Public record
Software health reportschema 0.27.0 · metrics 1.13.0 · 2026-07-27 15:29 UTC

ehrlich-b / wingthing

Sandboxed AI agents, reachable from anywhere

Go · JavaScriptMIT★ 49 stars⑂ 5 forkssince Jul 2025View on GitHub ↗

ehrlich-b/wingthing holds a health index of 59 out of 100, placing it in the Moderate band. It scores highest on Vitality (79/100) and lowest on Security (34/100). It was last updated 2 days ago. A single contributor accounts for most of its recent work.

59
overall / 100
Moderate

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

59
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

Bryan EhrlichPersonal account
14 followers56 public repossince Jan 2011

This repository is owned by a personal account. A single-owner project carries more continuity risk than an organization-backed one.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publish
Gogithub.com/ehrlich-b/wingthingv0.140.0-29510 days ago

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

79Good · 22% of overall
How it's scored
36/36Push recency — last push 2 days ago
9/36Commit cadence — 13/52 weeks with commits
18/18Commit volume — 592 commits in the last year
8/10OpenSSF Scorecard: Maintained — 10 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 8
Inputs used
commits_last_year592
human_commit_share1
days_since_last_push2
active_weeks_last_year13
How it's scored
27/27Ships releases — 100 releases published
36/36Release recency — latest release 10 days ago
27/27Release cadence — a release every ~13.9 days
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Inputs used
releases_count100
latest_release_tagv0.140.0
releases_from_tagsno
days_since_latest_release10
mean_days_between_releases13.9

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

40At risk · 18% of overall
How it's scored
27.3/60Stars — 49 stars
5/25Forks — 5 forks
0/15Watchers — 1 watchers
Inputs used
forks5
stars49
watchers1
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (MIT)
0/18CONTRIBUTING guide
0/13.5Code of conduct
0/7.2Issue template
0/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingno
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

58Moderate · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
0/22.5Commit distribution — top contributor authored 100% of commits
1.4/13.5Contributor breadth — 1 contributors
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Inputs used
bus_factor1
contributors_sampled1
top_contributor_share1
How it's scored
46.8/46.8Issue resolution — 100% of issues closed
38.2/38.3PR acceptance — 1/1 decided PRs merged
0/15OpenSSF Scorecard: Code-Review — Found 0/25 approved changesets -- score normalized to 0
Inputs used
merged_prs1
open_issues0
closed_issues1
issue_closed_ratio1
closed_unmerged_prs0
How it's scored
10/30Ownership backing — personal (user) account
0/20Verified domain — not applicable to user accounts
8.5/25Owner reach — 14 followers of ehrlich-b
24.8/25Track record — 56 public repos, account ~15 yr old
Inputs used
followers14
owner_typeUser
is_verified
owner_loginehrlich-b
public_repos56
account_age_days5,661
Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.
How it's scored
25/25Published & resolvable — 1 package(s) on go
35/35Publish recency — latest publish 10 days ago
20/20Version history — 295 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packagesgithub.com/ehrlich-b/wingthing
ecosystemsgo
any_deprecatedno
min_days_since_publish10

Engineering Quality

Are baseline engineering and documentation practices in place?

77Good · 20% of overall
How it's scored
24/24CI workflows — 2 workflow(s)
24/24Tests present
0/16Linter config
0/9.6Pre-commit hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 1 out of 1 merged PRs checked by a CI test -- score normalized to 10
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configno
has_precommit_configno

Documentation

90Excellent
How it's scored
30/30README
25/25Documentation directory
15/15Documentation / homepage site — https://wingthing.ai
10/10Repository description
0/10Topics
10/10Wiki
Inputs used
topics
has_wikiyes
homepagehttps://wingthing.ai
has_readmeyes
has_docs_diryes
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

34At risk · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
2.5/2.5CI-Tests — 1 out of 1 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/25 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
6/7.5Maintained — 10 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 8
0/5Packaging — no data
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 37 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate3.4
Excluded from scoring (no data or not applicable): packaging. Remaining weights renormalized.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

59Moderate · 0% of overall
How it's scored
45/45Agent instructions — CLAUDE.md
0/15Machine-readable docs (llms.txt)
0.5/40Legible commit history — 1 of 100 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share0.01
agent_instruction_filesCLAUDE.md
agent_instruction_max_bytes17,359
How it's scored
18/18One-command bootstrap — Makefile
22/22Automated tests
0/11Lint / format config
11/11Static type checking — Go (statically typed)
10/10Reproducible environment — devcontainer, Dockerfile, lockfile
0/10Demonstrated agent practice — no agent-authored commits among the last 100
0/8Automated maintenance — no automated dependency updates observed
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Inputs used
has_nixno
has_testsyes
lockfilesgo.sum, package-lock.json
has_dockerfileyes
typed_languageyes
bootstrap_filesMakefile
has_devcontaineryes
has_linter_configno
typecheck_configs
agent_commit_share0
toolchain_manifestsgo.mod
dependency_bot_commit_share0
How it's scored
45/45Type-checkable code — Go (statically typed)
54.5/55Manageable file sizes — 2/209 source files over 60KB
Inputs used
primary_languageGo
largest_source_bytes143,891
source_files_sampled209
oversized_source_files2
How it's scored
40/40API schema (OpenAPI/GraphQL/proto) — proto/egg.proto
0/20MCP server
0/40Runnable examples
Inputs used
example_dirs
has_mcp_signalno
api_schema_filesproto/egg.proto

Key facts

49GitHub stars
1contributors
592commits, last 12 months
2days since last push
100releases
1bus factor
0open issues
Go, npmpackage ecosystems

Data collection warnings

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

More detail

Star and fork history 0 ★ / 5 ⇿
0Stars
5Forks
40Releases

When each star and fork was added, collected from GitHub and bucketed by day. Cumulative growth sits directly above the daily additions it is made of, so the two read against each other: steady organic accretion looks nothing like an abrupt, short-lived burst. Where that difference is measurable, it is reported as growth authenticity.

12345512026-022026-032026-04
Major 0Minor 38Patch 2
OpenSSF Scorecard 3.4 / 10
3.4aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-27 15:28 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
10CI-Tests1 out of 1 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/25 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
8Maintained10 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 8
n/aPackagingpackaging workflow not detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
10Security-Policysecurity policy file detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities37 existing vulnerabilities detected
Direct dependencies 26
RegistryPackageVersion constraintManifest
Gogithub.com/charmbracelet/ultravioletv0.0.0-20251106193841-7889546fc720go.mod
Gogithub.com/charmbracelet/x/vtv0.0.0-00010101000000-000000000000go.mod
Gogithub.com/fsnotify/fsnotifyv1.9.0go.mod
Gogithub.com/google/uuidv1.6.0go.mod
Gogithub.com/pion/webrtc/v4v4.2.9go.mod
Gogithub.com/spf13/cobrav1.10.2go.mod
Gogolang.org/x/cryptov0.48.0go.mod
Gogolang.org/x/sysv0.41.0go.mod
Gogopkg.in/yaml.v3v3.0.1go.mod
Gomodernc.org/sqlitev1.44.3go.mod
Gogithub.com/coder/websocketv1.8.14go.mod
Gogithub.com/creack/ptyv1.1.24go.mod
Gogithub.com/go-webauthn/webauthnv0.15.0go.mod
Gogithub.com/golang-jwt/jwt/v5v5.3.1go.mod
Gogolang.org/x/termv0.40.0go.mod
Gogolang.org/x/timev0.14.0go.mod
Gogoogle.golang.org/grpcv1.78.0go.mod
Gogoogle.golang.org/protobufv1.36.11go.mod
npm@nlux/core^2.17.1web/package.json
npm@nlux/themes^2.17.1web/package.json
npm@noble/ciphers^2.1.1web/package.json
npm@noble/curves^2.0.1web/package.json
npm@xterm/addon-fit^0.11.0web/package.json
npm@xterm/addon-serialize^0.14.0web/package.json
npm@xterm/xterm^6.0.0web/package.json
npmmarked^15.0.0web/package.json
All dependencies not collected

The resolved dependency set could not be collected for this report: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 3693,
      "has_wiki": true,
      "homepage": "https://wingthing.ai",
      "languages": {
        "Go": 1350922,
        "CSS": 47876,
        "HTML": 88036,
        "Shell": 2596,
        "Makefile": 2968,
        "Dockerfile": 1610,
        "JavaScript": 330002
      },
      "pushed_at": "2026-07-25T01:04:08Z",
      "created_at": "2025-07-26T20:22:39Z",
      "owner_type": "User",
      "updated_at": "2026-07-17T14:31:29Z",
      "description": "Sandboxed AI agents, reachable from anywhere",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "Go",
      "significant_languages": [
        "Go",
        "JavaScript"
      ]
    },
    "owner": {
      "blog": null,
      "name": "Bryan Ehrlich",
      "type": "User",
      "login": "ehrlich-b",
      "company": null,
      "location": null,
      "followers": 14,
      "avatar_url": "https://avatars.githubusercontent.com/u/584109?v=4",
      "created_at": "2011-01-26T06:50:46Z",
      "is_verified": null,
      "public_repos": 56,
      "account_age_days": 5661
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.140.0",
          "kind": "minor",
          "published_at": "2026-07-17T14:34:50Z"
        },
        {
          "tag": "v0.139.0",
          "kind": "minor",
          "published_at": "2026-06-21T18:28:45Z"
        },
        {
          "tag": "v0.138.0",
          "kind": "minor",
          "published_at": "2026-06-16T19:09:04Z"
        },
        {
          "tag": "v0.137.0",
          "kind": "minor",
          "published_at": "2026-03-24T20:29:47Z"
        },
        {
          "tag": "v0.136.0",
          "kind": "minor",
          "published_at": "2026-03-19T18:21:15Z"
        },
        {
          "tag": "v0.135.0",
          "kind": "minor",
          "published_at": "2026-03-17T18:38:14Z"
        },
        {
          "tag": "v0.134.0",
          "kind": "minor",
          "published_at": "2026-03-17T18:19:05Z"
        },
        {
          "tag": "v0.133.0",
          "kind": "minor",
          "published_at": "2026-03-16T20:43:54Z"
        },
        {
          "tag": "v0.132.0",
          "kind": "minor",
          "published_at": "2026-03-14T21:16:57Z"
        },
        {
          "tag": "v0.131.0",
          "kind": "minor",
          "published_at": "2026-03-14T20:23:34Z"
        },
        {
          "tag": "v0.130.0",
          "kind": "minor",
          "published_at": "2026-03-12T23:47:39Z"
        },
        {
          "tag": "v0.129.0",
          "kind": "minor",
          "published_at": "2026-03-12T22:06:36Z"
        },
        {
          "tag": "v0.128.0",
          "kind": "minor",
          "published_at": "2026-03-12T20:09:27Z"
        },
        {
          "tag": "v0.127.0",
          "kind": "minor",
          "published_at": "2026-03-11T23:19:02Z"
        },
        {
          "tag": "v0.126.2",
          "kind": "patch",
          "published_at": "2026-03-11T22:56:48Z"
        },
        {
          "tag": "v0.126.1",
          "kind": "patch",
          "published_at": "2026-03-11T22:50:38Z"
        },
        {
          "tag": "v0.126.0",
          "kind": "minor",
          "published_at": "2026-03-11T22:45:40Z"
        },
        {
          "tag": "v0.125.0",
          "kind": "minor",
          "published_at": "2026-03-10T20:31:44Z"
        },
        {
          "tag": "v0.124.0",
          "kind": "minor",
          "published_at": "2026-03-10T20:05:40Z"
        },
        {
          "tag": "v0.123.0",
          "kind": "minor",
          "published_at": "2026-03-10T18:37:09Z"
        },
        {
          "tag": "v0.122.0",
          "kind": "minor",
          "published_at": "2026-03-10T18:01:17Z"
        },
        {
          "tag": "v0.121.0",
          "kind": "minor",
          "published_at": "2026-03-06T01:27:17Z"
        },
        {
          "tag": "v0.120.0",
          "kind": "minor",
          "published_at": "2026-03-05T02:48:03Z"
        },
        {
          "tag": "v0.119.0",
          "kind": "minor",
          "published_at": "2026-03-04T23:14:42Z"
        },
        {
          "tag": "v0.118.0",
          "kind": "minor",
          "published_at": "2026-03-04T15:36:30Z"
        },
        {
          "tag": "v0.117.0",
          "kind": "minor",
          "published_at": "2026-03-04T02:50:47Z"
        },
        {
          "tag": "v0.116.0",
          "kind": "minor",
          "published_at": "2026-03-04T01:15:55Z"
        },
        {
          "tag": "v0.115.0",
          "kind": "minor",
          "published_at": "2026-03-04T00:51:59Z"
        },
        {
          "tag": "v0.114.0",
          "kind": "minor",
          "published_at": "2026-03-04T00:33:55Z"
        },
        {
          "tag": "v0.113.0",
          "kind": "minor",
          "published_at": "2026-02-28T12:55:14Z"
        },
        {
          "tag": "v0.112.0",
          "kind": "minor",
          "published_at": "2026-02-26T16:59:38Z"
        },
        {
          "tag": "v0.111.0",
          "kind": "minor",
          "published_at": "2026-02-26T15:34:48Z"
        },
        {
          "tag": "v0.110.0",
          "kind": "minor",
          "published_at": "2026-02-26T15:05:57Z"
        },
        {
          "tag": "v0.109.0",
          "kind": "minor",
          "published_at": "2026-02-22T18:55:07Z"
        },
        {
          "tag": "v0.108.0",
          "kind": "minor",
          "published_at": "2026-02-22T18:32:02Z"
        },
        {
          "tag": "v0.107.0",
          "kind": "minor",
          "published_at": "2026-02-21T20:47:35Z"
        },
        {
          "tag": "v0.106.0",
          "kind": "minor",
          "published_at": "2026-02-21T14:11:15Z"
        },
        {
          "tag": "v0.105.0",
          "kind": "minor",
          "published_at": "2026-02-20T16:26:53Z"
        },
        {
          "tag": "v0.104.0",
          "kind": "minor",
          "published_at": "2026-02-20T14:53:55Z"
        },
        {
          "tag": "v0.103.0",
          "kind": "minor",
          "published_at": "2026-02-20T03:40:00Z"
        },
        {
          "tag": "v0.102.0",
          "kind": "minor",
          "published_at": "2026-02-20T03:11:35Z"
        },
        {
          "tag": "v0.101.0",
          "kind": "minor",
          "published_at": "2026-02-20T01:36:33Z"
        },
        {
          "tag": "v0.100.0",
          "kind": "minor",
          "published_at": "2026-02-20T00:38:20Z"
        },
        {
          "tag": "v0.99.0",
          "kind": "minor",
          "published_at": "2026-02-19T21:44:35Z"
        },
        {
          "tag": "v0.98.0",
          "kind": "minor",
          "published_at": "2026-02-19T20:07:28Z"
        },
        {
          "tag": "v0.97.0",
          "kind": "minor",
          "published_at": "2026-02-19T19:47:20Z"
        },
        {
          "tag": "v0.96.1",
          "kind": "patch",
          "published_at": "2026-02-19T19:46:50Z"
        },
        {
          "tag": "v0.96.0",
          "kind": "minor",
          "published_at": "2026-02-19T18:15:28Z"
        },
        {
          "tag": "v0.95.2",
          "kind": "patch",
          "published_at": "2026-02-19T18:13:51Z"
        },
        {
          "tag": "v0.95.1",
          "kind": "patch",
          "published_at": "2026-02-19T18:10:12Z"
        },
        {
          "tag": "v0.95.0",
          "kind": "minor",
          "published_at": "2026-02-19T17:19:56Z"
        },
        {
          "tag": "v0.94.0",
          "kind": "minor",
          "published_at": "2026-02-19T17:19:26Z"
        },
        {
          "tag": "v0.93.0",
          "kind": "minor",
          "published_at": "2026-02-19T15:24:32Z"
        },
        {
          "tag": "v0.92.1",
          "kind": "patch",
          "published_at": "2026-02-19T15:12:14Z"
        },
        {
          "tag": "v0.92.0",
          "kind": "minor",
          "published_at": "2026-02-19T14:05:05Z"
        },
        {
          "tag": "v0.91.0",
          "kind": "minor",
          "published_at": "2026-02-19T05:23:02Z"
        },
        {
          "tag": "v0.90.0",
          "kind": "minor",
          "published_at": "2026-02-19T05:04:56Z"
        },
        {
          "tag": "v0.89.0",
          "kind": "minor",
          "published_at": "2026-02-19T05:02:04Z"
        },
        {
          "tag": "v0.88.0",
          "kind": "minor",
          "published_at": "2026-02-19T04:49:40Z"
        },
        {
          "tag": "v0.87.0",
          "kind": "minor",
          "published_at": "2026-02-19T04:41:58Z"
        },
        {
          "tag": "v0.86.0",
          "kind": "minor",
          "published_at": "2026-02-19T04:39:54Z"
        },
        {
          "tag": "v0.85.0",
          "kind": "minor",
          "published_at": "2026-02-19T04:35:48Z"
        },
        {
          "tag": "v0.84.0",
          "kind": "minor",
          "published_at": "2026-02-19T04:29:49Z"
        },
        {
          "tag": "v0.83.0",
          "kind": "minor",
          "published_at": "2026-02-19T04:22:20Z"
        },
        {
          "tag": "v0.82.0",
          "kind": "minor",
          "published_at": "2026-02-19T04:12:27Z"
        },
        {
          "tag": "v0.81.0",
          "kind": "minor",
          "published_at": "2026-02-19T04:06:05Z"
        },
        {
          "tag": "v0.80.0",
          "kind": "minor",
          "published_at": "2026-02-19T03:58:16Z"
        },
        {
          "tag": "v0.79.0",
          "kind": "minor",
          "published_at": "2026-02-19T03:49:49Z"
        },
        {
          "tag": "v0.78.0",
          "kind": "minor",
          "published_at": "2026-02-19T03:45:01Z"
        },
        {
          "tag": "v0.77.0",
          "kind": "minor",
          "published_at": "2026-02-19T03:11:08Z"
        },
        {
          "tag": "v0.76.0",
          "kind": "minor",
          "published_at": "2026-02-19T03:07:01Z"
        },
        {
          "tag": "v0.75.0",
          "kind": "minor",
          "published_at": "2026-02-19T03:00:27Z"
        },
        {
          "tag": "v0.74.0",
          "kind": "minor",
          "published_at": "2026-02-19T02:50:50Z"
        },
        {
          "tag": "v0.73.0",
          "kind": "minor",
          "published_at": "2026-02-19T02:41:41Z"
        },
        {
          "tag": "v0.72.0",
          "kind": "minor",
          "published_at": "2026-02-19T02:38:44Z"
        },
        {
          "tag": "v0.71.0",
          "kind": "minor",
          "published_at": "2026-02-19T02:30:44Z"
        },
        {
          "tag": "v0.70.0",
          "kind": "minor",
          "published_at": "2026-02-19T02:20:52Z"
        },
        {
          "tag": "v0.69.0",
          "kind": "minor",
          "published_at": "2026-02-19T02:16:25Z"
        },
        {
          "tag": "v0.68.0",
          "kind": "minor",
          "published_at": "2026-02-19T00:05:02Z"
        },
        {
          "tag": "v0.67.0",
          "kind": "minor",
          "published_at": "2026-02-18T21:48:33Z"
        },
        {
          "tag": "v0.66.0",
          "kind": "minor",
          "published_at": "2026-02-18T21:18:52Z"
        },
        {
          "tag": "v0.65.0",
          "kind": "minor",
          "published_at": "2026-02-18T20:55:45Z"
        },
        {
          "tag": "v0.64.0",
          "kind": "minor",
          "published_at": "2026-02-18T20:40:18Z"
        },
        {
          "tag": "v0.63.0",
          "kind": "minor",
          "published_at": "2026-02-18T20:17:29Z"
        },
        {
          "tag": "v0.62.0",
          "kind": "minor",
          "published_at": "2026-02-18T16:14:31Z"
        },
        {
          "tag": "v0.61.1",
          "kind": "patch",
          "published_at": "2026-02-18T15:34:44Z"
        },
        {
          "tag": "v0.61.0",
          "kind": "minor",
          "published_at": "2026-02-18T15:21:40Z"
        },
        {
          "tag": "v0.60.0",
          "kind": "minor",
          "published_at": "2026-02-18T05:16:57Z"
        },
        {
          "tag": "v0.59.0",
          "kind": "minor",
          "published_at": "2026-02-18T04:18:56Z"
        },
        {
          "tag": "v0.58.2",
          "kind": "patch",
          "published_at": "2026-02-18T04:16:55Z"
        },
        {
          "tag": "v0.58.1",
          "kind": "patch",
          "published_at": "2026-02-18T04:13:51Z"
        },
        {
          "tag": "v0.58.0",
          "kind": "minor",
          "published_at": "2026-02-18T03:46:05Z"
        },
        {
          "tag": "v0.57.0",
          "kind": "minor",
          "published_at": "2026-02-18T03:11:13Z"
        },
        {
          "tag": "v0.56.0",
          "kind": "minor",
          "published_at": "2026-02-17T23:24:03Z"
        },
        {
          "tag": "v0.55.1",
          "kind": "patch",
          "published_at": "2026-02-17T02:09:11Z"
        },
        {
          "tag": "v0.55.0",
          "kind": "minor",
          "published_at": "2026-02-17T02:04:50Z"
        },
        {
          "tag": "v0.54.0",
          "kind": "minor",
          "published_at": "2026-02-16T21:15:26Z"
        },
        {
          "tag": "v0.53.0",
          "kind": "minor",
          "published_at": "2026-02-16T21:05:01Z"
        },
        {
          "tag": "v0.52.0",
          "kind": "minor",
          "published_at": "2026-02-16T20:35:20Z"
        },
        {
          "tag": "v0.51.0",
          "kind": "minor",
          "published_at": "2026-02-16T19:57:54Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "f4e88af20ae3f52b7976c58c78a9e4b4d742ea1c",
          "body": "Wingthing mcp",
          "is_bot": false,
          "headline": "Merge pull request #2 from ehrlich-b/wingthing-mcp",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-07-17T14:30:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5c85179bacc3cd433b7d6feb3f26626e9e86530b",
          "body": null,
          "is_bot": false,
          "headline": "Document future MCP service accounts",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-07-16T22:22:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "74a67dbe3a2e790a8a5fc9f5a49ca3a461a3af20",
          "body": null,
          "is_bot": false,
          "headline": "Reject cross-origin MCP requests before authentication",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-07-16T19:46:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aee5a284e579d7f234138b69ba5f61decd6621d6",
          "body": null,
          "is_bot": false,
          "headline": "Derive stable ES256 keys from existing JWT secrets",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-07-16T19:46:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8ee80fbbc4b22f8e203f1595e00f3ffe6f6a4505",
          "body": null,
          "is_bot": false,
          "headline": "Protect persisted signing keys",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-07-16T19:33:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5a8b623ef234c921d497175e2ee1b8488e0a1765",
          "body": null,
          "is_bot": false,
          "headline": "Add OAuth-gated role-scoped MCP tools",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-07-16T19:14:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "74ad60bf950dcebfb6f1daa28f4aeaca33823476",
          "body": "…a restart",
          "is_bot": false,
          "headline": "Recreate egg tool socket listener on daemon reclaim so tools survive …",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-06-21T18:15:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4abe51b19c468bd09c740802b7f3f776f0ce4b6e",
          "body": "…ng in browser terminal",
          "is_bot": false,
          "headline": "Translate mouse wheel to PgUp/PgDn for Claude Code alt-screen scrolli…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-06-21T18:15:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "06e84f19e67b0744c9312533f21c650eb98d87bf",
          "body": null,
          "is_bot": false,
          "headline": "Replace cinch CI with GitHub Actions for build and release",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-06-16T19:05:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b7ffeed0513e8602bf4954cddfd58e7d629ac075",
          "body": "…minal copy/paste",
          "is_bot": false,
          "headline": "Disable Claude Code mouse reporting in egg PTY to restore browser ter…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-06-16T19:05:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "84d24e228befb67c3ca02f33de04f26dad35f810",
          "body": "…indicators",
          "is_bot": false,
          "headline": "Fix spectator deep links, reattach viewer preservation, read-only UI …",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-03-24T20:29:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "be38a4b627a77b3b3f6c475edb117efb69726765",
          "body": null,
          "is_bot": false,
          "headline": "Remove spectator passkey auth, add relay routing tests",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-03-23T22:15:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7e8a9c659bcc2d3bab4b0e80477f1262eeb78117",
          "body": null,
          "is_bot": false,
          "headline": "Add spectator mode for read-only session viewing",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-03-23T21:51:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b69ec038506bf6a414cd548a07024dc9c1aed726",
          "body": null,
          "is_bot": false,
          "headline": "Fix .claude.json symlink leak between per-user homes and root home",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-03-19T18:20:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "178ad22e5c054e2048ec8e2d9415e8fa048aa734",
          "body": null,
          "is_bot": false,
          "headline": "Revert raw.githubusercontent.com domain allowlist - not needed",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-03-17T18:37:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b49e6a199bf5c5ed76c31a9a3c8ca838a5baab23",
          "body": null,
          "is_bot": false,
          "headline": "Allow raw.githubusercontent.com in claude agent domain proxy",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-03-17T18:18:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5085c0cb22924ac2c36f97305e16b38f6cd16f61",
          "body": null,
          "is_bot": false,
          "headline": "Auto-create org and auto-add members in roost mode",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-03-16T20:43:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3a567b0ae6dde3e172f7a8d442e1137861595a29",
          "body": "…tener leak, sandbox help text",
          "is_bot": false,
          "headline": "Fix per-user home ~expansion, invite consume ordering, PTY resize lis…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-03-15T21:45:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b518c3a18be40a81b9f6821c5eb0a79e80322435",
          "body": "…click race",
          "is_bot": false,
          "headline": "Fix PTY reconnect on deploy, chat-active stuck class, cached session …",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-03-14T22:37:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "059fb4d4c9196d9319db0c13d7da9731e8f1ca70",
          "body": null,
          "is_bot": false,
          "headline": "Remove chat/terminal toggle, hide grid button in terminal view",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-03-14T21:15:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "26841441fd59c4574f43e4e12dce54bd045d7f6e",
          "body": null,
          "is_bot": false,
          "headline": "Fix tool timeout in CI: kill process group not just shell parent",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-03-14T20:29:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "481f93ef8ddb9c6ca84db2c314ec5473739ff9dc",
          "body": "… save, mobile guard",
          "is_bot": false,
          "headline": "Canvas hardening: reconnect on return, agent chip icon, layout re-key…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-03-14T20:23:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b8ca44e9c1b83d0a70167e473a66b41e57311ad9",
          "body": "…nd toolbar chips",
          "is_bot": false,
          "headline": "Canvas use/create modes with floating controls, layout persistence, a…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-03-14T19:19:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "383739f8dedc114e8f6025c5f1735130e8b36c9f",
          "body": null,
          "is_bot": false,
          "headline": "Move tool shims to .tools subdir, extract and test apiKeyHelper setup",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-03-12T23:46:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8b3645e715d09b1157405e9c0ec3fc61cfc17881",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'main' into tools",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-03-12T23:20:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c938a296a22b4573644c4ac65d40ae4d262dbc9b",
          "body": null,
          "is_bot": false,
          "headline": "Fix apiKeyHelper race: use stable path instead of per-session egg dir",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-03-12T22:05:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cf3ffc06277c667f90d90805fbe254444bd8a1d3",
          "body": null,
          "is_bot": false,
          "headline": "Write API key to file instead of env, fix apiKeyHelper for non-org wings",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-03-12T20:09:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7d139a1e352c1351496df83588c529709be16cb0",
          "body": "… CLI commands",
          "is_bot": false,
          "headline": "Wire up privileged tools: socket listener, shims, sandbox mounts, and…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-03-12T14:49:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d926d6340758c2e787f2a6bd9247b1d9db297c43",
          "body": null,
          "is_bot": false,
          "headline": "Add tool name validation, reload mutex, deadline fix, and test coverage",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-03-12T14:48:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dd4e3d374a2623b73094d349a3a40e58f3100acb",
          "body": "… leaks",
          "is_bot": false,
          "headline": "Filter wing.info projects by exact path match to prevent subdirectory…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-03-11T23:18:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0f9060c7a5489896c6fac6b00bd5f4d039e59775",
          "body": null,
          "is_bot": false,
          "headline": "Add mobile chat view with live session polling and terminal/chat toggle",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-03-11T23:18:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "51b00c5ed2032f838dea235ef6653e2827952846",
          "body": "…t to egg config",
          "is_bot": false,
          "headline": "Support file/socket bind-mounts in jail, preserve cwd, add shim socke…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-03-11T22:56:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "13f24d2670300e85b95b488cab1228d07c16408e",
          "body": "…tory",
          "is_bot": false,
          "headline": "Restore cwd after pivot_root so claude sees the correct working direc…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-03-11T22:50:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "addf70651025295f19e819f96dd90dc13b1bca2a",
          "body": null,
          "is_bot": false,
          "headline": "Add allowlist sandbox via deny:/ with pivot_root jail",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-03-11T22:45:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f47d36d78c0a9799c724b48dcac94371d5213776",
          "body": "…homes",
          "is_bot": false,
          "headline": "Prepend ~/.local/bin to egg PATH for all sessions, not just per-user …",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-03-10T20:31:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a85378aa633302d3f0ef503ca2d4203b961901c8",
          "body": null,
          "is_bot": false,
          "headline": "Group eggs by user in roost mode",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-03-10T20:05:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c2c702dc2d8f001354554ca479eee469b6f27b41",
          "body": null,
          "is_bot": false,
          "headline": "Add wing owner labels to dashboard and detail view",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-03-10T18:35:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "193e911945c7dc208105df136b0b56f92b0d5d36",
          "body": "…transfer",
          "is_bot": false,
          "headline": "Add chat history capture, download, resume, and wing-to-wing session …",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-03-07T01:22:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9ed24546923850b005cd104a1af0fb065636e2bc",
          "body": null,
          "is_bot": false,
          "headline": "Add opencode agent, e2e test suites, P2P auth fix, docs overhaul",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-03-06T01:26:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bfa4e350e71b2d4cfb087fa20e0ef020e75eb4f8",
          "body": "…r --fix",
          "is_bot": false,
          "headline": "Fix AppArmor userns detection, add pre-flight sandbox check, wt docto…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-03-05T02:47:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ff312326cbf3836e76c75aa5ac9caa1914c687b5",
          "body": "… system section",
          "is_bot": false,
          "headline": "Add egg trace mode (strace wrapping), Linux e2e test suite, wt doctor…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-03-04T23:14:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d1c3658ea17c08349faa85d5b92c5edde40d7183",
          "body": "…ude session logs in wt support",
          "is_bot": false,
          "headline": "Preserve egg session logs across cleanup, dump egg.log on crash, incl…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-03-04T15:36:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9466261a10f994292d521e165779512f6a0acf43",
          "body": "…, show not_allowed in UI",
          "is_bot": false,
          "headline": "Remove PinnedCompat migration, auto-enroll token user on locked wings…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-03-04T02:50:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eafab02ca7a33bcc509aef6c5b5bbf1e11dce273",
          "body": "…ssthrough on personal wings",
          "is_bot": false,
          "headline": "Fix egg env: agent profile PlatformEnv for macOS Keychain, fix CWD pa…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-03-04T01:15:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5aedf56be33c22601852fb45074e616a1af55ffe",
          "body": null,
          "is_bot": false,
          "headline": "Fix Claude Code login on personal wings: only isolate homes on org wings",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-03-04T00:51:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ff676b0461c7e9123eb6ce2957a1c80daf8f3ba1",
          "body": null,
          "is_bot": false,
          "headline": "Update debug-wing skill to use support@wingthing.ai for bundle sharing",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-03-04T00:42:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b90ed592c7cb489be7a3f27c77dbb2ef09653f82",
          "body": "…rmatUserIdentity",
          "is_bot": false,
          "headline": "Add tests for auth check user info, WSHost routing, FetchUserInfo, fo…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-03-04T00:33:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c78062d31e060b0d1991299c677f12bc7137a2d4",
          "body": null,
          "is_bot": false,
          "headline": "Restart wing daemon on wt login so it picks up new token",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-03-04T00:28:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "02b87782af0667dcad80cd373f74ba1fc897376e",
          "body": "…r diagnostics",
          "is_bot": false,
          "headline": "Add wing UX overhaul: identity display, whoami, support bundle, bette…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-03-04T00:26:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8ac02b506c307966929fa1997ec48c467f2444be",
          "body": null,
          "is_bot": false,
          "headline": "Add debug-wing diagnostic skill for wing connectivity troubleshooting",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-03-03T23:08:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ed5c178423c7853a20ce96746e4f6df0352600a9",
          "body": "…g.yaml boot",
          "is_bot": false,
          "headline": "Fix sandbox escape: whitelist configured paths, block user-written eg…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-28T12:54:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "437602756168b54ef2772bc40b444a16ea6ddc5f",
          "body": "…r isolation bypass",
          "is_bot": false,
          "headline": "Fix egg sandbox secret leaks: file deny, env allowlist, remove IsOwne…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-26T16:59:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ba5ebd91305bbfe6fbda5eb9747304699bf6e82e",
          "body": "…r indirection\"\n\nThis reverts commit 35feeb6e3e0f1e4fce78d62a8b361857a4ec0847.",
          "is_bot": false,
          "headline": "Revert \"Pass ANTHROPIC_API_KEY directly instead of broken apiKeyHelpe…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-26T15:33:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "35feeb6e3e0f1e4fce78d62a8b361857a4ec0847",
          "body": "…ction",
          "is_bot": false,
          "headline": "Pass ANTHROPIC_API_KEY directly instead of broken apiKeyHelper indire…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-26T15:05:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8235730b73307cdf406b5f61aa62be57e9269f82",
          "body": "…identity cleanup",
          "is_bot": false,
          "headline": "Fix P2P showstopper: SendText for DC messages, ICE timeout, PC leak, …",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-22T18:54:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3f09231b5aa53e45bfd441e2b69076db0a4058f6",
          "body": "…t, drop logging, cleanupPeer scope, fallback cleanup",
          "is_bot": false,
          "headline": "Fix 6 P2P bugs: SwappableWriter race, migrate retry, migration timeou…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-22T18:44:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0211a8bf8672246bbc5633eb1927046916a46a91",
          "body": null,
          "is_bot": false,
          "headline": "Add JWT stateless migration to TODO",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-22T18:31:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bbabd995f36fbe019c918928684bc1a167b6bea7",
          "body": "…e pricing",
          "is_bot": false,
          "headline": "12-factor JWT keys, preserve known_hosts in sandbox, wt keygen, remov…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-22T18:19:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6f7c994e2c7a4891768d69bd93fa0ba64ed196b9",
          "body": "…d direct mode server",
          "is_bot": false,
          "headline": "Add P2P WebRTC transport with relay fallback, ES256 JWT migration, an…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-21T21:50:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a9fbc29bfaaf8d6afbaa269b1e634153402abf1e",
          "body": "…e, and 401 detection",
          "is_bot": false,
          "headline": "Eliminate silent wing auth failures with pre-flight probe, status fil…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-21T20:47:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b9c0c248d68665ea71798cc106a87e41cdec0fc3",
          "body": "…punching\"\n\nThis reverts commit 2db18676d9ee5e85d8f31ec079bca5435e4ca7f2.",
          "is_bot": false,
          "headline": "Revert \"Add design doc framing wingthing as modern SSH with P2P hole …",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-21T15:14:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2db18676d9ee5e85d8f31ec079bca5435e4ca7f2",
          "body": null,
          "is_bot": false,
          "headline": "Add design doc framing wingthing as modern SSH with P2P hole punching",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-21T15:13:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2016e24d23ceb3c30ecf47b0759c2cec5f1e9245",
          "body": null,
          "is_bot": false,
          "headline": "Add design doc for container and VM sandbox modes",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-21T14:10:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6e44a66a24766dd61eba2dfda124e7374b1e8df5",
          "body": "…scalls",
          "is_bot": false,
          "headline": "Add cgroups v2 resource limits and expand seccomp deny list to 27+ sy…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-21T13:52:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fba6feb73fa5a6dcc59acc14c8a289e20d06072b",
          "body": null,
          "is_bot": false,
          "headline": "Fix wt roost to wt roost start in README and docs",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-20T16:58:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "19c84ee6b368855546e459435bd811b063bde54a",
          "body": null,
          "is_bot": false,
          "headline": "Clarify three security domains in README with egg/wing/roost definitions",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-20T16:38:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fc0c585468df66543f5a22c1bf03316f21399670",
          "body": "…llment on restart",
          "is_bot": false,
          "headline": "Add per-user passkey enforcement on unlocked wings with relay re-enro…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-20T16:26:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dabbc54598c52ca88f23bf737335afd994404d85",
          "body": "… shared wings",
          "is_bot": false,
          "headline": "Stop persisting allow_keys from browser enrollment to prevent locking…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-20T14:53:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "64a94fec8936cc2cc3137dcfbed520ea644430b9",
          "body": null,
          "is_bot": false,
          "headline": "Fix owner home dir isolation and project discovery with egg.yaml support",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-20T03:39:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "16af2626f40ea937690c5970d645907296d2b53d",
          "body": "…oost terminology",
          "is_bot": false,
          "headline": "Update docs for shared wings, idle timeouts, wt roost, and relay-to-r…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-20T03:11:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fb811909fd6962b558520e1a443fbe7593a68eb7",
          "body": null,
          "is_bot": false,
          "headline": "Add session idle timeouts with wing reaper and egg self-enforcement",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-20T01:36:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "97eb46b1cd6b9c2d9946a248db230c478b6b8dd9",
          "body": null,
          "is_bot": false,
          "headline": "Make preview file session-specific to prevent cross-user preview leaks",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-19T22:12:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b1a3ad0cfd8f1658cfdd62632a17aefa6886c026",
          "body": "…hared wings",
          "is_bot": false,
          "headline": "Stop persisting allow_keys on passkey enrollment to prevent locking s…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-19T21:44:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "17012bdef59e6b517b01638bba01a527db391c44",
          "body": null,
          "is_bot": false,
          "headline": "Inject WT_PREVIEW_DIR env var so preview works when agent changes CWD",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-19T20:07:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "32b3874e488b8619e76aa099b0233bb32d8537c1",
          "body": null,
          "is_bot": false,
          "headline": "Pass --yolo to Cursor Agent when dangerously_skip_permissions is set",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-19T19:46:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2a83d59adfc5a09c49d3a49246898aa11a740096",
          "body": "… bypass",
          "is_bot": false,
          "headline": "Give all relay users per-user homes, owner is auth role not isolation…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-19T18:13:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "96e1788a365e8daafc4478da5a28b31de0249599",
          "body": null,
          "is_bot": false,
          "headline": "Inject agent settings for owners/admins, not just guests",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-19T18:09:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c21afd9c2312ddce08b497ddcb92c926a47dd842",
          "body": null,
          "is_bot": false,
          "headline": "Rebuild agent settings every session so host config changes propagate",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-19T17:19:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1779c9ce8d1615dbfe8c865812151dcb0a76e1bb",
          "body": "…ser sessions",
          "is_bot": false,
          "headline": "Add agent_settings to egg.yaml for inheriting agent config in multi-u…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-19T16:47:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "21391cbd156166af8855b9ad7eb3e986b4afccc2",
          "body": "…d OAuth work",
          "is_bot": false,
          "headline": "Skip per-user home for owners/admins so their real HOME, Keychain, an…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-19T15:24:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8ab53ce71395b0b20bae7f1e43e26d289141901a",
          "body": "…therwise",
          "is_bot": false,
          "headline": "Only set apiKeyHelper when ANTHROPIC_API_KEY exists, let OAuth work o…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-19T15:12:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9f6f8724e839a8129aaa7560ff5aa1ab734b1112",
          "body": null,
          "is_bot": false,
          "headline": "Allow keychain writes in seatbelt sandbox so OAuth tokens persist",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-19T14:04:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "363a13019b022a8546b08c2567f909fc379c759f",
          "body": "…ories",
          "is_bot": false,
          "headline": "Fix project discovery for paths that point directly at project direct…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-19T05:22:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "96927aa94563f84ffd66d1031e8e351ea555591e",
          "body": "…ve install warning",
          "is_bot": false,
          "headline": "Symlink agent binary into per-user .local/bin to fix Claude Code nati…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-19T05:04:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ac7ff86ccb80f529e82b5caa6eacb4dac9c46dfa",
          "body": "… Code warnings",
          "is_bot": false,
          "headline": "Create .local/bin in per-user home and add to PATH to suppress Claude…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-19T05:01:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ab5669f40738ffd13ce27b8a6d3277ac4e7d9fe3",
          "body": "…active",
          "is_bot": false,
          "headline": "Skip ANTHROPIC_API_KEY profile injection when apiKeyHelper rename is …",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-19T04:49:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8ab4f6d14f8bf4be05e113483ce7367937fc53de",
          "body": null,
          "is_bot": false,
          "headline": "Default TERM to xterm-256color when running under headless services",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-19T04:41:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3fddf4843cc8d1fd003caade343cea2f275ad90c",
          "body": "…id auth conflict",
          "is_bot": false,
          "headline": "Replace ANTHROPIC_API_KEY with hidden env var for apiKeyHelper to avo…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-19T04:39:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e956a30e3500e40d38f722cebf32331dccf5db36",
          "body": "…ogin prompt",
          "is_bot": false,
          "headline": "Add apiKeyHelper to per-user .claude/settings.json to bypass Claude l…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-19T04:35:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b13013b949e4c4edac2d824301878f34b45ecb03",
          "body": null,
          "is_bot": false,
          "headline": "Symlink .claude.json into per-user home to skip first-run onboarding",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-19T04:29:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9be30a4393b520998a908cc3bd32a87df6cca05d",
          "body": null,
          "is_bot": false,
          "headline": "Use per-user home for sandbox overlay so agent config writes work",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-19T04:22:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0cbdb10f9cd086b4c20760ed3a8d3737473c41d6",
          "body": "…xed agents",
          "is_bot": false,
          "headline": "Inject agent profile env vars into egg spawn so API keys reach sandbo…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-19T04:12:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cf5c3ae60bb4c232c5ff8d16bfd5bede100783ca",
          "body": "…ceeds",
          "is_bot": false,
          "headline": "Pre-create agent profile dirs in per-user home so sandbox overlay suc…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-19T04:05:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a26326c3b02b95b3a36b6e715852c415ea944473",
          "body": null,
          "is_bot": false,
          "headline": "Add *.claude.com to Claude agent domains for platform.claude.com OAuth",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-19T03:57:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e1570b42a2a62bf142221c407d82e755447008ea",
          "body": "…id websocket limit",
          "is_bot": false,
          "headline": "Discover egg.yaml as project marker and chunk large PTY output to avo…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-19T03:49:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b5148aa01cacd5c84ebe889dc6d4c73a6b3c4e98",
          "body": "…alled",
          "is_bot": false,
          "headline": "Show 'no agents' on wing card and detail page when no agents are inst…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-19T03:44:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "adbc9e72ab0eeb2ac67c24d5b15e120a8e7bf7c2",
          "body": "… admin users",
          "is_bot": false,
          "headline": "Auto-enroll admins for relay passkey auth so passkey unlock works for…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-19T03:10:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "03086a60607826af12fd2f8d055da59dff101b8f",
          "body": "…for users without passkeys",
          "is_bot": false,
          "headline": "Don't override add-passkey state when probe returns passkey_required …",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-19T03:06:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "235ee0d0453cd69665d322773e48718eabadb668",
          "body": "…tes, allow empty allow_keys with relay passkeys",
          "is_bot": false,
          "headline": "Full passkey flow: has_passkeys flag, add-passkey vs authenticate sta…",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-19T03:00:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d2c89a608ab47decb27148ad8d4e7d358e9c7027",
          "body": "…exist",
          "is_bot": false,
          "headline": "Guard org section event listeners for roost mode where elements dont …",
          "author_name": "Bryan Ehrlich",
          "author_login": "ehrlich-b",
          "committed_at": "2026-02-19T02:53:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 100,
      "commits_last_year": 592,
      "latest_release_at": "2026-07-17T14:34:50Z",
      "latest_release_tag": "v0.140.0",
      "releases_from_tags": false,
      "days_since_last_push": 2,
      "active_weeks_last_year": 13,
      "days_since_latest_release": 10,
      "mean_days_between_releases": 13.9
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 57,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/ehrlich-b/wingthing",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/ehrlich-b/wingthing",
          "is_deprecated": false,
          "latest_version": "v0.140.0",
          "repository_url": "https://github.com/ehrlich-b/wingthing",
          "versions_count": 295,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-17T14:30:40Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 10
        }
      ]
    },
    "popularity": {
      "forks": 5,
      "stars": 49,
      "watchers": 1,
      "fork_history": {
        "days": [
          {
            "date": "2026-02-20",
            "count": 1
          },
          {
            "date": "2026-04-02",
            "count": 1
          },
          {
            "date": "2026-04-03",
            "count": 1
          },
          {
            "date": "2026-04-06",
            "count": 1
          },
          {
            "date": "2026-04-07",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 5,
        "total_forks": 5
      },
      "star_history": null,
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Makefile"
      ],
      "api_schema_files": [
        "proto/egg.proto"
      ],
      "has_devcontainer": true,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "go.mod"
      ],
      "largest_source_bytes": 143891,
      "source_files_sampled": 209,
      "oversized_source_files": 2,
      "agent_instruction_files": [
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 17359
    },
    "dependencies": {
      "manifests": [
        "go.mod",
        "web/package.json"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go",
        "npm"
      ],
      "dependencies": [
        {
          "name": "github.com/charmbracelet/ultraviolet",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20251106193841-7889546fc720"
        },
        {
          "name": "github.com/charmbracelet/x/vt",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-00010101000000-000000000000"
        },
        {
          "name": "github.com/fsnotify/fsnotify",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.9.0"
        },
        {
          "name": "github.com/google/uuid",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.6.0"
        },
        {
          "name": "github.com/pion/webrtc/v4",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v4.2.9"
        },
        {
          "name": "github.com/spf13/cobra",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.10.2"
        },
        {
          "name": "golang.org/x/crypto",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.48.0"
        },
        {
          "name": "golang.org/x/sys",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.41.0"
        },
        {
          "name": "gopkg.in/yaml.v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.0.1"
        },
        {
          "name": "modernc.org/sqlite",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.3"
        },
        {
          "name": "github.com/coder/websocket",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.8.14"
        },
        {
          "name": "github.com/creack/pty",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.1.24"
        },
        {
          "name": "github.com/go-webauthn/webauthn",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.15.0"
        },
        {
          "name": "github.com/golang-jwt/jwt/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.3.1"
        },
        {
          "name": "golang.org/x/term",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.40.0"
        },
        {
          "name": "golang.org/x/time",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.14.0"
        },
        {
          "name": "google.golang.org/grpc",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.78.0"
        },
        {
          "name": "google.golang.org/protobuf",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.36.11"
        },
        {
          "name": "@nlux/core",
          "manifest": "web/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.17.1"
        },
        {
          "name": "@nlux/themes",
          "manifest": "web/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.17.1"
        },
        {
          "name": "@noble/ciphers",
          "manifest": "web/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.1.1"
        },
        {
          "name": "@noble/curves",
          "manifest": "web/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.0.1"
        },
        {
          "name": "@xterm/addon-fit",
          "manifest": "web/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.11.0"
        },
        {
          "name": "@xterm/addon-serialize",
          "manifest": "web/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.14.0"
        },
        {
          "name": "@xterm/xterm",
          "manifest": "web/package.json",
          "ecosystem": "npm",
          "version_constraint": "^6.0.0"
        },
        {
          "name": "marked",
          "manifest": "web/package.json",
          "ecosystem": "npm",
          "version_constraint": "^15.0.0"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 1,
        "open_issues": 0,
        "closed_ratio": 1,
        "closed_issues": 1,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "ehrlich-b",
          "commits": 611,
          "avatar_url": "https://avatars.githubusercontent.com/u/584109?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "release.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum",
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "1 out of 1 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/25 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 8,
            "reason": "10 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 8",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "37 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "f4e88af20ae3f52b7976c58c78a9e4b4d742ea1c",
        "ran_at": "2026-07-27T15:28:56Z",
        "aggregate_score": 3.4,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-17T14:34:54Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-17T14:30:41Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/ehrlich-b/wingthing",
    "host": "github.com",
    "name": "wingthing",
    "owner": "ehrlich-b"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 59,
      "inputs": {
        "security": 34,
        "vitality": 79,
        "community": 40,
        "governance": 58,
        "engineering": 77
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 79,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 71,
            "inputs": {
              "commits_last_year": 592,
              "human_commit_share": 1,
              "days_since_last_push": 2,
              "active_weeks_last_year": 13
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 2 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 2
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "13/52 weeks with commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 13
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "592 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 592
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "10 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 8",
                "points": 8,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 100,
              "latest_release_tag": "v0.140.0",
              "releases_from_tags": false,
              "days_since_latest_release": 10,
              "mean_days_between_releases": 13.9
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "100 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 100
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 10 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 10
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~13.9 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 13.9
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 10,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 10 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 10
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 40,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "at_risk",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 32,
            "inputs": {
              "forks": 5,
              "stars": 49,
              "watchers": 1,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "49 stars",
                "points": 27.3,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 49
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "5 forks",
                "points": 5,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "1 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 58,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "excellent",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "merged_prs": 1,
              "open_issues": 0,
              "closed_issues": 1,
              "issue_closed_ratio": 1,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "100% of issues closed",
                "points": 46.8,
                "status": "met",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "1/1 decided PRs merged",
                "points": 38.2,
                "status": "met",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 1,
                      "decided": 1
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/25 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 54,
            "inputs": {
              "followers": 14,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "ehrlich-b",
              "public_repos": 56,
              "account_age_days": 5661
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "14 followers of ehrlich-b",
                "points": 8.5,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 14,
                      "login": "ehrlich-b"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "56 public repos, account ~15 yr old",
                "points": 24.8,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 56
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 15
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/ehrlich-b/wingthing"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 10
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 10 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 10
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "295 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 295
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 77,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "2 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "1 out of 1 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": "https://wingthing.ai",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://wingthing.ai",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 34,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Packaging. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "packaging"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 34,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 3.4
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "1 out of 1 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/25 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "10 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 8",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "37 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 59,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 46,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.01,
              "agent_instruction_files": [
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 17359
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "1 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 0.5,
                "status": "partial",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 1,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 61,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum",
                "package-lock.json"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [
                "Makefile"
              ],
              "has_devcontainer": true,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "go.mod"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "devcontainer, Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "devcontainer, Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 143891,
              "source_files_sampled": 209,
              "oversized_source_files": 2
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "2/209 source files over 60KB",
                "points": 54.5,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 209,
                      "oversized": 2
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [],
              "has_mcp_signal": false,
              "api_schema_files": [
                "proto/egg.proto"
              ]
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": "proto/egg.proto",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "proto/egg.proto"
                    }
                  }
                ],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-27T15:29:03.673472Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/e/ehrlich-b/wingthing.svg",
  "full_name": "ehrlich-b/wingthing",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsGo.