1.2.0",
          "kind": "minor",
          "published_at": "2026-03-14T19:14:08Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "3f81d3211de524ac5c100bc99eb2cb14beb1d0f3",
          "body": "… (#287)\n\nThe embedded chart renders server-side by star-history.com for anonymous\nvisitors, so it never used a reader's token — and their shared token pool is\ncurrently exhausted. The URL returns 503 \"All GitHub API tokens are\nrate-limited\" for every repo, facebook/react included, not just this one\n[…]\nink to the live chart, which still works interactively for\nanyone signed in there. Same information, nothing that can render broken.\n\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(readme): replace the broken star-history embed with a live badge…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-25T22:25:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7ca52dddc1a719c4a8ab5eb9b755a1110063de53",
          "body": "…positories (#286)\n\n* fix(security): neutralize terminal control sequences from analyzed repositories\n\nA repository being analyzed could inject raw terminal control sequences into\nOpenLore's own output through any path or symbol name it echoes back. A file\nname may legally contain ESC on Linux and m\n[…]\nch is how the first version of\nthis survey fooled me.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(security): neutralize terminal control sequences from analyzed re…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-25T22:10:50Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5dfbe5b5b5b9648b4d800ec1a6e3e6194b4df5dd",
          "body": "…aims in real output (#285)\n\nReplaces the hero GIF with an unedited recording of the PUBLISHED openlore v2.1.6\non a fresh clone of BurntSushi/ripgrep, and replaces the one fabricated payload in\nthe README with real `orient --json` output from this repo.\n\n- New hero GIF (613 KB, down from 757 KB) wit\n[…]\n-party render that is currently rate-limited\n  upstream, so the section now degrades gracefully with live-chart and stargazer links.\n\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(readme): re-record the hero demo on ripgrep and re-ground the cl…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-25T21:22:43Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d05125e479f16062e07f6a5b51f85dfaab9f5613",
          "body": "…he analysis scope (#284)\n\n* fix(security): fix four CodeQL findings and scope the analysis to shipped code\n\nThe first CodeQL baseline was 458 alerts. Triaged all of them; this change\nfixes what was real and stops the noise recurring.\n\nWHY 80% OF IT WAS NOISE\n368 of 458 alerts were IN test files, an\n[…]\ncher-parity flake, which reproduces on pristine main.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(security): fix CodeQL findings, scope TLS per-request, and tune t…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-25T21:05:58Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5f8bb5ca1f09e6131d64daef316b0e87474feace",
          "body": "#282 deferred `preserve-caught-error` and `no-useless-assignment` so the\nfixes could be reviewed on their own. This is that change: both rules are\non and all 48 sites are fixed.\n\npreserve-caught-error (12 sites / 7 files)\n  Every one was `throw new Error(<message>)` inside a catch, discarding the\n  \n[…]\n pristine main and\npasses 3/3 in isolation, so it is pre-existing and unrelated — reported\nseparately rather than papered over here.\n\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor: adopt eslint 10's two new recommended rules (#283)",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-25T19:28:50Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8a7a114925d7d7ee7848657381307f215e25e42f",
          "body": "Rebuilt on current main. This also removes a mismatch: eslint itself went\nto 10.8.0 in #275 while @eslint/js stayed on 9, and the two ship in\nlockstep.\n\n@eslint/js 10 promotes two rules into `recommended`, which surfaced 48\npre-existing violations:\n\n  preserve-caught-error   12 sites /  7 files\n  no\n[…]\nrules off, `eslint src`\nreports zero problems, so the bump introduces no other findings.\n\nCo-authored-by: Clay Good <hi@claygood.com>\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump @eslint/js from 9.39.5 to 10.0.1 (#282)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-25T18:40:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0789e3711029ed712e6af078b3c8a49bf4e86916",
          "body": "Rebuilt on current main. No code changes needed.\n\nCoverage here is better than for the other majors: `select`, `confirm`,\n`input` and `checkbox` are static named imports in prompts.ts, init.ts,\nsetup.ts and generate.ts, so tsc genuinely validates the export surface\nand signatures. All four also reso\n[…]\ns install, so that is\nleft as a separate call rather than folded into a dependency bump.\n\nCo-authored-by: Clay Good <hi@claygood.com>\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": true,
          "headline": "chore(deps): bump @inquirer/prompts from 7.10.1 to 8.5.2 (#281)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-25T18:31:57Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3f0a8f23895339219cbd43a05d4dd069de64d8c2",
          "body": "Rebuilt on current main. No code changes were needed, but green CI is not\nevidence here and was verified by hand instead.\n\nWhy CI cannot see this: the plugin is dynamically imported only by\n`openlore view`, `npm run build` is tsc (never a vite build), and\nview.test.ts mocks '@vitejs/plugin-react'. S\n[…]\nthe served HTML\n  contains react-refresh — the plugin is transforming, not just loading.\n\nCo-authored-by: Clay Good <hi@claygood.com>\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": true,
          "headline": "chore(deps): bump @vitejs/plugin-react from 5.0.2 to 6.0.4 (#280)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-25T18:25:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3001481b4910a3fcd1e35ae2d237f6416327ae02",
          "body": "Rebuilt on current main and paired with the type fix v7 requires.\n\n`ignore` v7 dropped `.default` from its published types, which broke\nfile-walker.ts's `ignoreModule.default ?? ignoreModule` interop unwrap at\ncompile time only — at runtime v7 still exposes both shapes (CJS\n`module.exports = ignore`\n[…]\n still honours .gitignore on this repo — 971 files\nwalked, zero node_modules/dist leaks.\n\nCo-authored-by: Clay Good <hi@claygood.com>\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": true,
          "headline": "chore(deps): bump ignore from 6.0.2 to 7.0.6 (#279)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-25T18:17:54Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "30b734569741fd16646b0b3b9299c9cf1621bb58",
          "body": "Rebuilt on current main (the Dependabot branch predates #275-#277) and\npaired with the one type fix the bump requires.\n\n@types/node 26 adds `bytes()` to `Response`, tracking the undici/WHATWG\nsurface. One hand-built mock Response in chat-agent.test.ts is typed as a\nfull `Response`, so it now needs t\n[…]\nnge what ships — types are dev-only and the package\npublishes no .d.ts referencing them.\n\nCo-authored-by: Clay Good <hi@claygood.com>\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump @types/node from 22.20.1 to 26.1.1 (#278)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-25T18:11:42Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2000bd9b643b9756db6e82879c0ad55da1eb189a",
          "body": "Bumps the composite-action group in /.github/actions/openlore-review with 2 updates: [actions/setup-node](https://github.com/actions/setup-node) and [actions/github-script](https://github.com/actions/github-script).\n\n\nUpdates `actions/setup-node` from 4.4.0 to 7.0.0\n- [Release notes](https://github.\n[…]\non-update:semver-major\n  dependency-group: composite-action\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump the composite-action group (#277)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-25T18:04:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "56cd737cf1d39d276bc4f9d7ee076dd3b09f85cb",
          "body": "* chore(deps): close two gaps in the Dependabot config\n\nBoth surfaced from the first week of real Dependabot output.\n\n1. The ignore list named `web-tree-sitter` and `tree-sitter-wasms` but not\n   the native `tree-sitter` or the 18 `tree-sitter-*` grammars, so those\n   landed in the production-minor-\n[…]\nts own line because the wildcard requires the hyphen.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(deps): close two gaps in the Dependabot config (#276)",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-25T17:56:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6aec298e583f31fb607ff8dc026260225a5bad7f",
          "body": "Rebuilt on current main (the original Dependabot branch conflicted after\n#270/#271/#274 landed) and paired with the audit-gate bookkeeping the\nupgrade forces.\n\neslint 10 raises its minimatch floor, which removes the eslint ->\nminimatch@3 -> brace-expansion@1.x path that GHSA-mh99 was allowlisted\nfor\n[…]\nint one that\nno longer does.\n\neslint 10 lints the codebase clean with no config changes.\n\nCo-authored-by: Clay Good <hi@claygood.com>\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump eslint from 9.17.0 to 10.8.0 (#275)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-25T17:42:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0efcdaa0d5dcdcd604df928f4f623f1b0bdc2da3",
          "body": "Bumps [globals](https://github.com/sindresorhus/globals) from 16.5.0 to 17.7.0.\n- [Release notes](https://github.com/sindresorhus/globals/releases)\n- [Commits](https://github.com/sindresorhus/globals/compare/v16.5.0...v17.7.0)\n\n---\nupdated-dependencies:\n- dependency-name: globals\n  dependency-versio\n[…]\nrect:development\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump globals from 16.5.0 to 17.7.0 (#274)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-25T17:27:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "70f03c827a06d9680a91e14ca8889a9edf252759",
          "body": "Bumps the dev-dependencies group with 9 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [@earendil-works/pi-ai](https://github.com/earendil-works/pi/tree/HEAD/packages/ai) | `0.79.6` | `0.82.1` |\n| [@earendil-works/pi-coding-agent](https://github.com/earendil-works/pi/tree/HEAD/packages/codi\n[…]\non-update:semver-patch\n  dependency-group: dev-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump the dev-dependencies group with 9 updates (#271)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-25T17:27:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6a8f4f572e15edd518c17680f77fc8c23caa452d",
          "body": "Bumps the github-actions group with 2 updates: [actions/checkout](https://github.com/actions/checkout) and [actions/setup-node](https://github.com/actions/setup-node).\n\n\nUpdates `actions/checkout` from 6.1.0 to 7.0.1\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https\n[…]\nsion-update:semver-major\n  dependency-group: github-actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump the github-actions group with 2 updates (#270)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-25T17:26:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0618bd176b9fab405dfd0809f8d7874957ce54d2",
          "body": "* fix(openspec): repair the corpus defect that silently broke every archive\n\n`openspec archive` has been aborting for EVERY change, in a way nothing\nreported: openspec parses a main spec's requirements only from inside\n`## Requirements`, and 175 `### Requirement:` headers had accumulated outside\nit \n[…]\nfully applied to the spec,\nso archiving was purely moving the folder — verified requirement by requirement\nbefore moving.\n\n---------\n\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(spec): clean up the change backlog (#269)",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-25T17:26:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "12c3c2ea2d1c7a4ab27d191c05cfbcfce62b34a0",
          "body": "…lly (#268)\n\n* perf(analyzer): run Pass-1 extraction on a worker pool, byte-identically\n\nPass 1 — per-file tree-sitter parsing and fact extraction — was a strictly\nserial loop on one core, and it is 14.3s of this repo's 20.2s call-graph\nbuild. It is also embarrassingly parallel: no file's extraction\n[…]\nker in its\nassumptions rather than differently timed.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "perf(analyzer): run Pass-1 extraction on a worker pool, byte-identica…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-25T17:26:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9611bd1c6bfe38a5c4d960d3c234f9e0ea6bc7d6",
          "body": "…ity checks (#267)\n\n* fix(deps): pin the remaining vulnerable transitive deps\n\nDependabot's #263/#266 cleared tar, postcss, fast-uri, body-parser and\nthe modern brace-expansion line. Four gaps were left because each needs\nan override the automated PRs could not make:\n\n- sharp -> ^0.35.0: @huggingfac\n[…]\nnds with a completed run rather than a cancelled one.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(security): update vulnerable dependencies and add automated secur…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-25T17:05:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6572a75b04dde207d4d8f2d352a729b2204cfa2c",
          "body": "…dates (#266)\n\nBumps the npm_and_yarn group with 7 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.13` | `1.1.16` |\n| [body-parser](https://github.com/expressjs/body-parser) | `2.2.2` | `2.3.0` |\n| [\n[…]\n dependency-type: indirect\n  dependency-group: npm_and_yarn\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump the npm_and_yarn group across 1 directory with 7 up…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-25T15:18:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e47ad582b173b01ae546943a4c69bd1fed7025bf",
          "body": null,
          "is_bot": false,
          "headline": "fix: normalize Windows backslash paths before splitting on '/' (#264)",
          "author_name": "Tu Thanh Nguyen",
          "author_login": "zoroneo",
          "committed_at": "2026-07-25T15:14:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9020cffec465d66f3b94b7d30d238198ba8f7dc0",
          "body": "Bumps the npm_and_yarn group with 1 update in the / directory: [protobufjs](https://github.com/protobufjs/protobuf.js).\n\n\nUpdates `protobufjs` from 8.6.4 to 8.6.6\n- [Release notes](https://github.com/protobufjs/protobuf.js/releases)\n- [Changelog](https://github.com/protobufjs/protobuf.js/blob/master\n[…]\ncy-type: direct:production\n  dependency-group: npm_and_yarn\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump protobufjs (#263)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-25T15:12:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b1b90238b929a7111bea4e2e3a6b475a41a9eacd",
          "body": "Bump to 2.1.6 and cut user-facing release notes for the 45-change\npost-v2.1.5 hardening sweep (all merged, #219–#262): self-healing\nindexes that never self-destruct, deterministic + atomically-written\nartifacts, a daemon that survives async event errors, tighter secret\nredaction and closed local HTT\n[…]\nource GitHub Release notes from the\nmatching CHANGELOG.md section, falling back to auto-generated notes if\nthe section is missing.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): v2.1.6 — the hardening release",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-19T22:58:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2be345af2dc56bb48549378b8c67d0a2b35b15c4",
          "body": "…#262)\n\nFour determinism-doctrine violations (decision c6d1ad07) in artifact/inventory\ngeneration, each fixed with an in-repo precedent — no new tuning constant, no LLM:\n\n- (a) llm-context.json phase-3 sampling used a `Math.random()` Fisher-Yates, so\n  two analyzes of an identical tree embedded diff\n[…]\negation to input order; digest test asserts the edge population\nmatches its label. Adds analyzer + architecture spec requirements.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(analyzer): make analysis artifacts a pure function of the input (…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-19T22:49:52Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d1e1840e620e731a3ded1b768c1e06497e31b759",
          "body": "…fact (#261)\n\nBoth artifact writers — the analyze generator and the live watcher — bare-wrote\nllm-context.json and its siblings, so a crash mid-write left a torn file that\nloads as \"your index is gone, re-run analyze\", and the watcher's self-heal\n`analyze --force` could race the watcher's own persis\n[…]\nze, stale-steal, decisions-lock independence).\nArchitecture spec: ADD ArtifactWritesAreAtomic, ConcurrentArtifactWritersSerialize.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(architecture): atomic writes and one lock for every analysis arti…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-19T22:25:43Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "744ed468679a24a5f2235dbe81b0fde9cde8e5ca",
          "body": "…rn an unredacted cycle (#260)\n\nTwo defects inside secret-redaction.ts — the single module every output channel\nscrubs through — let credentials survive a \"redaction\":\n\n(a) The Authorization pattern `Authorization:\\s*\\S+` consumed only the first token\n    (the scheme), so `Authorization: Basic dXNlc\n[…]\nUnredactedInput, and tests covering Basic/Digest/custom\nschemes, multi-line isolation, and cyclic object/array/cause-cycle graphs.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(mcp-security): redact the full Authorization value and never retu…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-19T22:01:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f82b1b07b3c133fe001b6ebfc72b06459b2e0548",
          "body": "The parity doctrine says the same structural capabilities ship through both\nthe MCP tools and the Pi extension, with any deviation stated. The audit found\nsilent drift: Pi's verify_claim could not express `decision-current`, six\nrecently-shipped conclusion tools never reached NAV_TOOLS, and the only\n[…]\no binary mode); replaced with the '\\x00' escape\n  (byte-identical at runtime).\n- Spec: mcp-quality gains PiSurfaceParityIsGuarded.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(mcp-quality): guard MCP↔Pi surface parity in both directions (#259)",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-19T21:30:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "cb114beb31b1503023eef8aaac866ce252b78cef",
          "body": "…gistry (#258)\n\nA repo registered before its first `openlore analyze` stored an empty\nfingerprint, and the staleness check was gated on a truthy stored hash — so\nthe entry reported `indexed`/consultable FOREVER while its index drifted\narbitrarily, the exact silent-degradation class this audit closes\n[…]\non), and spec_store_status\n(index-unbaselined). Full suite green.\n\nChange: harden-federation-freshness (e2e audit follow-up pass).\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(federation): baseline the empty fingerprint, degrade a corrupt re…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-19T20:53:18Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2ed7f27d3079e99f779a9021819803b78765b454",
          "body": "…ved process (#257)\n\nTwo long-lived paths registered Node event emitters without an 'error'\nlistener. An unhandled 'error' on an EventEmitter throws, and neither the\nserve daemon nor the stdio MCP server installs an uncaughtException handler,\nso the throw is fatal.\n\n- mcp-watcher: the .git ref watch\n[…]\nsAndRotation; mcp-handlers ADD\n  WatcherErrorEventsNeverKillTheHost.\n- lint + typecheck clean; full suite 6084 passed / 2 skipped.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(runtime): an async watcher/stream 'error' must not kill a long-li…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-19T20:30:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "452257f67369f84f63ecb548941ab0f6e49157e6",
          "body": "…e the capability, not the version (#256)\n\nengines.node declared >=22.5.0, but node:sqlite (imported at module load by\nEdgeStore, the epistemic lease, and preflight scoring) required\n--experimental-sqlite until Node 22.13.0 / 23.4.0 — and nothing passes that flag.\nA fresh install on 22.5–22.12 crash\n[…]\nends to constants.ts (one floor, three declarations);\nnew tests cover the probe branches and the capability-beats-arithmetic path.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(cli): raise the Node floor to where node:sqlite exists — and prob…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-19T20:11:24Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "21297dc869a8b67faecb8a8b9ffb44cb15f60b72",
          "body": "…ifted line numbers (#255)\n\nTwo fidelity defects in the shared import/export parser\n(`src/core/analyzer/import-parser.ts`):\n\n(a) Modifier-prefixed exports were invisible. `parseJSExports` matched neither\n`export async function` nor a generator `export function* gen`, missed\n`export abstract class`, \n[…]\nsts stay green.\nSpec: analyzer gains ExportParserRecognizesModifierPrefixedExports and\nImportExportLineNumbersMatchOriginalSource.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(analyzer): recognize modifier-prefixed exports and fix comment-sh…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-19T19:51:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "71f425bf3f15f6600edeb7bbc173b6e2df6def91",
          "body": "… no more drifted route-handler edges (#254)\n\n`extractTsRouteDefinitions` parsed the SKELETON of a file (comment/log/blank\nlines removed, text shrunk) and computed every `route.line` against it, but the\nconsumers anchor that line into the ORIGINAL file bytes. Any comment or log\npreamble above a rout\n[…]\nraggler: delegate-lifecycle-scope-decision-sync\nfrontmatter proposed → shipped (merged as #236; prose already reconciled by #248).\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(analyzer): length-preserving comment mask for TS/JS route lines —…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-19T19:24:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "69497f06d9d6395c515cea73caa049974d139d05",
          "body": "…ock, three doors (#253)\n\n`.openlore/serve.json` is a repo-local, attacker-writable artifact that OpenLore\nreads at three sites to discover the warm daemon, then FETCHES the host/port it\nnames and POSTs the project directory + full tool args to it. Only `serve.ts`\nvalidated it (loopback host, intege\n[…]\neader (outbound\n  counterpart of AllLocalHttpSurfacesShareTheGuard).\n- lint + typecheck clean; full suite 6042 passed / 2 skipped.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(mcp-security): validate serve.json at every reader — one shared l…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-19T19:02:27Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d95aae3d54d1f72b531a8fd02ab87b9001325247",
          "body": "…an't resurrect a rejected verdict (#252)\n\nsync_decisions with an explicit id promoted ANY decision to approved —\nincluding one a human explicitly rejected — and wrote it into the specs,\ndefeating the approve/reject governance gate through its own sync tool.\napprove_decision blocked only 'synced', s\n[…]\ns (MCP approve + sync),\napi/decisions.test.ts (API door). Full suite green (6026 passed).\n\nChange: fix-decision-status-transitions\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(mcp-handlers): guard decision status transitions — sync/approve c…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-19T18:39:43Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5f4467ea8be7d00ed97fc8dbc37bdf4ddebc59a5",
          "body": "…e, not the base tip (#251)\n\nstructural_diff's changed-file list is merge-base-scoped (three-dot), but its OLD\nsnapshots were read at the base ref's TIP. On any branch whose base advanced past\nthe branch point, a file changed on both sides yielded an old snapshot polluted\nwith the base branch's own \n[…]\n and parse-crash scenarios; verified to fail\nagainst the pre-fix code. Full suite green (6016 passed), lint/typecheck/build clean.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(mcp-handlers): structural_diff reads old content at the merge-bas…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-19T15:06:20Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f3895a85960a03d3fefc61e35c2f5b73be20b335",
          "body": "…k + ADR id normalization (#250)\n\nTwo live-reproduced honesty holes made the drift gate blind exactly when it\nmatters:\n\n(a) Staged/working-tree changes always fell through to +0/-0. `getChangedFiles`\nmerges staged and working-tree files into the changeset when `includeUnstaged`\nis set, but line stat\n[…]\nlers\" fix must also cover.\n\nSpecs: drift — ADD UncommittedChangesCarryRealLineCounts,\nADRIdentityIsNormalizedAcrossDriftDetection.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(drift): un-blind the drift gate — real counts for uncommitted wor…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-19T14:52:39Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "952ce96768549a1e948697a11dc74feaf4d715ed",
          "body": "… filenames stop silently dropping (#249)\n\n* fix(analyzer): quotepath-off at every git path-list spawn — non-ASCII filenames stop silently dropping\n\nGit's default core.quotepath=true renders any path with bytes above 0x80 as a\ndouble-quoted, octal-escaped C string in --name-only/--name-status/--nums\n[…]\n reference PR #249 in fix-git-path-quoting status\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(analyzer): quotepath-off at every git path-list spawn — non-ASCII…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-19T14:38:11Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "389b7a9d6ab140b2edaa6eac0456b20d863489dd",
          "body": "…248)\n\n14 change proposals were merged to main (PRs #221–#242) but still carried a\nstale `PROPOSED` status line — the proposal corpus read as if the work were\nunbuilt. Ground truth was established from git history (a real src-touching\nimplementation commit beyond the bulk audit commit), cross-checke\n[…]\n an unrelated PR\n(harden-openspec-writer-fidelity, unify-onboarding-entrypoint) were verified\ngenuinely unbuilt and left PROPOSED.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(openspec): reconcile shipped change statuses with git reality (#…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-19T14:18:17Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "58f1d0aff34d771e99dc24ede94453b87000feae",
          "body": "… verdicts from truncated literals (#247)\n\nThe duplicate detector's comment stripping ran string-blind: a `//` inside a\nURL or a `#` inside a hex color truncated the literal, so two functions\ndiffering ONLY in that constant normalized identical and were reported as\nclones at similarity 1.0 — exactly\n[…]\nth empirical repros and the language-selection/interpolation cases are pinned\nby tests. No clone snapshots existed to re-baseline.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(analyzer): string-literal-safe clone normalization — no false 1.0…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-19T14:00:32Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f8da4b7ad10ade6981e0fc18430a389c8df89a13",
          "body": "…the watcher-parity flake (#246)\n\nTwo liabilities that would bite on their own schedule (TestSuiteHasNoKnownTimeBombs):\n\n1. vi.mock hoisting deprecation. vitest hoists every vi.mock to the top of its\n   module and warns \"this will become an error in a future version\" for calls\n   written inside desc\n[…]\neintroduce a timer-based wait.\n\nFull suite green (308 files, 5986 passed), zero vi.mock hoisting warnings; lint +\ntypecheck clean.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(project): defuse the test-suite time bombs — vi.mock hoisting + …",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-19T13:37:12Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "aaa2d8e4b2b289ec9c2b4787a8fac312ad2f9343",
          "body": "…ation is actually read (#245)\n\nThe global `--config <path>` option was inert: readOpenLoreConfig(rootPath) derived\nits own <root>/.openlore/config.json at ~45 call sites and ignored the flag, so a\nuser who pointed --config at a readable file elsewhere was silently served the\ndefault. (fix-cli-outpu\n[…]\ntConfigPathIsHonored. Full suite green (307 files, 5985\npassed); lint + typecheck clean. Stacked on fix-cli-output-hygiene (#244).\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(config): honor the global --config path — an explicit config loc…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-19T11:02:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "29097996b48b09f079ccc628bbb804fce8b2f065",
          "body": "…est summaries, one vocabulary (#244)\n\nA full-surface CLI dogfood found a batch of small output/UX defects. Fixed together\nunder one requirement (OutputContractsAreUniform), each with a regression test:\n\n1. Color contract: color now flows through a shared chalk-backed layer\n   (src/utils/colors.ts) \n[…]\nnfig.json, no\n   package.json); manifest emit gains --dry-run.\n\nFull suite green (306 files, 5976 passed); lint + typecheck clean.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(cli): uniform output contracts — color layer, fatal --config, hon…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-19T10:59:48Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c5517b722d85a0eddf1f9c74334dda7b1728ec1b",
          "body": "…staleness, unknown inputs (#243)\n\nThe honesty disciplines already existed; the v2.1.5 audit found the commands that\nskipped them. This makes them uniform behind one shared helper plus a parity guard.\n\n- resolveBaseRefDisclosed: one resolve-or-disclose helper for every --base command.\n  Certificatio\n[…]\n drops off the shared helper path.\n\nSpecs: cli ADDs BaseRefResolutionIsDisclosedOrFatal, ConclusionCommandsDiscloseIndexStaleness.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(cli): uniform conclusion honesty — base-ref resolve-or-disclose, …",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-19T03:14:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b374025ae76fbc377842f8f345354e428d1607eb",
          "body": "…type mismatches, and version skew (#242)\n\n`readOpenLoreConfig` parsed the file with a bare `JSON.parse(...) as OpenLoreConfig`\n— a type assertion checked by nothing at runtime. A typo'd key (`pancResponse`,\n`embeding`) was silently dropped, the default silently won, and the user believed a\nfeature \n[…]\nes exactly as before.\n\nChange: add-config-schema-validation. Spec: config +ConfigUnknownKeysAreDisclosed,\n+ConfigVersionIsChecked.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(config): validate .openlore/config.json — disclose typo'd keys, …",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-19T02:35:52Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "71a2005fb12093608317138e2799a2a05957a530",
          "body": "…ed edit location the host can trust (#241)\n\nAdds one read-only conclusion tool (`locate_symbol_span`, family `navigate`) on\n`--preset full`. Given a `name`/`name::path` symbol it returns the byte-exact edit\nspan (startByte/endByte UTF-16 offsets + 1-based startLine/endLine) plus a freshness\nverdict\n[…]\nt budget bumped 88k→90k (documented). substrate/navigation\ndefaults byte-identical (new tool is opt-in, ADR-0023 benchmark-gated).\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(mcp-handlers): locate_symbol_span — a read-only, staleness-check…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-19T02:11:52Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "30bd6d8cf20120158bc0401cae9ed9cf50e3a542",
          "body": "…stroy the index, corruption is quarantined (#240)\n\nA schema-version bump made EdgeStore.open() DROP TABLE across the whole graph on the\nnext open — so a READ command after an upgrade (orient, search, any MCP query) silently\ndestroyed the index, and the user paid a full re-analyze for having asked a\n[…]\nuarantineCorruptSync in atomic-store.ts.\n\narchitecture spec: ADD ReadPathsNeverDestroyTheIndex, CorruptGraphStoreQuarantineParity.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(architecture): harden the graph-store lifecycle — reads never de…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-19T01:48:39Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c06cc5690a676677cc8ed3bf8311893ab7f950c6",
          "body": "…ccuracy gate (#239)\n\nHardens four runtime defects in the opt-in behavioral-governance subsystem without\nchanging its posture (modes stay off by default; blocking stays experimental, opt-in,\nand advisory-flagged; the defer-panic-* decisions are untouched):\n\n(a) L4 blocking no longer traps its own re\n[…]\nactivation gate, rotated-telemetry episode counting.\nFull suite green (5890 passed); typecheck + lint clean; panic e2e (23) green.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(panic): escapable L4 blocking, atomic watcher singleton, honest a…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-19T01:02:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3ca5fd38165e40f4f8f76e678880e626acf6669e",
          "body": "…re (#238)\n\nBrings OpenLore's spec corpus up to date with the product as it exists today, and adds a\nlightweight guard that keeps it accurate.\n\n- Refreshed the system overview to describe OpenLore clearly and concisely.\n- Kept only specs that map to real code, so the corpus reflects what the product\n[…]\nll test suite green (5,858 passing), type check clean, and OpenLore's own audit\nreports 0 orphan requirements and 0 stale domains.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(specs): refresh OpenLore's specs to match its current architectu…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-19T00:30:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "bab6fb8fe6129b1f221fe99d4df97b04093fd234",
          "body": "…the wrong install (#237)\n\n`detectInstallMethod` classified any path containing `/node_modules/openlore/`\nas a global npm install, so `openlore update` run from a project-local\ndependency executed `npm install -g openlore@latest` — mutating global state the\nuser never touched — while Windows global \n[…]\ntory\nor absent evidence yields `unknown` and the existing manual fallback — disclosed\nindeterminacy, never a state-mutating guess.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(cli): detect openlore install method from evidence, never mutate …",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-18T23:33:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e33b73118ddd2c1a4622f4c8becaa21e23e59580",
          "body": "…te change lifecycle to OpenSpec (#236)\n\n* refactor(decisions): scope decision sync to one owning domain; delegate change lifecycle to OpenSpec\n\nOpenLore is a distinct product; OpenSpec (@fission-ai/openspec) is the\nspec-driven-development framework OpenLore is built with, not a thing OpenLore\nrebui\n[…]\nlean; decisions +\ndrift suites green (437 tests).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(decisions): scope decision sync to one owning domain; delega…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-18T23:07:21Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6255e8f5b6ca228a28671e557fb47da20f17458b",
          "body": "…est guard (#235)\n\n* fix(mcp-security): put the view server behind the serve daemon's request guard\n\nThe `view` graph server mounted /api/chat (runs the chat agent, spends the\nuser's LLM key), /api/skeleton (reads arbitrary project files), and /api/search\nwith no Host check, no Origin check, and no \n[…]\nes\" test above it — no promise outlives the test.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(mcp-security): put the view server behind the serve daemon's requ…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-18T21:58:12Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4afd1f17ce32094476d088b8052b49a12c250bfd",
          "body": "…s-only contents (#234)\n\nThe default `substrate` preset carries the navigation core plus governance\n*reads* (recall, verify_claim, blast_radius) — the read face, not the write\nface (remember, record_decision). Every outward \"both faces of the substrate\"\nclaim was an over-claim: the same defect class\n[…]\n must\nfollow the ADR-0023 process — no preset contents change here.\n\nSpec: mcp-quality gains DefaultSurfaceCopyMatchesItsContents.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(mcp-quality): reconcile the substrate preset's copy with its read…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-18T21:16:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8adde93d4df70f98e2be99c9725ad5ded847eb87",
          "body": "…ete the adjacency table (#233)\n\nThe conclusion-over-graph contract's runtime check (assertConclusionShape) had\nzero non-test callers — the invariant that \"the server does the traversal so the\nagent never has to\" was aspirational exactly where it matters. And the\nNoRedundantConclusions adjacency tab\n[…]\ng bumped 13_700 -> 14_200 (find_path is in the navigation\npreset; its cross-reference costs ~180 B) — a conscious budget decision.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(mcp-quality): enforce the conclusion contract at dispatch, compl…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-18T21:03:17Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1e05f514189b9e135505304d529165f8ee22bb52",
          "body": "… it to the registry (#232)\n\nThe lease's per-session cognitive-load accounting silently under-counted 27 of 72\ndispatched tools: every unlisted tool fell to the minimum weight via the `?? 1`\nfallback, including deep graph traversals on the default surface. The starkest case:\nfind_path scored 1 while\n[…]\n tool without a weight now fails CI.\n\nThresholds unchanged; no payload or tool-surface change. Closes fix-epistemic-lease-weights.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(mcp-handlers): complete the epistemic-lease weight table and bind…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-18T20:46:28Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "663fd9c2d224b3a198498e6eb4963b9603026f0a",
          "body": "… honest outcome, CAS-checked sync promotion (#231)\n\nCloses three robustness gaps in the record_decision → background-consolidation\npath (e2e-audit fix-track item):\n\n1. An ENOENT spawn could crash the long-lived MCP server. spawnConsolidateBackground\n   now registers child.on('error'), contains any \n[…]\nomotion with co-resident draft survival, and isDecisionsLockHeld held/stale/\nabsent/non-mutating. Full suite green (5759 passing).\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(mcp-handlers): harden decision consolidation — fail-closed spawn,…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-18T19:14:39Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5dfdf39b7edb3885c977e34ba6c229acbb62e57e",
          "body": "Extend the honesty-contract guard pattern to the remaining quantitative doc\nclaims nothing bound to code: the README language-count badge (and the\ndocs/output.md call-graph note), the \"5500+\" test floor, and package metadata.\n\n- src/doc-claim-sync.test.ts derives the badge counts from CODE_LANGUAGES\n[…]\ncount and preset-size claims were already guarded by mcp-tool-count-doc.test.ts\n(PR #229) — descoped here, documented in tasks.md.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(mcp-quality): guard quantitative doc claims against code (#230)",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-18T18:54:43Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1a5fde5b031f5c390f417e4ccfaf65caa8a9afb8",
          "body": "…R-0023 (#229)\n\nThe ADR-0023 flip made `substrate` the out-of-box default (via the single\n`LEAN_DEFAULT_PRESET` constant), but the blast radius was under-applied: help\nstrings, docstrings, one adapter comment, two reference docs — and one real code\npath (`openlore serve`) — still named or implemente\n[…]\ne default. Full `vitest run src examples` green\n(294 files / 5744 tests); serve /health + all --help verified live; analyze clean.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(cli): one default preset, said once — align every surface with AD…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-18T18:39:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b608eea483846aa0cbe41fd2b3054f119b594a8b",
          "body": "… ambiguity (#228)\n\nThe resolution ladder enforced refuse-to-guess everywhere except three spots that\ntook candidates[0]: bare-name (name_only), Python self./cls. dispatch, and\ncapitalized-receiver (type_name). On a common name (parse/run/build) the edge\nsilently landed on whichever node sorted firs\n[…]\n-> 94, exactly 19\nfirst-match guesses replaced by 19 ambiguous sites (each >=2 candidates); every\nother confidence tier unchanged.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(analyzer): harden call resolution — never bind by first-match on…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-18T18:14:40Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8c7e02198a6c1653f32fadc7f9748bd613d8f1b5",
          "body": "…from parse errors or grammar drift (#227)\n\n* feat(analyzer): parse-health disclosure — no silent under-extraction from parse errors or grammar drift\n\nThe language-support registry can't over-claim a *language*, but nothing disclosed\nFAILED extraction *inside* a supported language: a file the pinned\n[…]\ncost\nclass as the sibling style-fingerprint lane.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(analyzer): parse-health disclosure — no silent under-extraction …",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-18T17:25:58Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "cc1899524df6091324b502d3eec2977f263f6fa0",
          "body": "…ed (#226)\n\nTwo detectLanguage functions had silently diverged: the complete one in\nsignature-extractor.ts and an incomplete EXT_TO_LANGUAGE-backed copy in\ncode-shaper.ts that fed AST-aware chunking. The .mts/.cts/.jsx variants (and\n~12 languages) resolved to 'unknown' on the chunking path → generic\n[…]\ndetection-bounded.\n\nImplements openspec change fix-language-detection-single-source\n(analyzer: ADD SingleSourceLanguageDetection).\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(analyzer): single-source language detection — one detector, guard…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-18T16:19:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c255602f9d999b8625f1ca95e20ce04bfc6b60f6",
          "body": "…ir, not just disclosure (#225)\n\n* feat(analyzer): self-healing index — read-path staleness triggers background repair\n\nGeneralize the cold-start bootstrap into a shared background repair service:\nevery read-path staleness signal (integrity mismatched, stale region, schema\nreset, aged analysis) now \n[…]\namp make-index-self-healing IMPLEMENTED (PR #225)\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(analyzer): make the index self-healing — staleness triggers repa…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-18T15:50:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2fe24253321c00e52282d4ca2583c38aba18c6e1",
          "body": "…append-only audit trail (#223)\n\n* feat(decisions): decision autopilot — auto-accept governance with an append-only audit trail\n\nImplements openspec change add-decision-autopilot. With\n{ \"governance\": { \"autopilot\": true } } in .openlore/config.json the commit\ngate auto-accepts verified decisions in\n[…]\npic.com>\n\n* docs(openspec): mark add-decision-autopilot IMPLEMENTED (PR #223)\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(decisions): decision autopilot — auto-accept governance with an …",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-18T14:48:58Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ebd9b751fd349b220edc4a6100de3f721a864207",
          "body": "…nizer stamp guards serving end-to-end (#222)\n\nThe keyword (BM25) corpus was rebuilt in memory from the raw `text` column on the\nfirst query in every process, so the `TOKENIZER_VERSION` stamp added by\nfix-bm25-identifier-tokenization guarded only the incremental-patch lane, never\nserving — the shipp\n[…]\nits and implements openspec change persist-tokenized-keyword-corpus\n(analyzer: ADD PersistedKeywordCorpusGuardedByTokenizerStamp).\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(analyzer): persist the tokenized BM25 keyword corpus so the toke…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-18T13:53:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9c05d5d002042132b52df0369e30046f445ed0ea",
          "body": "… match compound identifiers (#221)\n\nThe keyword (BM25) tokenizer — the zero-config DEFAULT retrieval mode — lowercased\nand split only on non-alphanumerics, so `getUserById` became the single token\n`getuserbyid` and the most common identifier queries (`user`, `getUser`) missed\nentirely. Split compou\n[…]\nng common words).\n\nImplements openspec change fix-bm25-identifier-tokenization\n(analyzer: ADD IdentifierAwareKeywordTokenization).\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(analyzer): identifier-aware BM25 tokenization so sub-word queries…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-18T13:36:53Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1294c359898a4d166dd7473b881e9bb941dc2101",
          "body": "PR #220 pinned tree-sitter-c-sharp to ^0.21.3 in package.json but did not\nregenerate the lock file, so npm ci failed on main with EUSAGE\n(lock file's tree-sitter-c-sharp@0.23.1 does not satisfy ^0.21.3).\n\nVerified locally: npm ci dry-run in sync, typecheck + build green, grammar\nloads at 0.21.3 and parses, 94 tests across the C#-touching suites pass.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(deps): sync package-lock.json with tree-sitter-c-sharp ^0.21.3 pin",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-10T11:13:43Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f8f0742facab3b1d784a39151e12e4de709bc1af",
          "body": "… ABI 14 (#220)\n\nCo-authored-by: Evgeniy Kolobov <ekolobov@symplast.com>",
          "is_bot": false,
          "headline": "fix(grammar): pin tree-sitter-c-sharp to ^0.21.3 to match tree-sitter…",
          "author_name": "Zhenya Kolobov",
          "author_login": "zkolobov",
          "committed_at": "2026-07-10T11:10:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6aa2553a6bca8d8ac76cd049dfcb5de0b877653a",
          "body": "…passes\n\nAdds the full 2026-07 end-to-end audit change set under openspec/changes/:\n86 proposals from the four 2026-07-03 passes (previously uncommitted) plus\n23 new fifth-pass proposals (2026-07-08): 16 fixes from four subsystem\naudits of the layers no prior pass read internally (drift/verification\n[…]\nERS evidence, build-graph ingest, flag\nimpact, benchmark protocol). Index and provenance in E2E-AUDIT-2026-07.md.\n\nSpec-only; no source changes.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(openspec): e2e audit 2026-07 — 109 proposed changes across five …",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-07-08T20:29:17Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "faacc2f43afe5b5bb1b5f08512bd4373be202f9c",
          "body": "…(#219)",
          "is_bot": false,
          "headline": "fix(viewer): clear selection on cluster collapse to kill ghost edges …",
          "author_name": "Laurent",
          "author_login": "laurentftech",
          "committed_at": "2026-07-01T21:08:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a34eb5545af5caedc1ac9d337f088253c6302c24",
          "body": "… the benchmark-cleared substrate default (#218)\n\n* feat(cli): openlore features — guided opt-in activation (\"where do I turn on X?\")\n\nImplements the ZeroConfigWithGuidedActivation requirement of the\nrefine-happy-path-and-defaults change. OpenLore needs zero config for its core\nvalue; everything bey\n[…]\nin the README were already updated with the flip.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: refine the happy path — guided activation, legible surface, and…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-06-28T23:11:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "21af57485eb87120a1b670b9a17d5c4318d79340",
          "body": "The README marketing rewrite renamed the Value Scorecard heading, trimmed\nthe 2026-06-03 re-prove figures, and bolded a word inside \"factual freshness\nnote\" — breaking the self-referential guards in honesty-contract.test.ts and\nepistemic-lease.test.ts. Restore the guarded strings without losing the new\nframing.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(readme): restore honesty-contract + epistemic-lease guarded strings",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-06-28T17:04:01Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "d2281769f385555ffe5ce052a39f16e82e719fad",
          "body": null,
          "is_bot": false,
          "headline": "updated readme for v2.1.4",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-06-28T16:56:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e2dcdf5d2bf43da9f35ed2fb9f89c79acdba3f5c",
          "body": "… (one substrate, two faces) (#217)\n\n* feat(mcp): capability-family taxonomy + substrate both-faces preset (one substrate, two faces)\n\nImplements the unify-navigation-and-governance-substrate change: turns the ~72-tool\nsurface from a flat registry into one discoverable-by-family substrate.\n\n- TOOL_C\n[…]\nsuite 279 files / 5538 passed. No source changed.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(mcp): capability-family taxonomy + `substrate` both-faces preset…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-06-27T15:49:40Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a4a4a49217d333dc54ee5bb1a630a994aaff5417",
          "body": "…MCP server; substrate-unification specs; archive 52 shipped changes (#216)\n\n* docs(openspec): archive 52 shipped changes; add substrate-unification + call-graph-modularization proposals\n\nSpec-only. No code, no dependency, no LLM.\n\nArchive sweep:\n- Move 52 fully-shipped change proposals into changes\n[…]\ntest. tsc + eslint clean; cold-start tests green.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: zero-interaction onboarding + auto-update + self-bootstrapping …",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-06-27T04:16:15Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "932d7951dca91c5c11bbd83ca0aabeac778dc661",
          "body": "…I remove/rename an env var) (#215)\n\n* feat(mcp): env-var impact graph — analyze_env_impact (what breaks if I remove/rename an env var)\n\nThe configuration analogue of analyze_impact: given an env var name, return the\nline-precise read sites (file/line/enclosing function; module-level reads\ndisclosed\n[…]\n run src examples green (274 files / 5395 tests).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(mcp): env-var impact graph — analyze_env_impact (what breaks if …",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-06-27T02:35:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "88f1bc6b9f2365df13a5fb108b958dcd6dad8c5b",
          "body": "… same-named nested functions) (#214)\n\n* feat(analyzer): stable identity for nested functions — stop collapsing same-named nested functions into one node\n\nSame-named functions nested in different scopes (a `function helper(){}` in one\nmethod and another in a second, two `const cleanup = …` in one fu\n[…]\nosal/spec/tasks document the query-spec coverage.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(analyzer): stable identity for nested functions (stop collapsing…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-06-27T01:51:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b901c07e00156085057a078f1f51d2954dc2ed42",
          "body": "…exceptions escape a function, where they're caught) (#213)\n\n* feat(mcp): error-propagation graph — analyze_error_propagation surfaces what exceptions escape a function and where they're caught\n\nThe call graph answers who-calls-whom but is silent on \"what can throw out of\nhere, and is it handled?\" —\n[…]\n\nlist across the six identity-bearing subsystems.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(mcp): error-propagation graph — analyze_error_propagation (what …",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-06-27T01:00:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d60f6dfa548a65f96834cf795d2b92f1cca10cec",
          "body": "…tead of reinvent) (#212)\n\n* feat(mcp): find_clones — symbol/snippet-scoped clone query (reuse instead of reinvent)\n\nExpose the existing near-clone detector as an edit-time conclusion tool. Where\nget_duplicate_report is the whole-repo audit (every clone group, read from a\nprecomputed artifact), find\n[…]\n passed, 2 skipped. Change: add-clone-query-tool.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(mcp): find_clones — symbol/snippet-scoped clone query (reuse ins…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-06-26T21:22:40Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2b50513c14da5af90f676b3340fc1dd523c89f01",
          "body": "…xpress, observability, and the cross-repo federation bridge (#211)\n\n* fix(cross-service): make single-repo client→handler HTTP edges actually wire for Express & same-language full-stack\n\nThe call-graph already projects outbound HTTP client call sites onto route\nhandlers as function→function `http_e\n[…]\nd, byte-identical runs, find_dead_code liveness).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(cross-service): client→handler HTTP topology — fix single-repo E…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-06-26T20:17:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "810aad945a1987e7627a5c6c50b727748b800dc5",
          "body": "…nce, bootstrap everywhere) (#210)\n\n* feat(cli): shareable graph artifact — export bundle / import (index once, bootstrap everywhere)\n\nA team's graph index is a deterministic function of the committed source, so\nre-indexing it on every machine and CI run is redundant work that scales with\nteam size.\n[…]\ne dogfooding of PR #210's export/import boundary.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(cli): shareable graph artifact — export bundle / import (index o…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-06-26T18:05:28Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f7091ac77ea5ee5d461dd8000504ca5c303c6564",
          "body": "…hanged since a ref (#209)\n\n* feat(mcp): change significance briefing — briefing_since ranks what changed since a ref\n\nAdds an opt-in conclusion tool (and `openlore briefing-since` CLI) that answers the\nreviewer / catch-up / onboarding question the other change tools don't: not \"what does\nMY pending\n[…]\n contract-shape\nintact, coverage-gaps unaffected.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(mcp): change significance briefing — briefing_since ranks what c…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-06-26T16:09:53Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0a858281772e474556bb1bec3448660537fa10a1",
          "body": "… idiom profile + get_style_fingerprint tool (#208)\n\n* feat(analyzer): codebase style fingerprint — descriptive per-language idiom profile + get_style_fingerprint tool\n\nTally a fixed, closed set of idiom counters (function form, const/let binding,\nternary/if, await/.then, template/concat, function-n\n[…]\nboth pass in\nisolation, 16/16 — not regressions.)\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(analyzer): codebase style fingerprint — descriptive per-language…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-06-26T14:06:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "705022882ffe7b655be65622d448af206e84722a",
          "body": "…king-change verdict over a diff) (#207)\n\n* feat(mcp): public API surface contract — certify_public_surface tool + CLI (breaking-change verdict over a diff)\n\nFEATURE-UPDATES proposal 2. Adds a deterministic public-surface artifact and a\nbreaking-change classifier, surfaced as one opt-in conclusion t\n[…]\nlic-surface\nsuite 54 → 60; full suite 5167 green.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(mcp): public API surface contract — certify_public_surface (brea…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-06-26T02:43:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "48dd5aeb12b1122e89007ba2fdc4197dff5a8b7f",
          "body": "…sions across renames & moves (#206)\n\n* feat(memory): symbol identity continuity — carry anchored memory/decisions across renames & moves\n\nA pure rename (computeTax → calculateTax) or a file move changed a symbol's name\n(hence its stableId), orphaning every memory, decision, and spec link anchored t\n[…]\ncheck, build green; rename carry reconfirmed e2e.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(memory): symbol identity continuity — carry anchored memory/deci…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-06-26T00:49:52Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "215e52424d931e4dc5dc45f4b223f0939513941c",
          "body": "… Python relative imports + re_export provenance (#205)\n\n* feat(call-graph): re-export/barrel resolution threaded into Pass 2 + re_export provenance\n\nCall resolution recall (FEATURE-UPDATES proposal 4), scoped to the genuinely-missing\nedge class. The import resolver now follows re-export chains (exp\n[…]\nsable scratchpad repos; all real repos untouched.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(call-graph): call resolution recall — re-export/barrel (TS/JS) +…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-06-25T22:16:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6f81a6b6cdd54aed6915489e7eb4732bab49eb26",
          "body": "… + coverage-gaps CLI (#204)\n\n* feat: structural test-coverage gap report — report_coverage_gaps tool + coverage-gaps CLI\n\nSurfaces important code with NO reaching test, ranked by hub/chokepoint\nsignificance — the structural inverse of select_tests over the whole graph,\nno runtime/coverage tool, det\n[…]\nesolvedOnly.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: sim <sim@test.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: structural test-coverage gap report — report_coverage_gaps tool…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-06-25T12:58:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "12f2b01ab6259a8a01edefd4032cce36c41f9740",
          "body": "…ol (+ correct stale proposal statuses) (#203)\n\n* docs(openspec): correct 6 stale DRAFT statuses to IMPLEMENTED\n\nAudited all open change proposals against src/. Six were marked DRAFT but their\nfeatures actually shipped (the 2026-06-20 batch — decisions recorded \"before any\ncode\", code landed, status\n[…]\nhened guard.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: sim <sim@test.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: declarative language-support registry + get_language_support to…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-06-25T11:07:09Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9758d398e79a4688ced42d0df1008d071a6d11d6",
          "body": "…nches/PRs/agent tasks (PARALLEL-WORK proposal 4) (#202)\n\n* feat: plan_parallel_work — schedule N tasks into safe-to-dispatch waves\n\nPARALLEL-WORK-COORDINATION proposal 2: the agent-facing conclusion tool that\ncomposes the footprint + hazard classifier (proposal 1) into the artifact a swarm\norchestr\n[…]\nNo new tool.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: sim <sim@test.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: cross-actor interference map — map_in_flight_conflicts over bra…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-06-25T03:14:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "048adfa581bee6484ba94a47d8d8fad2ab7118fd",
          "body": "…ed write-footprint (PARALLEL-WORK proposal 3) (#201)\n\n* feat: footprint escape detection — flag diffs that leave their declared write-footprint\n\nThe back-side safety net of PARALLEL-WORK-COORDINATION (proposal 3). Proposals 1 and 2\nplan a swarm from *predicted* (declared) write-footprints — advisor\n[…]\ntests green.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: sim <sim@test.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: footprint escape detection — flag diffs that leave their declar…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-06-25T03:10:16Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "eb78e54b391885759a8be0d0bae7e5e643779cf7",
          "body": "feat: change footprint projection + pairwise hazard classifier (PARALLEL-WORK proposal 1)",
          "is_bot": false,
          "headline": "Merge pull request #199 from clay-good/feat/change-footprint-projection",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-06-25T03:05:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ed44c7dab2841b17b196040002b99909ef1336de",
          "body": "… gaps\n\nAudited PR #199 against its spec and dogfood. The 24 existing tests cover\nevery spec scenario, but 5 public-contract gaps had zero coverage; the most\nload-bearing was WAW-over-RAW precedence — a refactor reordering those branches\nwould silently downgrade a true write-write conflict to a mere\n[…]\nrified byte-identical against the real 5932-node graph.\nFull suite: 245 files, 4893 pass / 2 skip; lint + typecheck + build clean.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(change-footprint): adversarial regression set closing 5 coverage…",
          "author_name": "sim",
          "author_login": null,
          "committed_at": "2026-06-25T01:04:01Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "842bfef38a13304bf0e0fb413b79f4133aef4425",
          "body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: mark PARALLEL-WORK proposal 1 (footprint projection) shipped",
          "author_name": "sim",
          "author_login": null,
          "committed_at": "2026-06-24T23:22:30Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "00b8de5890b65914146b50e0bcb298e9fc0549a3",
          "body": "The borrow-analysis core of PARALLEL-WORK-COORDINATION (proposal 1). Generalizes\nblast_radius from one symbol to a declared task: a deterministic three-region\nfootprint (write / read / affected) plus a soft co-change annotation, and a pure\npairwise hazard classifier (WAW / shared-append / RAW / WAR \n[…]\n5932-node graph, reproducing the validation exercise's shared-append\non dispatchTool (see DOGFOOD-change-footprint-projection.md).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: change footprint projection + pairwise hazard classifier",
          "author_name": "sim",
          "author_login": null,
          "committed_at": "2026-06-24T23:21:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "73907c3171d38f2d77002ef2923e0e3ebe1ea448",
          "body": "…-structural-diff\n\nfeat(pi): close the MCP-tool / Pi-extension parity gap (16 native tools)",
          "is_bot": false,
          "headline": "Merge pull request #198 from laurentftech/feat/pi-expose-blast-radius…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-06-24T23:05:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5e2aa15c43fde39197c4a867bb85f597f230c594",
          "body": "…-injection\n\nfeat(pi): task-scoped context injection parity with `orient --inject`",
          "is_bot": false,
          "headline": "Merge pull request #197 from laurentftech/feat/pi-task-scoped-context…",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-06-24T23:03:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b44b8e8b73a3323bf4148401cb3759a72bddeeb4",
          "body": "feat: index integrity attestation — never serve a half-built graph silently",
          "is_bot": false,
          "headline": "Merge pull request #196 from clay-good/feat/index-integrity-attestation",
          "author_name": "Clay Good",
          "author_login": "clay-good",
          "committed_at": "2026-06-24T23:03:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fad655cf8c80a8eeefde95eaed8fd33332a99014",
          "body": "…-side + agent-surface tests\n\nSecond adversarial review of the index integrity attestation (PR #196).\n\nBug fixes (dogfooded on this repo's real index):\n- HIGH — refreshAttestationCounts could mask a `mismatched` verdict. It re-stamped the\n  attestation's schemaVersion to the current value; in the wi\n[…]\ne as-built behavior, including that the\nverdict is a load-time/cache-miss property kept healthy by the watcher's lockstep refresh.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "harden(round 2): no schema-mask on refresh, passive checkpoint, build…",
          "author_name": "sim",
          "author_login": null,
          "committed_at": "2026-06-24T22:53:21Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7edf0f1a2ebb44e917904bfc379cb9bbeb670f99",
          "body": "The compact tool-result render listed modifiedSpecs, which duplicates\nthe per-item `specs` already shown under synced[]. Skip it so the glance\nis just the synced decisions plus any errors.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(pi): drop redundant modifiedSpecs from the sync_decisions glance",
          "author_name": "Laurent FRANCOISE",
          "author_login": "laurentftech",
          "committed_at": "2026-06-24T21:48:15Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f8bb42cfb476a0f956c72990adea7954cc8fd2b5",
          "body": "Export NAV_TOOLS and add a surface contract test:\n- names unique; every entry fully specified for registerTool (name,\n  label, description, guideline, object params schema);\n- every Pi-surfaced tool name exists in TOOL_DEFINITIONS — the daemon\n  registry — so a renamed/removed tool (e.g. get_decisio\n[…]\n params are a subset of the daemon tool's\n  inputSchema (directory excepted — injected by the daemon), catching a\n  typo'd or stale param name.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(pi): assert the NAV_TOOLS surface stays valid and dispatchable",
          "author_name": "Laurent FRANCOISE",
          "author_login": "laurentftech",
          "committed_at": "2026-06-24T21:26:18Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3444421504a87b849f287f50610a7af4d02bbb73",
          "body": "Spec & drift: check_spec_drift, audit_spec_coverage, list_spec_domains.\nDecision gate: record_decision, list_decisions, approve_decision,\nreject_decision, sync_decisions — so the Pi agent can drive the project's\nown decision workflow (record before coding; present/approve/sync at the\ngate). approve_\n[…]\ns —\nrarely triggered, and surface dilution hurts weak local tool-callers\n(the Spec 14 / lean-default lesson). Pi stays curated, not exhaustive.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(pi): expose spec-drift and decision-gate tools as native tools",
          "author_name": "Laurent FRANCOISE",
          "author_login": "laurentftech",
          "committed_at": "2026-06-24T21:20:43Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b2ff738accdfc391e68fe0f7b87c11dba9dedaff",
          "body": "… tools\n\nPi is a full agent host, not a second-class one: if Claude Code agents\nget code-anchored memory via the memory preset, the Pi agent should too.\nremember persists a durable fact anchored to a symbol/file (self-\ninvalidating); recall surfaces task-scoped memories with a freshness\nverdict. serve dispatches both regardless of preset; Pi already ships a\nwrite tool (configure), so statefulness is no blocker.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(pi): expose remember and recall (code-anchored memory) as native…",
          "author_name": "Laurent FRANCOISE",
          "author_login": "laurentftech",
          "committed_at": "2026-06-24T21:12:10Z",
          "body_truncated": false,
          "is_coding_agent": true
        }
      ],
      "releases_count": 43,
      "commits_last_year": 1437,
      "latest_release_at": "2026-07-19T23:07:09Z",
      "latest_release_tag": "v2.1.6",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 23,
      "days_since_latest_release": 6,
      "mean_days_between_releases": 4.2
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 100,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "openlore",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "architectural-memory",
            "structural-analysis",
            "code-analysis",
            "call-graph",
            "static-analysis",
            "ai-coding-agents",
            "mcp",
            "cli",
            "pi-package"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/openlore",
          "is_deprecated": false,
          "latest_version": "2.1.6",
          "repository_url": "https://github.com/clay-good/openlore",
          "versions_count": 27,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 3645,
          "first_published_at": "2026-05-12T11:45:51.764000Z",
          "latest_published_at": "2026-07-19T23:09:38.512000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 6
        }
      ]
    },
    "popularity": {
      "forks": 31,
      "stars": 207,
      "watchers": 3,
      "fork_history": {
        "days": [
          {
            "date": "2026-02-07",
            "count": 1
          },
          {
            "date": "2026-02-18",
            "count": 2
          },
          {
            "date": "2026-02-28",
            "count": 1
          },
          {
            "date": "2026-03-02",
            "count": 1
          },
          {
            "date": "2026-03-03",
            "count": 1
          },
          {
            "date": "2026-03-04",
            "count": 1
          },
          {
            "date": "2026-03-16",
            "count": 1
          },
          {
            "date": "2026-03-17",
            "count": 1
          },
          {
            "date": "2026-03-25",
            "count": 1
          },
          {
            "date": "2026-03-28",
            "count": 1
          },
          {
            "date": "2026-04-03",
            "count": 1
          },
          {
            "date": "2026-04-10",
            "count": 1
          },
          {
            "date": "2026-04-11",
            "count": 2
          },
          {
            "date": "2026-04-27",
            "count": 1
          },
          {
            "date": "2026-04-28",
            "count": 1
          },
          {
            "date": "2026-05-07",
            "count": 1
          },
          {
            "date": "2026-05-27",
            "count": 1
          },
          {
            "date": "2026-06-05",
            "count": 1
          },
          {
            "date": "2026-06-07",
            "count": 1
          },
          {
            "date": "2026-06-12",
            "count": 1
          },
          {
            "date": "2026-06-15",
            "count": 1
          },
          {
            "date": "2026-06-25",
            "count": 1
          },
          {
            "date": "2026-06-28",
            "count": 1
          },
          {
            "date": "2026-07-06",
            "count": 1
          },
          {
            "date": "2026-07-10",
            "count": 1
          },
          {
            "date": "2026-07-15",
            "count": 1
          },
          {
            "date": "2026-07-16",
            "count": 1
          },
          {
            "date": "2026-07-21",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 30,
        "total_forks": 31
      },
      "star_history": null,
      "open_issues_and_prs": 1
    },
    "ai_readiness": {
      "has_nix": true,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": true,
      "bootstrap_files": [],
      "api_schema_files": [
        "src/core/scip/vendor/scip.proto"
      ],
      "has_devcontainer": false,
      "typecheck_configs": [
        "examples/drift-demo/tsconfig.json",
        "tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 228745,
      "source_files_sampled": 757,
      "oversized_source_files": 15,
      "agent_instruction_files": [
        "AGENTS.md",
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 25853
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [
          {
            "name": "sharp",
            "direct": false,
            "version": "0.34.5",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.3,
            "advisory_ids": [
              "GHSA-f88m-g3jw-g9cj"
            ],
            "fixed_version": "0.35.0",
            "advisory_count": 1,
            "oldest_advisory_days": 4
          },
          {
            "name": "@hono/node-server",
            "direct": false,
            "version": "1.19.15",
            "severity": "moderate",
            "ecosystem": "npm",
            "cvss_score": 5.9,
            "advisory_ids": [
              "GHSA-frvp-7c67-39w9"
            ],
            "fixed_version": "2.0.5",
            "advisory_count": 1,
            "oldest_advisory_days": 4
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "high": 1,
          "moderate": 1
        },
        "advisory_count": 2,
        "affected_count": 2,
        "assessed_count": 361,
        "malicious_count": 0,
        "assessed_package": "npm:openlore@2.1.6",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "@inquirer/prompts",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^8.5.2"
        },
        {
          "name": "@modelcontextprotocol/sdk",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.27.1"
        },
        {
          "name": "@modelcontextprotocol/server-memory",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^2026.1.26"
        },
        {
          "name": "@vitejs/plugin-react",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^6.0.4"
        },
        {
          "name": "chalk",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.3.0"
        },
        {
          "name": "chokidar",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.0.0"
        },
        {
          "name": "commander",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^12.1.0"
        },
        {
          "name": "glob",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^13.0.6"
        },
        {
          "name": "ignore",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^7.0.6"
        },
        {
          "name": "jsonc-parser",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.3.1"
        },
        {
          "name": "ora",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^8.1.1"
        },
        {
          "name": "react",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^19.1.1"
        },
        {
          "name": "react-dom",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^19.1.1"
        },
        {
          "name": "tree-sitter-wasms",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "0.1.13"
        },
        {
          "name": "vite",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^8.0.16"
        },
        {
          "name": "web-tree-sitter",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "0.25.0"
        },
        {
          "name": "yaml",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.6.1"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "@inquirer/prompts",
            "direct": true,
            "version": "8.5.2",
            "ecosystem": "npm"
          },
          {
            "name": "@modelcontextprotocol/sdk",
            "direct": true,
            "version": "1.29.0",
            "ecosystem": "npm"
          },
          {
            "name": "@modelcontextprotocol/server-memory",
            "direct": true,
            "version": "2026.7.4",
            "ecosystem": "npm"
          },
          {
            "name": "@vitejs/plugin-react",
            "direct": true,
            "version": "6.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "chalk",
            "direct": true,
            "version": "5.6.2",
            "ecosystem": "npm"
          },
          {
            "name": "chokidar",
            "direct": true,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "commander",
            "direct": true,
            "version": "12.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "glob",
            "direct": true,
            "version": "13.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "ignore",
            "direct": true,
            "version": "5.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "ignore",
            "direct": true,
            "version": "7.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "ignore",
            "direct": true,
            "version": "7.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "jsonc-parser",
            "direct": true,
            "version": "3.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "ora",
            "direct": true,
            "version": "8.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "react",
            "direct": true,
            "version": "19.2.8",
            "ecosystem": "npm"
          },
          {
            "name": "react-dom",
            "direct": true,
            "version": "19.2.8",
            "ecosystem": "npm"
          },
          {
            "name": "tree-sitter-wasms",
            "direct": true,
            "version": "0.1.13",
            "ecosystem": "npm"
          },
          {
            "name": "vite",
            "direct": true,
            "version": "8.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "web-tree-sitter",
            "direct": true,
            "version": "0.25.0",
            "ecosystem": "npm"
          },
          {
            "name": "yaml",
            "direct": true,
            "version": "2.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "@anthropic-ai/sdk",
            "direct": false,
            "version": "0.91.1",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-crypto/crc32",
            "direct": false,
            "version": "5.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-crypto/sha256-browser",
            "direct": false,
            "version": "5.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-crypto/sha256-js",
            "direct": false,
            "version": "5.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-crypto/supports-web-crypto",
            "direct": false,
            "version": "5.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-crypto/util",
            "direct": false,
            "version": "5.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/client-bedrock-runtime",
            "direct": false,
            "version": "3.1048.0",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/core",
            "direct": false,
            "version": "3.974.11",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/core",
            "direct": false,
            "version": "3.977.1",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/credential-provider-env",
            "direct": false,
            "version": "3.972.37",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/credential-provider-env",
            "direct": false,
            "version": "3.972.61",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/credential-provider-http",
            "direct": false,
            "version": "3.972.39",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/credential-provider-http",
            "direct": false,
            "version": "3.972.63",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/credential-provider-ini",
            "direct": false,
            "version": "3.972.41",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/credential-provider-ini",
            "direct": false,
            "version": "3.973.6",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/credential-provider-login",
            "direct": false,
            "version": "3.972.41",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/credential-provider-login",
            "direct": false,
            "version": "3.972.68",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/credential-provider-node",
            "direct": false,
            "version": "3.972.42",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/credential-provider-node",
            "direct": false,
            "version": "3.972.72",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/credential-provider-process",
            "direct": false,
            "version": "3.972.37",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/credential-provider-process",
            "direct": false,
            "version": "3.972.61",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/credential-provider-sso",
            "direct": false,
            "version": "3.972.41",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/credential-provider-sso",
            "direct": false,
            "version": "3.973.5",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/credential-provider-web-identity",
            "direct": false,
            "version": "3.972.41",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/credential-provider-web-identity",
            "direct": false,
            "version": "3.972.67",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/eventstream-handler-node",
            "direct": false,
            "version": "3.972.16",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/eventstream-handler-node",
            "direct": false,
            "version": "3.972.30",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/middleware-eventstream",
            "direct": false,
            "version": "3.972.12",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/middleware-eventstream",
            "direct": false,
            "version": "3.972.25",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/middleware-websocket",
            "direct": false,
            "version": "3.972.19",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/middleware-websocket",
            "direct": false,
            "version": "3.972.43",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/nested-clients",
            "direct": false,
            "version": "3.997.35",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/nested-clients",
            "direct": false,
            "version": "3.997.9",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/signature-v4-multi-region",
            "direct": false,
            "version": "3.996.27",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/signature-v4-multi-region",
            "direct": false,
            "version": "3.996.42",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/token-providers",
            "direct": false,
            "version": "3.1048.0",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/token-providers",
            "direct": false,
            "version": "3.1095.0",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/types",
            "direct": false,
            "version": "3.973.8",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/types",
            "direct": false,
            "version": "3.974.2",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/util-locate-window",
            "direct": false,
            "version": "3.965.5",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/util-locate-window",
            "direct": false,
            "version": "3.965.8",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/xml-builder",
            "direct": false,
            "version": "3.972.24",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/xml-builder",
            "direct": false,
            "version": "3.972.37",
            "ecosystem": "npm"
          },
          {
            "name": "@aws/lambda-invoke-store",
            "direct": false,
            "version": "0.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "@aws/lambda-invoke-store",
            "direct": false,
            "version": "0.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-string-parser",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-validator-identifier",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/parser",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/runtime",
            "direct": false,
            "version": "7.29.2",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/runtime",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/types",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@bcoe/v8-coverage",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@earendil-works/pi-agent-core",
            "direct": false,
            "version": "0.82.1",
            "ecosystem": "npm"
          },
          {
            "name": "@earendil-works/pi-ai",
            "direct": false,
            "version": "0.82.1",
            "ecosystem": "npm"
          },
          {
            "name": "@earendil-works/pi-coding-agent",
            "direct": false,
            "version": "0.82.1",
            "ecosystem": "npm"
          },
          {
            "name": "@earendil-works/pi-tui",
            "direct": false,
            "version": "0.82.1",
            "ecosystem": "npm"
          },
          {
            "name": "@emnapi/core",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "@emnapi/runtime",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "@emnapi/runtime",
            "direct": false,
            "version": "1.11.3",
            "ecosystem": "npm"
          },
          {
            "name": "@emnapi/wasi-threads",
            "direct": false,
            "version": "1.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/aix-ppc64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-arm",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/darwin-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/darwin-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/freebsd-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/freebsd-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-arm",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-ia32",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-loong64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-mips64el",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-ppc64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-riscv64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-s390x",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/netbsd-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/netbsd-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openbsd-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openbsd-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openharmony-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/sunos-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-ia32",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint-community/eslint-utils",
            "direct": false,
            "version": "4.10.1",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint-community/regexpp",
            "direct": false,
            "version": "4.12.2",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/config-array",
            "direct": false,
            "version": "0.23.5",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/config-helpers",
            "direct": false,
            "version": "0.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/core",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/js",
            "direct": false,
            "version": "10.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/object-schema",
            "direct": false,
            "version": "3.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/plugin-kit",
            "direct": false,
            "version": "0.7.2",
            "ecosystem": "npm"
          },
          {
            "name": "@google/genai",
            "direct": false,
            "version": "1.52.0",
            "ecosystem": "npm"
          },
          {
            "name": "@hono/node-server",
            "direct": false,
            "version": "2.0.11",
            "ecosystem": "npm"
          },
          {
            "name": "@huggingface/jinja",
            "direct": false,
            "version": "0.5.9",
            "ecosystem": "npm"
          },
          {
            "name": "@huggingface/transformers",
            "direct": false,
            "version": "3.8.1",
            "ecosystem": "npm"
          },
          {
            "name": "@humanfs/core",
            "direct": false,
            "version": "0.19.2",
            "ecosystem": "npm"
          },
          {
            "name": "@humanfs/node",
            "direct": false,
            "version": "0.16.8",
            "ecosystem": "npm"
          },
          {
            "name": "@humanfs/types",
            "direct": false,
            "version": "0.15.0",
            "ecosystem": "npm"
          },
          {
            "name": "@humanwhocodes/module-importer",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "@humanwhocodes/retry",
            "direct": false,
            "version": "0.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "@img/colour",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-darwin-arm64",
            "direct": false,
            "version": "0.35.3",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-darwin-x64",
            "direct": false,
            "version": "0.35.3",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-freebsd-wasm32",
            "direct": false,
            "version": "0.35.3",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-libvips-darwin-arm64",
            "direct": false,
            "version": "1.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-libvips-darwin-x64",
            "direct": false,
            "version": "1.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-libvips-linux-arm",
            "direct": false,
            "version": "1.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-libvips-linux-arm64",
            "direct": false,
            "version": "1.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-libvips-linux-ppc64",
            "direct": false,
            "version": "1.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-libvips-linux-riscv64",
            "direct": false,
            "version": "1.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-libvips-linux-s390x",
            "direct": false,
            "version": "1.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-libvips-linux-x64",
            "direct": false,
            "version": "1.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-libvips-linuxmusl-arm64",
            "direct": false,
            "version": "1.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-libvips-linuxmusl-x64",
            "direct": false,
            "version": "1.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-linux-arm",
            "direct": false,
            "version": "0.35.3",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-linux-arm64",
            "direct": false,
            "version": "0.35.3",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-linux-ppc64",
            "direct": false,
            "version": "0.35.3",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-linux-riscv64",
            "direct": false,
            "version": "0.35.3",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-linux-s390x",
            "direct": false,
            "version": "0.35.3",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-linux-x64",
            "direct": false,
            "version": "0.35.3",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-linuxmusl-arm64",
            "direct": false,
            "version": "0.35.3",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-linuxmusl-x64",
            "direct": false,
            "version": "0.35.3",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-wasm32",
            "direct": false,
            "version": "0.35.3",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-webcontainers-wasm32",
            "direct": false,
            "version": "0.35.3",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-win32-arm64",
            "direct": false,
            "version": "0.35.3",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-win32-ia32",
            "direct": false,
            "version": "0.35.3",
            "ecosystem": "npm"
          },
          {
            "name": "@img/sharp-win32-x64",
            "direct": false,
            "version": "0.35.3",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/ansi",
            "direct": false,
            "version": "2.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/checkbox",
            "direct": false,
            "version": "5.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/confirm",
            "direct": false,
            "version": "6.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/core",
            "direct": false,
            "version": "11.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/editor",
            "direct": false,
            "version": "5.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/expand",
            "direct": false,
            "version": "5.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/external-editor",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/figures",
            "direct": false,
            "version": "2.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/input",
            "direct": false,
            "version": "5.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/number",
            "direct": false,
            "version": "4.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/password",
            "direct": false,
            "version": "5.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/rawlist",
            "direct": false,
            "version": "5.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/search",
            "direct": false,
            "version": "4.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/select",
            "direct": false,
            "version": "5.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/type",
            "direct": false,
            "version": "4.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "@isaacs/fs-minipass",
            "direct": false,
            "version": "4.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/resolve-uri",
            "direct": false,
            "version": "3.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/sourcemap-codec",
            "direct": false,
            "version": "1.5.5",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/trace-mapping",
            "direct": false,
            "version": "0.3.31",
            "ecosystem": "npm"
          },
          {
            "name": "@jsonjoy.com/base64",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@jsonjoy.com/base64",
            "direct": false,
            "version": "17.67.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jsonjoy.com/buffers",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "@jsonjoy.com/buffers",
            "direct": false,
            "version": "17.67.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jsonjoy.com/codegen",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jsonjoy.com/codegen",
            "direct": false,
            "version": "17.67.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jsonjoy.com/fs-core",
            "direct": false,
            "version": "4.64.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jsonjoy.com/fs-fsa",
            "direct": false,
            "version": "4.64.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jsonjoy.com/fs-node",
            "direct": false,
            "version": "4.64.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jsonjoy.com/fs-node-builtins",
            "direct": false,
            "version": "4.64.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jsonjoy.com/fs-node-to-fsa",
            "direct": false,
            "version": "4.64.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jsonjoy.com/fs-node-utils",
            "direct": false,
            "version": "4.64.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jsonjoy.com/fs-print",
            "direct": false,
            "version": "4.64.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jsonjoy.com/fs-snapshot",
            "direct": false,
            "version": "4.64.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jsonjoy.com/json-pack",
            "direct": false,
            "version": "1.21.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jsonjoy.com/json-pack",
            "direct": false,
            "version": "17.67.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jsonjoy.com/json-pointer",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@jsonjoy.com/json-pointer",
            "direct": false,
            "version": "17.67.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jsonjoy.com/util",
            "direct": false,
            "version": "1.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jsonjoy.com/util",
            "direct": false,
            "version": "17.67.0",
            "ecosystem": "npm"
          },
          {
            "name": "@lancedb/lancedb",
            "direct": false,
            "version": "0.22.4-beta.3",
            "ecosystem": "npm"
          },
          {
            "name": "@lancedb/lancedb-darwin-arm64",
            "direct": false,
            "version": "0.22.4-beta.3",
            "ecosystem": "npm"
          },
          {
            "name": "@lancedb/lancedb-darwin-x64",
            "direct": false,
            "version": "0.22.4-beta.3",
            "ecosystem": "npm"
          },
          {
            "name": "@lancedb/lancedb-linux-arm64-gnu",
            "direct": false,
            "version": "0.22.4-beta.3",
            "ecosystem": "npm"
          },
          {
            "name": "@lancedb/lancedb-linux-arm64-musl",
            "direct": false,
            "version": "0.22.4-beta.3",
            "ecosystem": "npm"
          },
          {
            "name": "@lancedb/lancedb-linux-x64-gnu",
            "direct": false,
            "version": "0.22.4-beta.3",
            "ecosystem": "npm"
          },
          {
            "name": "@lancedb/lancedb-linux-x64-musl",
            "direct": false,
            "version": "0.22.4-beta.3",
            "ecosystem": "npm"
          },
          {
            "name": "@lancedb/lancedb-win32-arm64-msvc",
            "direct": false,
            "version": "0.22.4-beta.3",
            "ecosystem": "npm"
          },
          {
            "name": "@lancedb/lancedb-win32-x64-msvc",
            "direct": false,
            "version": "0.22.4-beta.3",
            "ecosystem": "npm"
          },
          {
            "name": "@mariozechner/clipboard",
            "direct": false,
            "version": "0.3.9",
            "ecosystem": "npm"
          },
          {
            "name": "@mariozechner/clipboard-darwin-arm64",
            "direct": false,
            "version": "0.3.9",
            "ecosystem": "npm"
          },
          {
            "name": "@mariozechner/clipboard-darwin-universal",
            "direct": false,
            "version": "0.3.9",
            "ecosystem": "npm"
          },
          {
            "name": "@mariozechner/clipboard-darwin-x64",
            "direct": false,
            "version": "0.3.9",
            "ecosystem": "npm"
          },
          {
            "name": "@mariozechner/clipboard-linux-arm64-gnu",
            "direct": false,
            "version": "0.3.9",
            "ecosystem": "npm"
          },
          {
            "name": "@mariozechner/clipboard-linux-arm64-musl",
            "direct": false,
            "version": "0.3.9",
            "ecosystem": "npm"
          },
          {
            "name": "@mariozechner/clipboard-linux-riscv64-gnu",
            "direct": false,
            "version": "0.3.9",
            "ecosystem": "npm"
          },
          {
            "name": "@mariozechner/clipboard-linux-x64-gnu",
            "direct": false,
            "version": "0.3.9",
            "ecosystem": "npm"
          },
          {
            "name": "@mariozechner/clipboard-linux-x64-musl",
            "direct": false,
            "version": "0.3.9",
            "ecosystem": "npm"
          },
          {
            "name": "@mariozechner/clipboard-win32-arm64-msvc",
            "direct": false,
            "version": "0.3.9",
            "ecosystem": "npm"
          },
          {
            "name": "@mariozechner/clipboard-win32-x64-msvc",
            "direct": false,
            "version": "0.3.9",
            "ecosystem": "npm"
          },
          {
            "name": "@mistralai/mistralai",
            "direct": false,
            "version": "2.2.6",
            "ecosystem": "npm"
          },
          {
            "name": "@napi-rs/wasm-runtime",
            "direct": false,
            "version": "1.1.6",
            "ecosystem": "npm"
          },
          {
            "name": "@nodable/entities",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/api",
            "direct": false,
            "version": "1.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/semantic-conventions",
            "direct": false,
            "version": "1.41.1",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/semantic-conventions",
            "direct": false,
            "version": "1.43.0",
            "ecosystem": "npm"
          },
          {
            "name": "@oxc-project/types",
            "direct": false,
            "version": "0.139.0",
            "ecosystem": "npm"
          },
          {
            "name": "@protobufjs/aspromise",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@protobufjs/base64",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@protobufjs/codegen",
            "direct": false,
            "version": "2.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "@protobufjs/eventemitter",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "@protobufjs/fetch",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "@protobufjs/float",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@protobufjs/path",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@protobufjs/pool",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@protobufjs/utf8",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "@protobufjs/utf8",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-android-arm64",
            "direct": false,
            "version": "1.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-darwin-arm64",
            "direct": false,
            "version": "1.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-darwin-x64",
            "direct": false,
            "version": "1.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-freebsd-x64",
            "direct": false,
            "version": "1.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-linux-arm-gnueabihf",
            "direct": false,
            "version": "1.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-linux-arm64-gnu",
            "direct": false,
            "version": "1.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-linux-arm64-musl",
            "direct": false,
            "version": "1.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-linux-ppc64-gnu",
            "direct": false,
            "version": "1.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-linux-s390x-gnu",
            "direct": false,
            "version": "1.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-linux-x64-gnu",
            "direct": false,
            "version": "1.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-linux-x64-musl",
            "direct": false,
            "version": "1.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-openharmony-arm64",
            "direct": false,
            "version": "1.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-wasm32-wasi",
            "direct": false,
            "version": "1.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-win32-arm64-msvc",
            "direct": false,
            "version": "1.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-win32-x64-msvc",
            "direct": false,
            "version": "1.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/pluginutils",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "@silvia-odwyer/photon-node",
            "direct": false,
            "version": "0.3.4",
            "ecosystem": "npm"
          },
          {
            "name": "@smithy/core",
            "direct": false,
            "version": "3.24.3",
            "ecosystem": "npm"
          },
          {
            "name": "@smithy/core",
            "direct": false,
            "version": "3.30.0",
            "ecosystem": "npm"
          },
          {
            "name": "@smithy/credential-provider-imds",
            "direct": false,
            "version": "4.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "@smithy/credential-provider-imds",
            "direct": false,
            "version": "4.4.14",
            "ecosystem": "npm"
          },
          {
            "name": "@smithy/fetch-http-handler",
            "direct": false,
            "version": "5.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "@smithy/fetch-http-handler",
            "direct": false,
            "version": "5.6.11",
            "ecosystem": "npm"
          },
          {
            "name": "@smithy/is-array-buffer",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@smithy/node-http-handler",
            "direct": false,
            "version": "4.7.3",
            "ecosystem": "npm"
          },
          {
            "name": "@smithy/node-http-handler",
            "direct": false,
            "version": "4.9.11",
            "ecosystem": "npm"
          },
          {
            "name": "@smithy/signature-v4",
            "direct": false,
            "version": "5.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "@smithy/signature-v4",
            "direct": false,
            "version": "5.6.10",
            "ecosystem": "npm"
          },
          {
            "name": "@smithy/types",
            "direct": false,
            "version": "4.14.2",
            "ecosystem": "npm"
          },
          {
            "name": "@smithy/types",
            "direct": false,
            "version": "4.16.1",
            "ecosystem": "npm"
          },
          {
            "name": "@smithy/util-buffer-from",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@smithy/util-utf8",
            "direct": false,
            "version": "2.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@standard-schema/spec",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@tybys/wasm-util",
            "direct": false,
            "version": "0.10.3",
            "ecosystem": "npm"
          },
          {
            "name": "@types/chai",
            "direct": false,
            "version": "5.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "@types/deep-eql",
            "direct": false,
            "version": "4.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@types/esrecurse",
            "direct": false,
            "version": "4.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "@types/estree",
            "direct": false,
            "version": "1.0.9",
            "ecosystem": "npm"
          },
          {
            "name": "@types/json-schema",
            "direct": false,
            "version": "7.0.15",
            "ecosystem": "npm"
          },
          {
            "name": "@types/node",
            "direct": false,
            "version": "22.19.19",
            "ecosystem": "npm"
          },
          {
            "name": "@types/node",
            "direct": false,
            "version": "25.9.5",
            "ecosystem": "npm"
          },
          {
            "name": "@types/node",
            "direct": false,
            "version": "26.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "@types/retry",
            "direct": false,
            "version": "0.12.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/eslint-plugin",
            "direct": false,
            "version": "8.65.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/parser",
            "direct": false,
            "version": "8.65.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/project-service",
            "direct": false,
            "version": "8.65.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/scope-manager",
            "direct": false,
            "version": "8.65.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/tsconfig-utils",
            "direct": false,
            "version": "8.65.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/type-utils",
            "direct": false,
            "version": "8.65.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/types",
            "direct": false,
            "version": "8.65.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/typescript-estree",
            "direct": false,
            "version": "8.65.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/utils",
            "direct": false,
            "version": "8.65.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/visitor-keys",
            "direct": false,
            "version": "8.65.0",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/coverage-v8",
            "direct": false,
            "version": "4.1.10",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/expect",
            "direct": false,
            "version": "4.1.10",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/mocker",
            "direct": false,
            "version": "4.1.10",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/pretty-format",
            "direct": false,
            "version": "4.1.10",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/runner",
            "direct": false,
            "version": "4.1.10",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/snapshot",
            "direct": false,
            "version": "4.1.10",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/spy",
            "direct": false,
            "version": "4.1.10",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/utils",
            "direct": false,
            "version": "4.1.10",
            "ecosystem": "npm"
          },
          {
            "name": "accepts",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "acorn",
            "direct": false,
            "version": "8.17.0",
            "ecosystem": "npm"
          },
          {
            "name": "acorn-jsx",
            "direct": false,
            "version": "5.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "agent-base",
            "direct": false,
            "version": "7.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "ajv",
            "direct": false,
            "version": "6.15.0",
            "ecosystem": "npm"
          },
          {
            "name": "ajv",
            "direct": false,
            "version": "8.20.0",
            "ecosystem": "npm"
          },
          {
            "name": "ajv-formats",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-regex",
            "direct": false,
            "version": "6.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "apache-arrow",
            "direct": false,
            "version": "21.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "assertion-error",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "ast-v8-to-istanbul",
            "direct": false,
            "version": "1.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "balanced-match",
            "direct": false,
            "version": "4.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "base64-js",
            "direct": false,
            "version": "1.5.1",
            "ecosystem": "npm"
          },
          {
            "name": "bcrypt",
            "direct": false,
            "version": "^5.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "bignumber.js",
            "direct": false,
            "version": "9.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "body-parser",
            "direct": false,
            "version": "2.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "boolean",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "bowser",
            "direct": false,
            "version": "2.14.1",
            "ecosystem": "npm"
          },
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "5.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "5.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "buffer-equal-constant-time",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "bytes",
            "direct": false,
            "version": "3.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "call-bind-apply-helpers",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "call-bound",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "chai",
            "direct": false,
            "version": "6.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "chardet",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "chownr",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "cli-cursor",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "cli-spinners",
            "direct": false,
            "version": "2.9.2",
            "ecosystem": "npm"
          },
          {
            "name": "cli-width",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "content-disposition",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "content-type",
            "direct": false,
            "version": "1.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "content-type",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "convert-source-map",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "cookie",
            "direct": false,
            "version": "0.7.2",
            "ecosystem": "npm"
          },
          {
            "name": "cookie-signature",
            "direct": false,
            "version": "1.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "cors",
            "direct": false,
            "version": "2.8.6",
            "ecosystem": "npm"
          },
          {
            "name": "cross-spawn",
            "direct": false,
            "version": "7.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "data-uri-to-buffer",
            "direct": false,
            "version": "4.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "debug",
            "direct": false,
            "version": "4.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "deep-is",
            "direct": false,
            "version": "0.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "define-data-property",
            "direct": false,
            "version": "1.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "define-properties",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "depd",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "detect-libc",
            "direct": false,
            "version": "2.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "detect-node",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "diff",
            "direct": false,
            "version": "8.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "dunder-proto",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "ecdsa-sig-formatter",
            "direct": false,
            "version": "1.0.11",
            "ecosystem": "npm"
          },
          {
            "name": "ee-first",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "emoji-regex",
            "direct": false,
            "version": "10.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "encodeurl",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "es-define-property",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "es-errors",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "es-module-lexer",
            "direct": false,
            "version": "2.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "es-object-atoms",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "es6-error",
            "direct": false,
            "version": "4.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "esbuild",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "escape-html",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "escape-string-regexp",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "eslint",
            "direct": false,
            "version": "10.8.0",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-scope",
            "direct": false,
            "version": "9.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-visitor-keys",
            "direct": false,
            "version": "3.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-visitor-keys",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "espree",
            "direct": false,
            "version": "11.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "esquery",
            "direct": false,
            "version": "1.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "esrecurse",
            "direct": false,
            "version": "4.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "estraverse",
            "direct": false,
            "version": "5.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "estree-walker",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "esutils",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "etag",
            "direct": false,
            "version": "1.8.1",
            "ecosystem": "npm"
          },
          {
            "name": "eventsource",
            "direct": false,
            "version": "3.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "eventsource-parser",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "expect-type",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "express",
            "direct": false,
            "version": "5.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "express",
            "direct": false,
            "version": "^4.18.2",
            "ecosystem": "npm"
          },
          {
            "name": "express-rate-limit",
            "direct": false,
            "version": "8.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "extend",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "fast-deep-equal",
            "direct": false,
            "version": "3.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "fast-json-stable-stringify",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "fast-levenshtein",
            "direct": false,
            "version": "2.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "fast-string-truncated-width",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "fast-string-width",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "fast-uri",
            "direct": false,
            "version": "3.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "fast-wrap-ansi",
            "direct": false,
            "version": "0.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "fast-xml-builder",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "fast-xml-parser",
            "direct": false,
            "version": "5.7.3",
            "ecosystem": "npm"
          },
          {
            "name": "fdir",
            "direct": false,
            "version": "6.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "fetch-blob",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "file-entry-cache",
            "direct": false,
            "version": "8.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "finalhandler",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "find-up",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "flat-cache",
            "direct": false,
            "version": "4.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "flatbuffers",
            "direct": false,
            "version": "25.9.23",
            "ecosystem": "npm"
          },
          {
            "name": "flatted",
            "direct": false,
            "version": "3.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "formdata-polyfill",
            "direct": false,
            "version": "4.0.10",
            "ecosystem": "npm"
          },
          {
            "name": "forwarded",
            "direct": false,
            "version": "0.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "fresh",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "fsevents",
            "direct": false,
            "version": "2.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "function-bind",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "gaxios",
            "direct": false,
            "version": "7.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "gaxios",
            "direct": false,
            "version": "7.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "gcp-metadata",
            "direct": false,
            "version": "8.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "get-east-asian-width",
            "direct": false,
            "version": "1.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "get-intrinsic",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "get-proto",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "glob-parent",
            "direct": false,
            "version": "6.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "glob-to-regex.js",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "global-agent",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "globals",
            "direct": false,
            "version": "17.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "globalthis",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "google-auth-library",
            "direct": false,
            "version": "10.6.2",
            "ecosystem": "npm"
          },
          {
            "name": "google-auth-library",
            "direct": false,
            "version": "10.9.1",
            "ecosystem": "npm"
          },
          {
            "name": "google-logging-utils",
            "direct": false,
            "version": "1.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "gopd",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "graceful-fs",
            "direct": false,
            "version": "4.2.11",
            "ecosystem": "npm"
          },
          {
            "name": "guid-typescript",
            "direct": false,
            "version": "1.0.9",
            "ecosystem": "npm"
          },
          {
            "name": "has-flag",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "has-property-descriptors",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "has-symbols",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "hasown",
            "direct": false,
            "version": "2.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "highlight.js",
            "direct": false,
            "version": "10.7.3",
            "ecosystem": "npm"
          },
          {
            "name": "hono",
            "direct": false,
            "version": "4.12.32",
            "ecosystem": "npm"
          },
          {
            "name": "hosted-git-info",
            "direct": false,
            "version": "9.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "html-escaper",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "http-errors",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "http-proxy-agent",
            "direct": false,
            "version": "7.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "https-proxy-agent",
            "direct": false,
            "version": "7.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "hyperdyperid",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "iconv-lite",
            "direct": false,
            "version": "0.7.3",
            "ecosystem": "npm"
          },
          {
            "name": "imurmurhash",
            "direct": false,
            "version": "0.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "inherits",
            "direct": false,
            "version": "2.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "ip-address",
            "direct": false,
            "version": "10.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "ipaddr.js",
            "direct": false,
            "version": "1.9.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-extglob",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-glob",
            "direct": false,
            "version": "4.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "is-interactive",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-promise",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-unicode-supported",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-unicode-supported",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "isexe",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-lib-coverage",
            "direct": false,
            "version": "3.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-lib-report",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-reports",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "jiti",
            "direct": false,
            "version": "2.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jose",
            "direct": false,
            "version": "6.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "js-tokens",
            "direct": false,
            "version": "10.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "json-bigint",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "json-buffer",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "json-schema-to-ts",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "json-schema-traverse",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "json-schema-traverse",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "json-schema-typed",
            "direct": false,
            "version": "8.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "json-stable-stringify-without-jsonify",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "json-stringify-safe",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "json-with-bigint",
            "direct": false,
            "version": "3.5.10",
            "ecosystem": "npm"
          },
          {
            "name": "jsonwebtoken",
            "direct": false,
            "version": "^9.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "jwa",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "jws",
            "direct": false,
            "version": "4.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "keyv",
            "direct": false,
            "version": "4.5.4",
            "ecosystem": "npm"
          },
          {
            "name": "levn",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss",
            "direct": false,
            "version": "1.33.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-android-arm64",
            "direct": false,
            "version": "1.33.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-darwin-arm64",
            "direct": false,
            "version": "1.33.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-darwin-x64",
            "direct": false,
            "version": "1.33.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-freebsd-x64",
            "direct": false,
            "version": "1.33.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-linux-arm-gnueabihf",
            "direct": false,
            "version": "1.33.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-linux-arm64-gnu",
            "direct": false,
            "version": "1.33.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-linux-arm64-musl",
            "direct": false,
            "version": "1.33.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-linux-x64-gnu",
            "direct": false,
            "version": "1.33.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-linux-x64-musl",
            "direct": false,
            "version": "1.33.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-win32-arm64-msvc",
            "direct": false,
            "version": "1.33.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-win32-x64-msvc",
            "direct": false,
            "version": "1.33.0",
            "ecosystem": "npm"
          },
          {
            "name": "locate-path",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "log-symbols",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "long",
            "direct": false,
            "version": "5.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "lru-cache",
            "direct": false,
            "version": "11.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "lru-cache",
            "direct": false,
            "version": "11.5.2",
            "ecosystem": "npm"
          },
          {
            "name": "magic-string",
            "direct": false,
            "version": "0.30.21",
            "ecosystem": "npm"
          },
          {
            "name": "magicast",
            "direct": false,
            "version": "0.5.3",
            "ecosystem": "npm"
          },
          {
            "name": "make-dir",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "marked",
            "direct": false,
            "version": "18.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "matcher",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "math-intrinsics",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "media-typer",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "memfs",
            "direct": false,
            "version": "4.64.0",
            "ecosystem": "npm"
          },
          {
            "name": "merge-descriptors",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "mime-db",
            "direct": false,
            "version": "1.54.0",
            "ecosystem": "npm"
          },
          {
            "name": "mime-types",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "mimic-function",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "minimatch",
            "direct": false,
            "version": "10.2.5",
            "ecosystem": "npm"
          },
          {
            "name": "minipass",
            "direct": false,
            "version": "7.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "minizlib",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "ms",
            "direct": false,
            "version": "2.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "mute-stream",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "nanoid",
            "direct": false,
            "version": "3.3.16",
            "ecosystem": "npm"
          },
          {
            "name": "natural-compare",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "negotiator",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "node-addon-api",
            "direct": false,
            "version": "7.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "node-addon-api",
            "direct": false,
            "version": "8.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "node-domexception",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "node-fetch",
            "direct": false,
            "version": "3.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "node-gyp-build",
            "direct": false,
            "version": "4.8.4",
            "ecosystem": "npm"
          },
          {
            "name": "object-assign",
            "direct": false,
            "version": "4.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "object-inspect",
            "direct": false,
            "version": "1.13.4",
            "ecosystem": "npm"
          },
          {
            "name": "object-keys",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "obug",
            "direct": false,
            "version": "2.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "on-finished",
            "direct": false,
            "version": "2.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "once",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "onetime",
            "direct": false,
            "version": "7.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "onnxruntime-common",
            "direct": false,
            "version": "1.21.0",
            "ecosystem": "npm"
          },
          {
            "name": "onnxruntime-common",
            "direct": false,
            "version": "1.22.0-dev.20250409-89f8206ba4",
            "ecosystem": "npm"
          },
          {
            "name": "onnxruntime-node",
            "direct": false,
            "version": "1.21.0",
            "ecosystem": "npm"
          },
          {
            "name": "onnxruntime-web",
            "direct": false,
            "version": "1.22.0-dev.20250409-89f8206ba4",
            "ecosystem": "npm"
          },
          {
            "name": "openai",
            "direct": false,
            "version": "6.26.0",
            "ecosystem": "npm"
          },
          {
            "name": "optionator",
            "direct": false,
            "version": "0.9.4",
            "ecosystem": "npm"
          },
          {
            "name": "p-limit",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "p-locate",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "p-retry",
            "direct": false,
            "version": "4.6.2",
            "ecosystem": "npm"
          },
          {
            "name": "parseurl",
            "direct": false,
            "version": "1.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "partial-json",
            "direct": false,
            "version": "0.1.7",
            "ecosystem": "npm"
          },
          {
            "name": "path-exists",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "path-expression-matcher",
            "direct": false,
            "version": "1.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "path-key",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "path-scurry",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "path-to-regexp",
            "direct": false,
            "version": "8.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "pathe",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "pg",
            "direct": false,
            "version": "^8.11.0",
            "ecosystem": "npm"
          },
          {
            "name": "picocolors",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "picomatch",
            "direct": false,
            "version": "4.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "pkce-challenge",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "platform",
            "direct": false,
            "version": "1.3.6",
            "ecosystem": "npm"
          },
          {
            "name": "postcss",
            "direct": false,
            "version": "8.5.23",
            "ecosystem": "npm"
          },
          {
            "name": "prelude-ls",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "proper-lockfile",
            "direct": false,
            "version": "4.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "protobufjs",
            "direct": false,
            "version": "7.6.5",
            "ecosystem": "npm"
          },
          {
            "name": "protobufjs",
            "direct": false,
            "version": "8.7.1",
            "ecosystem": "npm"
          },
          {
            "name": "proxy-addr",
            "direct": false,
            "version": "2.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "punycode",
            "direct": false,
            "version": "2.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "qs",
            "direct": false,
            "version": "6.15.3",
            "ecosystem": "npm"
          },
          {
            "name": "range-parser",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "raw-body",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "readdirp",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "reflect-metadata",
            "direct": false,
            "version": "0.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "require-from-string",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "restore-cursor",
            "direct": false,
            "version": "5.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "retry",
            "direct": false,
            "version": "0.12.0",
            "ecosystem": "npm"
          },
          {
            "name": "retry",
            "direct": false,
            "version": "0.13.1",
            "ecosystem": "npm"
          },
          {
            "name": "roarr",
            "direct": false,
            "version": "2.15.4",
            "ecosystem": "npm"
          },
          {
            "name": "rolldown",
            "direct": false,
            "version": "1.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "router",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "safe-buffer",
            "direct": false,
            "version": "5.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "safer-buffer",
            "direct": false,
            "version": "2.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "scheduler",
            "direct": false,
            "version": "0.27.0",
            "ecosystem": "npm"
          },
          {
            "name": "semver",
            "direct": false,
            "version": "7.8.0",
            "ecosystem": "npm"
          },
          {
            "name": "semver",
            "direct": false,
            "version": "7.8.5",
            "ecosystem": "npm"
          },
          {
            "name": "semver-compare",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "send",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "serialize-error",
            "direct": false,
            "version": "7.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "serve-static",
            "direct": false,
            "version": "2.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "setprototypeof",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "sharp",
            "direct": false,
            "version": "0.35.3",
            "ecosystem": "npm"
          },
          {
            "name": "shebang-command",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "shebang-regex",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "side-channel",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "side-channel-list",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "side-channel-map",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "side-channel-weakmap",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "siginfo",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "signal-exit",
            "direct": false,
            "version": "3.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "signal-exit",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "source-map-js",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "sprintf-js",
            "direct": false,
            "version": "1.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "stackback",
            "direct": false,
            "version": "0.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "statuses",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "std-env",
            "direct": false,
            "version": "4.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "stdin-discarder",
            "direct": false,
            "version": "0.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "string-width",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "strip-ansi",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "strnum",
            "direct": false,
            "version": "2.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "supports-color",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "tar",
            "direct": false,
            "version": "7.5.22",
            "ecosystem": "npm"
          },
          {
            "name": "thingies",
            "direct": false,
            "version": "2.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "tinybench",
            "direct": false,
            "version": "2.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "tinyexec",
            "direct": false,
            "version": "1.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "tinyglobby",
            "direct": false,
            "version": "0.2.17",
            "ecosystem": "npm"
          },
          {
            "name": "tinyrainbow",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "toidentifier",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "tree-dump",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "tree-sitter",
            "direct": false,
            "version": "0.22.4",
            "ecosystem": "npm"
          },
          {
            "name": "tree-sitter-bash",
            "direct": false,
            "version": "0.23.3",
            "ecosystem": "npm"
          },
          {
            "name": "tree-sitter-c",
            "direct": false,
            "version": "0.23.6",
            "ecosystem": "npm"
          },
          {
            "name": "tree-sitter-c-sharp",
            "direct": false,
            "version": "0.21.3",
            "ecosystem": "npm"
          },
          {
            "name": "tree-sitter-cpp",
            "direct": false,
            "version": "0.23.4",
            "ecosystem": "npm"
          },
          {
            "name": "tree-sitter-elixir",
            "direct": false,
            "version": "0.3.5",
            "ecosystem": "npm"
          },
          {
            "name": "tree-sitter-go",
            "direct": false,
            "version": "0.23.4",
            "ecosystem": "npm"
          },
          {
            "name": "tree-sitter-java",
            "direct": false,
            "version": "0.23.5",
            "ecosystem": "npm"
          },
          {
            "name": "tree-sitter-javascript",
            "direct": false,
            "version": "0.23.1",
            "ecosystem": "npm"
          },
          {
            "name": "tree-sitter-kotlin",
            "direct": false,
            "version": "0.3.8",
            "ecosystem": "npm"
          },
          {
            "name": "tree-sitter-php",
            "direct": false,
            "version": "0.23.12",
            "ecosystem": "npm"
          },
          {
            "name": "tree-sitter-python",
            "direct": false,
            "version": "0.23.6",
            "ecosystem": "npm"
          },
          {
            "name": "tree-sitter-ruby",
            "direct": false,
            "version": "0.23.1",
            "ecosystem": "npm"
          },
          {
            "name": "tree-sitter-rust",
            "direct": false,
            "version": "0.24.0",
            "ecosystem": "npm"
          },
          {
            "name": "tree-sitter-scala",
            "direct": false,
            "version": "0.24.0",
            "ecosystem": "npm"
          },
          {
            "name": "tree-sitter-swift",
            "direct": false,
            "version": "0.7.1",
            "ecosystem": "npm"
          },
          {
            "name": "tree-sitter-typescript",
            "direct": false,
            "version": "0.23.2",
            "ecosystem": "npm"
          },
          {
            "name": "ts-algebra",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "ts-api-utils",
            "direct": false,
            "version": "2.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "tslib",
            "direct": false,
            "version": "2.8.1",
            "ecosystem": "npm"
          },
          {
            "name": "tsx",
            "direct": false,
            "version": "4.23.1",
            "ecosystem": "npm"
          },
          {
            "name": "type-check",
            "direct": false,
            "version": "0.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "type-fest",
            "direct": false,
            "version": "0.13.1",
            "ecosystem": "npm"
          },
          {
            "name": "type-is",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "typebox",
            "direct": false,
            "version": "1.1.38",
            "ecosystem": "npm"
          },
          {
            "name": "typebox",
            "direct": false,
            "version": "1.3.8",
            "ecosystem": "npm"
          },
          {
            "name": "typescript",
            "direct": false,
            "version": "5.9.3",
            "ecosystem": "npm"
          },
          {
            "name": "typescript",
            "direct": false,
            "version": "^5.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "typescript-eslint",
            "direct": false,
            "version": "8.65.0",
            "ecosystem": "npm"
          },
          {
            "name": "undici",
            "direct": false,
            "version": "8.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "undici-types",
            "direct": false,
            "version": "6.21.0",
            "ecosystem": "npm"
          },
          {
            "name": "undici-types",
            "direct": false,
            "version": "7.24.6",
            "ecosystem": "npm"
          },
          {
            "name": "undici-types",
            "direct": false,
            "version": "8.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "unpipe",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "uri-js",
            "direct": false,
            "version": "4.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "vary",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "vitest",
            "direct": false,
            "version": "4.1.10",
            "ecosystem": "npm"
          },
          {
            "name": "vitest",
            "direct": false,
            "version": "^4.1.8",
            "ecosystem": "npm"
          },
          {
            "name": "web-streams-polyfill",
            "direct": false,
            "version": "3.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "which",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "why-is-node-running",
            "direct": false,
            "version": "2.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "word-wrap",
            "direct": false,
            "version": "1.2.5",
            "ecosystem": "npm"
          },
          {
            "name": "wrappy",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "ws",
            "direct": false,
            "version": "8.21.0",
            "ecosystem": "npm"
          },
          {
            "name": "ws",
            "direct": false,
            "version": "8.21.1",
            "ecosystem": "npm"
          },
          {
            "name": "xml-naming",
            "direct": false,
            "version": "0.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "yallist",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "yocto-queue",
            "direct": false,
            "version": "0.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "zod",
            "direct": false,
            "version": "3.25.76",
            "ecosystem": "npm"
          },
          {
            "name": "zod",
            "direct": false,
            "version": "4.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "zod-to-json-schema",
            "direct": false,
            "version": "3.25.2",
            "ecosystem": "npm"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 626,
        "direct_count": 19,
        "indirect_count": 607
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 1,
        "merged_prs": 254,
        "open_issues": 0,
        "closed_ratio": 1,
        "closed_issues": 17,
        "closed_unmerged_prs": 11
      },
      "bus_factor": 2,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "clay-good",
          "commits": 623,
          "avatar_url": "https://avatars.githubusercontent.com/u/237345393?v=4"
        },
        {
          "type": "User",
          "login": "laurentftech",
          "commits": 541,
          "avatar_url": "https://avatars.githubusercontent.com/u/44120190?v=4"
        },
        {
          "type": "User",
          "login": "claude",
          "commits": 72,
          "avatar_url": "https://avatars.githubusercontent.com/u/81847?v=4"
        },
        {
          "type": "User",
          "login": "mipmip",
          "commits": 5,
          "avatar_url": "https://avatars.githubusercontent.com/u/658612?v=4"
        },
        {
          "type": "User",
          "login": "Caspersonn",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/96787412?v=4"
        },
        {
          "type": "User",
          "login": "mhv2109",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/14115762?v=4"
        },
        {
          "type": "User",
          "login": "zoroneo",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/208247780?v=4"
        },
        {
          "type": "User",
          "login": "Wars",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/1128707?v=4"
        },
        {
          "type": "User",
          "login": "rzylim",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/19969292?v=4"
        },
        {
          "type": "User",
          "login": "zkolobov",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/4434702?v=4"
        }
      ],
      "contributors_sampled": 10,
      "top_contributor_share": 0.5
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "codeql.yml",
        "release.yml",
        "scorecard.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        "eslint.config.js"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 3,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 8,
            "reason": "26 out of 29 merged PRs checked by a CI test -- score normalized to 8",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 1/18 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 9 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 4 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 6,
            "reason": "dependency not pinned by hash detected -- score normalized to 6",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 8,
            "reason": "SAST tool detected but not run on all commits",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 10,
            "reason": "GitHub workflow tokens follow principle of least privilege",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 9,
            "reason": "1 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "3f81d3211de524ac5c100bc99eb2cb14beb1d0f3",
        "ran_at": "2026-07-25T23:11:11Z",
        "aggregate_score": 7.5,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": true,
      "has_security_policy": true,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-25T22:25:57Z",
      "oldest_open_prs": [
        {
          "number": 288,
          "created_at": "2026-07-25T22:55:07Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-25T22:25:14Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/clay-good/OpenLore",
    "host": "github.com",
    "name": "OpenLore",
    "owner": "clay-good"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "good",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 78,
      "inputs": {
        "security": 77,
        "vitality": 88,
        "community": 68,
        "governance": 69,
        "engineering": 88
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 88,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "commits_last_year": 1437,
              "human_commit_share": 0.88,
              "days_since_last_push": 0,
              "active_weeks_last_year": 23
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "23/52 weeks with commits",
                "points": 15.9,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 23
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "1437 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 1437
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 4 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 43,
              "latest_release_tag": "v2.1.6",
              "releases_from_tags": false,
              "days_since_latest_release": 6,
              "mean_days_between_releases": 4.2
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "43 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 43
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 6 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~4.2 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 4.2
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 68,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "moderate",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 52,
            "inputs": {
              "forks": 31,
              "stars": 207,
              "watchers": 3,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "207 stars",
                "points": 37.5,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 207
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "31 forks",
                "points": 12.3,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 31
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "3 watchers",
                "points": 1.7,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 59,
            "inputs": {
              "packages": [
                "openlore"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 3645
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "3,645 downloads/month across npm",
                "points": 47.5,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 3645,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 69,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "moderate",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "bus_factor": 2,
              "contributors_sampled": 10,
              "top_contributor_share": 0.5
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "2 contributor(s) cover half of all commits",
                "points": 25.2,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 50% of commits",
                "points": 11.2,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 50
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "10 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 10
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 9 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "merged_prs": 254,
              "open_issues": 0,
              "closed_issues": 17,
              "issue_closed_ratio": 1,
              "closed_unmerged_prs": 11
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "100% of issues closed",
                "points": 46.8,
                "status": "met",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "254/265 decided PRs merged",
                "points": 36.7,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 254,
                      "decided": 265
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 1/18 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 41,
            "inputs": {
              "followers": 19,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "clay-good",
              "public_repos": 39,
              "account_age_days": 287
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "19 followers of clay-good",
                "points": 9.4,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 19,
                      "login": "clay-good"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "39 public repos, account ~0 yr old",
                "points": 13.2,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 39
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "openlore"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 6
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 6 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "27 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 27
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "excellent",
        "name": "Engineering Quality",
        "value": 88,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "4 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": "eslint.config.js",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.js"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "26 out of 29 merged PRs checked by a CI test -- score normalized to 8",
                "points": 16,
                "status": "partial",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "topics": [
                "developer-tools",
                "software-architecture",
                "static-analysis",
                "adr",
                "agentic-workflows",
                "ai-agents",
                "call-graph",
                "codebase-analysis",
                "knowledge-graph",
                "living-documentation",
                "llm-tools",
                "mcp-server",
                "model-context-protocol",
                "code-navigation",
                "coding-agents",
                "dead-code-detection",
                "infrastructure-as-code",
                "scip",
                "test-impact-analysis",
                "tree-sitter"
              ],
              "has_wiki": true,
              "homepage": "https://www.npmjs.com/package/openlore",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://www.npmjs.com/package/openlore",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "20 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 20
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "good",
        "name": "Security",
        "value": 77,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "good",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 75,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 7.5
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "26 out of 29 merged PRs checked by a CI test -- score normalized to 8",
                "points": 2,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 1/18 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 9 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 4 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 6",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool detected but not run on all commits",
                "points": 4,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "GitHub workflow tokens follow principle of least privilege",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "1 existing vulnerabilities detected",
                "points": 6.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "good",
            "name": "Dependency advisories",
            "note": "Matched the npm:openlore@2.1.6 runtime dependency closure — what installing the published package pulls in — 361 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:openlore@2.1.6",
                  "assessed": 361
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 84,
            "inputs": {
              "source": "osv",
              "advisories": 2,
              "affected_packages": 2,
              "assessed_packages": 361,
              "unassessed_packages": 0,
              "affected_by_severity": "high 1, moderate 1",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "2 affected: sharp 0.34.5 (high 7.3), @hono/node-server 1.19.15 (moderate 5.9)",
                "points": 9.1,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 2,
                      "packages": "sharp 0.34.5 (high 7.3), @hono/node-server 1.19.15 (moderate 5.9)"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory has been public longer than 90 days",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "advisories_none_stale",
                    "params": {
                      "days": 90
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 361,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 4
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "excellent",
        "name": "AI Readiness",
        "value": 87,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.989,
              "agent_instruction_files": [
                "AGENTS.md",
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 25853
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "AGENTS.md, CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "AGENTS.md, CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "87 of 88 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 87,
                      "sampled": 88
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 78,
            "inputs": {
              "has_nix": true,
              "has_tests": true,
              "lockfiles": [
                "package-lock.json"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "examples/drift-demo/tsconfig.json",
                "tsconfig.json"
              ],
              "agent_commit_share": 0.86,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0.12
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": "eslint.config.js",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.js"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "examples/drift-demo/tsconfig.json, tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples/drift-demo/tsconfig.json, tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, Nix, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, Nix, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "86 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 86,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "12 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 12,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 6",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 99,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 228745,
              "source_files_sampled": 757,
              "oversized_source_files": 15
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "15/757 source files over 60KB",
                "points": 53.9,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 757,
                      "oversized": 15
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "excellent",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": true,
              "api_schema_files": [
                "src/core/scip/vendor/scip.proto"
              ]
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": "src/core/scip/vendor/scip.proto",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "src/core/scip/vendor/scip.proto"
                    }
                  }
                ],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-25T23:11:31.120671Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/c/clay-good/OpenLore.svg",
  "full_name": "clay-good/OpenLore",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsnpm.