Public record
Software health reportschema 0.27.0 · metrics 2.5.0 · 2026-07-30 10:36 UTC

escalated-dev / escalated-laravel

Escalated plugin for Laravel

PHPMIT★ 27 stars⑂ 7 forkssince Feb 2026View on GitHub ↗

escalated-dev/escalated-laravel holds a health index of 77 out of 100, placing it in the Good band. It scores highest on Vitality (89/100) and lowest on Community & Adoption (41/100). It was last updated today. A single contributor accounts for most of its recent work.

77
overall / 100
Good

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean, calibrated against the distribution of the public record so bands carry percentile meaning; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At Risk ceiling of 34.

77
Exceptional93-100The record's top tier (≈ top 5%); essentially all checked criteria met
Excellent80-92Strong across the board; minor gaps
Good65-79Healthy; gaps are limited and manageable
Moderate50-64Acceptable with notable gaps; review recommended
Weak35-49Material weaknesses across several areas
At Risk20-34Significant weaknesses; adoption warrants caution
Critical1-19Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

The weighted overall 66 is calibrated to 77 on the published index scale (record calibration 2026-08-02).

Ownership

EscalatedOrganization
10 followers31 public repossince Feb 2026

This repository is backed by an organization — shared, accountable stewardship that can outlive any single maintainer.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publishTags
Packagistescalated-dev/escalated-laravelv1.5.12,0632656 days agosupportlaravelticketshelpdeskcustomer-support

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

89Excellent · 21% of overall
How it's scored
36/36Push recency — last push 0 days ago
16.6/36Commit cadence — 24/52 weeks with commits
18/18Commit volume — 292 commits in the last year
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 7 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year292
human_commit_share0.62
days_since_last_push0
active_weeks_last_year24

Release discipline

100Exceptional
How it's scored
27/27Ships releases — 13 releases published
36/36Release recency — latest release 56 days ago
27/27Release cadence — a release every ~5.1 days
0/10OpenSSF Scorecard: Signed-Releases — no data
Inputs used
releases_count13
latest_release_tagv1.5.1
releases_from_tagsno
days_since_latest_release56
mean_days_between_releases5.1
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

41Weak · 17% of overall
How it's scored
23/60Stars — 27 stars
6.5/25Forks — 7 forks
1.7/15Watchers — 3 watchers
Inputs used
forks7
stars27
watchers3
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (MIT)
0/18CONTRIBUTING guide
0/13.5Code of conduct
0/7.2Issue template
0/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
readme_badges
has_contributingno
has_issue_templateno
has_code_of_conductno
readme_badge_services
has_pull_request_templateno
How it's scored
44.2/80Monthly downloads — 2,063 downloads/month across packagist
2/20Registry dependents — 1 packages depend on it
Inputs used
packagesescalated-dev/escalated-laravel
dependents1
ecosystemspackagist
total_downloads5,848
monthly_downloads2,063

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

60Moderate · 23% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
2.1/22.5Commit distribution — top contributor authored 91% of commits
5.4/13.5Contributor breadth — 4 contributors
10/10OpenSSF Scorecard: Contributors — project has 11 contributing companies or organizations
Inputs used
bus_factor1
contributors_sampled4
top_contributor_share0.906
How it's scored
42/42Issue resolution — 100% of issues closed
27.1/30PR acceptance — 133/147 decided PRs merged
0/13Newcomer PR acceptance — no first-time contributor's PR decided in 30d
0/15OpenSSF Scorecard: Code-Review — Found 0/5 approved changesets -- score normalized to 0
Inputs used
merged_prs133
open_issues0
closed_issues16
prs_merged_7d
prs_decided_7d
prs_merged_30d
prs_decided_30d
issue_closed_ratio1
closed_unmerged_prs14
first_time_authors_30d
first_time_prs_merged_30d
first_time_prs_decided_30d
Excluded from scoring (no data or not applicable): newcomer_pr_acceptance. Remaining weights renormalized.
How it's scored
30/30Ownership backing — organization-owned
0/20Verified domain
7.5/25Owner reach — 10 followers of escalated-dev
11.9/25Track record — 31 public repos, account ~0 yr old
Inputs used
followers10
owner_typeOrganization
is_verified
owner_loginescalated-dev
public_repos31
account_age_days173

Package maintenance

100Exceptional
How it's scored
25/25Published & resolvable — 1 package(s) on packagist
35/35Publish recency — latest publish 56 days ago
20/20Version history — 26 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packagesescalated-dev/escalated-laravel
ecosystemspackagist
any_deprecatedno
min_days_since_publish56

Engineering Quality

Are baseline engineering and documentation practices in place?

81Excellent · 19% of overall
How it's scored
24/24CI workflows — 2 workflow(s)
24/24Tests present
0/16Linter config
0/9.6Pre-commit hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 25 out of 25 merged PRs checked by a CI test -- score normalized to 10
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configno
has_precommit_configno

Documentation

100Exceptional
How it's scored
30/30README
25/25Documentation directory
15/15Documentation / homepage site — https://escalated.dev/framework/laravel
10/10Repository description
10/10Topics — 1 topics
10/10Wiki
Inputs used
topicslaravel
has_wikiyes
homepagehttps://escalated.dev/framework/laravel
has_readmeyes
has_docs_diryes
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

61Moderate · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
2.5/2.5CI-Tests — 25 out of 25 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/5 approved changesets -- score normalized to 0
2.5/2.5Contributors — project has 11 contributing companies or organizations
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
7.5/7.5Maintained — 30 commit(s) and 7 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — no data
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
5/5SAST — SAST tool is run on all commits
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — no data
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
6.8/7.5Vulnerabilities — 1 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate6.1
Excluded from scoring (no data or not applicable): packaging, signed_releases. Remaining weights renormalized.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? Carries a deliberately small weight (4%): agent tooling is a real maintenance signal, but a repository with none can still reach 100/100.

43Weak · 4% of overall
How it's scored
0/45Agent instructions — no CLAUDE.md / AGENTS.md / editor rules
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 60 of 62 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share0.968
agent_instruction_files
agent_instruction_max_bytes
How it's scored
0/18One-command bootstrap
22/22Automated tests
0/11Lint / format config
0/11Static type checking
10/10Reproducible environment — Dockerfile, lockfile
0/10Demonstrated agent practice — no agent-authored commits among the last 100
8/8Automated maintenance — 38 of the last 100 commits are automated dependency updates
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Inputs used
has_nixno
has_testsyes
lockfilespackage-lock.json
has_dockerfileyes
typed_languageno
bootstrap_files
has_devcontainerno
has_linter_configno
typecheck_configs
agent_commit_share0
toolchain_manifests
dependency_bot_commit_share0.38
How it's scored
0/45Type-checkable code — PHP without a type-check config
55/55Manageable file sizes — 0/582 source files over 60KB
Inputs used
primary_languagePHP
largest_source_bytes46,189
source_files_sampled582
oversized_source_files0

Key facts

27GitHub stars
4contributors
292commits, last 12 months
0days since last push
13releases
1bus factor
0open issues
npm, Packagistpackage ecosystems

Data collection warnings

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

More detail

Star and fork history 0 ★ / 7 ⇿
0Stars
7Forks
13Releases

When each star and fork was added, collected from GitHub and bucketed by day. Cumulative growth sits directly above the daily additions it is made of, so the two read against each other: steady organic accretion looks nothing like an abrupt, short-lived burst. Where that difference is measurable, it is reported as growth authenticity.

1234567712026-022026-052026-07
Major 1Minor 5Patch 7
OpenSSF Scorecard 6.1 / 10
6.1aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-30 10:35 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
10CI-Tests25 out of 25 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/5 approved changesets -- score normalized to 0
10Contributorsproject has 11 contributing companies or organizations
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 7 issue activity found in the last 90 days -- score normalized to 10
n/aPackagingpackaging workflow not detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
10SASTSAST tool is run on all commits
10Security-Policysecurity policy file detected
n/aSigned-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
9Vulnerabilities1 existing vulnerabilities detected
Direct dependencies 6
RegistryPackageVersion constraintManifest
Packagistescalated-dev/locale^0.1.8composer.json
Packagistilluminate/contracts^11.0|^12.0|^13.0composer.json
Packagistinertiajs/inertia-laravel^2.0|^3.0composer.json
Packagistleague/commonmark^2.0composer.json
Packagistsymfony/dom-crawler^6.0|^7.0composer.json
npm@escalated-dev/escalated^0.9.0package.json
All dependencies not collected

The resolved dependency set could not be collected for this report: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [
        "laravel"
      ],
      "is_fork": false,
      "size_kb": 1431,
      "has_wiki": true,
      "homepage": "https://escalated.dev/framework/laravel",
      "languages": {
        "CSS": 59,
        "PHP": 1712328,
        "Vue": 1383,
        "Blade": 14795,
        "Shell": 1100,
        "Dockerfile": 2143,
        "JavaScript": 1931
      },
      "pushed_at": "2026-07-30T10:35:07Z",
      "created_at": "2026-02-07T03:44:30Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-30T10:33:59Z",
      "description": "Escalated plugin for Laravel",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "PHP",
      "significant_languages": [
        "PHP"
      ]
    },
    "owner": {
      "blog": "https://escalated.dev",
      "name": "Escalated",
      "type": "Organization",
      "login": "escalated-dev",
      "company": null,
      "location": null,
      "followers": 10,
      "avatar_url": "https://avatars.githubusercontent.com/u/259997415?v=4",
      "created_at": "2026-02-07T03:42:48Z",
      "is_verified": null,
      "public_repos": 31,
      "account_age_days": 173
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v1.5.1",
          "kind": "patch",
          "published_at": "2026-06-04T05:29:13Z"
        },
        {
          "tag": "v1.5.0",
          "kind": "minor",
          "published_at": "2026-06-04T05:10:51Z"
        },
        {
          "tag": "v1.4.1",
          "kind": "patch",
          "published_at": "2026-05-29T11:53:46Z"
        },
        {
          "tag": "v1.4.0",
          "kind": "minor",
          "published_at": "2026-05-29T02:46:28Z"
        },
        {
          "tag": "v1.3.0",
          "kind": "minor",
          "published_at": "2026-05-10T21:51:42Z"
        },
        {
          "tag": "v1.2.5",
          "kind": "patch",
          "published_at": "2026-05-07T14:22:06Z"
        },
        {
          "tag": "v1.2.4",
          "kind": "patch",
          "published_at": "2026-05-07T03:42:56Z"
        },
        {
          "tag": "v1.2.3",
          "kind": "patch",
          "published_at": "2026-05-07T01:48:06Z"
        },
        {
          "tag": "v1.2.2",
          "kind": "patch",
          "published_at": "2026-04-20T15:23:50Z"
        },
        {
          "tag": "v1.2.1",
          "kind": "patch",
          "published_at": "2026-04-19T00:17:40Z"
        },
        {
          "tag": "v1.2.0",
          "kind": "minor",
          "published_at": "2026-04-18T04:21:05Z"
        },
        {
          "tag": "v1.1.0",
          "kind": "minor",
          "published_at": "2026-04-06T17:18:23Z"
        },
        {
          "tag": "v1.0.0",
          "kind": "major",
          "published_at": "2026-04-06T08:30:26Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "db7d6832c2738a67fc294a59071d7fc757d90eae",
          "body": "Bumps [@tailwindcss/postcss](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/@tailwindcss-postcss) from 4.3.2 to 4.3.3.\n- [Release notes](https://github.com/tailwindlabs/tailwindcss/releases)\n- [Changelog](https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md)\n- [Commits]\n[…]\nrect:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump @tailwindcss/postcss in /docker/host-app (#164)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-30T10:32:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e6b17f2c54280af660f5637a28877ba5938c8749",
          "body": "Bumps [@vitejs/plugin-vue](https://github.com/vitejs/vite-plugin-vue/tree/HEAD/packages/plugin-vue) from 6.0.7 to 6.0.8.\n- [Release notes](https://github.com/vitejs/vite-plugin-vue/releases)\n- [Changelog](https://github.com/vitejs/vite-plugin-vue/blob/main/packages/plugin-vue/CHANGELOG.md)\n- [Commit\n[…]\nrect:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump @vitejs/plugin-vue in /docker/host-app (#159)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-19T22:42:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c65694c85ce187e66240086100f266d583c63fbf",
          "body": "Bumps [laravel-vite-plugin](https://github.com/laravel/vite-plugin) from 3.1.0 to 3.1.3.\n- [Release notes](https://github.com/laravel/vite-plugin/releases)\n- [Changelog](https://github.com/laravel/vite-plugin/blob/3.x/CHANGELOG.md)\n- [Commits](https://github.com/laravel/vite-plugin/compare/v3.1.0...\n[…]\nrect:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump laravel-vite-plugin in /docker/host-app (#160)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-19T22:42:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "37b341f72d991ac089ce4c38fa92432b81989c9b",
          "body": "Bumps [tailwindcss](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/tailwindcss) from 4.3.2 to 4.3.3.\n- [Release notes](https://github.com/tailwindlabs/tailwindcss/releases)\n- [Changelog](https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md)\n- [Commits](https://github.co\n[…]\nigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Matt Gros <3311227+mpge@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump tailwindcss in /docker/host-app (#161)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-19T22:42:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4f5a6cf41b84fb69abf77ad121413e7f6ccfcfc3",
          "body": "…158)\n\nBumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 8.1.4 to 8.1.5.\n- [Release notes](https://github.com/vitejs/vite/releases)\n- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)\n- [Commits](https://github.com/vitejs/vite/commits/v8.1.5/pac\n[…]\nrect:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump vite from 8.1.4 to 8.1.5 in /docker/host-app (#…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-19T22:41:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "12634316ee1727434487d6fbc3a772c54570953c",
          "body": "…#162)\n\nBumps [vue](https://github.com/vuejs/core) from 3.5.39 to 3.5.40.\n- [Release notes](https://github.com/vuejs/core/releases)\n- [Changelog](https://github.com/vuejs/core/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/vuejs/core/compare/v3.5.39...v3.5.40)\n\n---\nupdated-dependencies:\n- de\n[…]\nrect:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump vue from 3.5.39 to 3.5.40 in /docker/host-app (…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-19T21:21:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fb88980b9dd3a6f2daee28fd5e4a7491e75497f5",
          "body": "Bumps [@inertiajs/vue3](https://github.com/inertiajs/inertia/tree/HEAD/packages/vue3) from 3.6.0 to 3.6.1.\n- [Release notes](https://github.com/inertiajs/inertia/releases)\n- [Changelog](https://github.com/inertiajs/inertia/blob/3.x/CHANGELOG.md)\n- [Commits](https://github.com/inertiajs/inertia/commi\n[…]\nrect:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump @inertiajs/vue3 in /docker/host-app (#157)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-14T23:08:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5dc62d0b38357e4cdfa09bd846b474ffdb53f211",
          "body": "…156)\n\nBumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 8.1.3 to 8.1.4.\n- [Release notes](https://github.com/vitejs/vite/releases)\n- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)\n- [Commits](https://github.com/vitejs/vite/commits/v8.1.4/pac\n[…]\nrect:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump vite from 8.1.3 to 8.1.4 in /docker/host-app (#…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-14T23:08:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4d97d70746990e72e262bf25d15ffe42eeba43bd",
          "body": "…pp (#151)\n\nBumps [postcss](https://github.com/postcss/postcss) from 8.5.15 to 8.5.16.\n- [Release notes](https://github.com/postcss/postcss/releases)\n- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/postcss/postcss/compare/8.5.15...8.5.16)\n\n---\n\n[…]\nrect:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump postcss from 8.5.15 to 8.5.16 in /docker/host-a…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-06T03:42:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "609e891b50b0a12e8250e592f8e5b6a3c145ed51",
          "body": "Bumps [@inertiajs/vue3](https://github.com/inertiajs/inertia/tree/HEAD/packages/vue3) from 3.5.0 to 3.6.0.\n- [Release notes](https://github.com/inertiajs/inertia/releases)\n- [Changelog](https://github.com/inertiajs/inertia/blob/3.x/CHANGELOG.md)\n- [Commits](https://github.com/inertiajs/inertia/commi\n[…]\nigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Matt Gros <3311227+mpge@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump @inertiajs/vue3 in /docker/host-app (#152)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-06T03:41:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3bec86fb13a972cb463d1f6df67c2ace85eee986",
          "body": "Bumps [@tailwindcss/postcss](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/@tailwindcss-postcss) from 4.3.1 to 4.3.2.\n- [Release notes](https://github.com/tailwindlabs/tailwindcss/releases)\n- [Changelog](https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md)\n- [Commits]\n[…]\nrect:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump @tailwindcss/postcss in /docker/host-app (#154)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-06T03:40:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fa36bf0bbe1c4476de95626294396c5f26a6d94d",
          "body": "…155)\n\nBumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 8.1.0 to 8.1.3.\n- [Release notes](https://github.com/vitejs/vite/releases)\n- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)\n- [Commits](https://github.com/vitejs/vite/commits/v8.1.3/pac\n[…]\nrect:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump vite from 8.1.0 to 8.1.3 in /docker/host-app (#…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-06T03:40:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "18c4111aa7cde8d6ea8e1ec3cab01b51e1b9807a",
          "body": "Supersedes dependabot #147, which went stale (lockfile conflict after the\nother host-app dependabot PRs merged, and dependabot did not rebase it).\nApplied directly.\n\nCo-authored-by: Matt Gros <mpge@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore(deps-dev): bump vue to 3.5.39 in /docker/host-app (#150)",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-06-27T10:41:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "58ae5d3410c9442afcac38667c82c64ee96ec820",
          "body": "Bumps [@inertiajs/vue3](https://github.com/inertiajs/inertia/tree/HEAD/packages/vue3) from 3.4.0 to 3.5.0.\n- [Release notes](https://github.com/inertiajs/inertia/releases)\n- [Changelog](https://github.com/inertiajs/inertia/blob/3.x/CHANGELOG.md)\n- [Commits](https://github.com/inertiajs/inertia/commi\n[…]\nrect:development\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump @inertiajs/vue3 in /docker/host-app (#148)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-27T10:16:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "45238590981ca113f73d0208c99d0961214a937d",
          "body": "…#149)\n\nBumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 8.0.16 to 8.1.0.\n- [Release notes](https://github.com/vitejs/vite/releases)\n- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)\n- [Commits](https://github.com/vitejs/vite/commits/create-v\n[…]\nrect:development\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump vite from 8.0.16 to 8.1.0 in /docker/host-app (…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-27T10:16:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e996bfb6feba35c81013e760c47f40f94bec72be",
          "body": "… (#146)\n\nBumps [axios](https://github.com/axios/axios) from 1.18.0 to 1.18.1.\n- [Release notes](https://github.com/axios/axios/releases)\n- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)\n- [Commits](https://github.com/axios/axios/compare/v1.18.0...v1.18.1)\n\n---\nupdated-dependenci\n[…]\nrect:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump axios from 1.18.0 to 1.18.1 in /docker/host-app…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-27T10:13:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7a364a2ef6e454d3f06f470573c75854f26d5f54",
          "body": null,
          "is_bot": false,
          "headline": "ci: remove unused FOSSA workflow and badge",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-06-20T18:52:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "44ce1241acb65a6a0bd0f3102430be3588f19cd0",
          "body": "Bumps [tailwindcss](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/tailwindcss) from 4.3.0 to 4.3.1.\n- [Release notes](https://github.com/tailwindlabs/tailwindcss/releases)\n- [Changelog](https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md)\n- [Commits](https://github.co\n[…]\nrect:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump tailwindcss in /docker/host-app (#141)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-20T13:13:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ae082881d8d600dd6f8d9594a858f3985b1fb11f",
          "body": "… (#140)\n\nBumps [axios](https://github.com/axios/axios) from 1.17.0 to 1.18.0.\n- [Release notes](https://github.com/axios/axios/releases)\n- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)\n- [Commits](https://github.com/axios/axios/compare/v1.17.0...v1.18.0)\n\n---\nupdated-dependenci\n[…]\nrect:development\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump axios from 1.17.0 to 1.18.0 in /docker/host-app…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-20T13:13:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7fe351ba1ca6db752edcc8a62067c0adf5f5abf1",
          "body": "Bumps [@tailwindcss/postcss](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/@tailwindcss-postcss) from 4.3.0 to 4.3.1.\n- [Release notes](https://github.com/tailwindlabs/tailwindcss/releases)\n- [Changelog](https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md)\n- [Commits]\n[…]\nrect:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump @tailwindcss/postcss in /docker/host-app (#139)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-20T13:13:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9bd8b4b42bdcce5e3e5a2c11ba553131983c8dc5",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/v6...v7)\n\n---\nupdated-dependenc\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/checkout from 6 to 7 (#138)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-20T13:13:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "077b7000f0b37ec6b4fc20755dc5eaeb51bf6beb",
          "body": "…ly (#144)\n\nescalated:install ran `npm install @escalated-dev/escalated` through\nLaravel's Process facade with the default 60s timeout. npm routinely\nexceeds that and throws ProcessTimedOutException, which bypassed the\nexisting \"show manual instructions\" fallback (it only handled a non-zero\nexit, no\n[…]\ncause.\n- Add regression tests: a faked npm timeout no longer aborts the\n  installer, and a non-zero npm exit still shows manual instructions.\n\nCo-authored-by: Matt Gros <mpge@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(install): raise npm/composer Process timeout and degrade graceful…",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-06-20T13:13:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "429cd1ebabdeab9a01d7994aad92db6b4cdd89f1",
          "body": "…ix installs (#145)\n\nComposer 2.9+ refuses to install packages affected by security advisories.\nTwo newly-published laravel/framework 11.x advisories (PKSA-m5cs-t1y6-qpcs,\nPKSA-3r5d-mb8f-1qw9) are not yet in config.audit.ignore, so\n`composer require laravel/framework:^11.0` can no longer resolve and\n[…]\nting 11.x ignores (root CI config only; does not\npropagate to host apps). Unblocks the red L^11 legs on dependabot PRs\n#138-#141 and on main.\n\nCo-authored-by: Matt Gros <mpge@users.noreply.github.com>",
          "is_bot": false,
          "headline": "ci: ignore two new laravel/framework 11.x advisories so the L^11 matr…",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-06-20T11:11:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "45da63245fc5f0e2e9db609f3616f43bf7f9bc1d",
          "body": "…cker/host-app/vue-3.5.38\n\nchore(deps-dev): bump vue from 3.5.35 to 3.5.38 in /docker/host-app",
          "is_bot": false,
          "headline": "Merge pull request #136 from escalated-dev/dependabot/npm_and_yarn/do…",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-06-12T04:10:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "097091d04d8dc7a34c93a30e2dfb6bc083d59adf",
          "body": "…3.5.38",
          "is_bot": false,
          "headline": "Merge branch 'main' into dependabot/npm_and_yarn/docker/host-app/vue-…",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-06-12T04:10:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "651cd7bf27312446d44da8f710e11d2acabfabd1",
          "body": "…cker/host-app/inertiajs/vue3-3.4.0\n\nchore(deps-dev): bump @inertiajs/vue3 from 3.3.1 to 3.4.0 in /docker/host-app",
          "is_bot": false,
          "headline": "Merge pull request #137 from escalated-dev/dependabot/npm_and_yarn/do…",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-06-12T04:09:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "723906c6d40e3c60abefc06056139a8730c2c73d",
          "body": "Bumps [@inertiajs/vue3](https://github.com/inertiajs/inertia/tree/HEAD/packages/vue3) from 3.3.1 to 3.4.0.\n- [Release notes](https://github.com/inertiajs/inertia/releases)\n- [Changelog](https://github.com/inertiajs/inertia/blob/3.x/CHANGELOG.md)\n- [Commits](https://github.com/inertiajs/inertia/commi\n[…]\ndependency-name: \"@inertiajs/vue3\"\n  dependency-version: 3.4.0\n  dependency-type: direct:development\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump @inertiajs/vue3 in /docker/host-app",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-12T03:24:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1620f8a44328f682017157269f3e3c4c1d510fc8",
          "body": "Bumps [vue](https://github.com/vuejs/core) from 3.5.35 to 3.5.38.\n- [Release notes](https://github.com/vuejs/core/releases)\n- [Changelog](https://github.com/vuejs/core/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/vuejs/core/compare/v3.5.35...v3.5.38)\n\n---\nupdated-dependencies:\n- dependency-name: vue\n  dependency-version: 3.5.38\n  dependency-type: direct:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump vue from 3.5.35 to 3.5.38 in /docker/host-app",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-12T03:23:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b9f642f23af1f7539f242cd04aa280cf1c2dfb4b",
          "body": "Add SECURITY.md security policy",
          "is_bot": false,
          "headline": "Merge pull request #135 from escalated-dev/chore/add-security-policy",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-06-10T00:43:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7d6f0e4c0293b90699571a2de6aedde30d1a58d4",
          "body": null,
          "is_bot": false,
          "headline": "Add SECURITY.md pointing to main Escalated security policy",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-06-10T00:36:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2ef9417e2e69c0ab87c9b4351c58f64c691a62a7",
          "body": "…cker/host-app (#134)\n\n* chore(deps-dev): bump @tailwindcss/postcss in /docker/host-app\n\nBumps [@tailwindcss/postcss](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/@tailwindcss-postcss) from 4.2.4 to 4.3.0.\n- [Release notes](https://github.com/tailwindlabs/tailwindcss/releases)\n- [C\n[…]\nigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Matt Gros <3311227+mpge@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump @tailwindcss/postcss from 4.2.4 to 4.3.0 in /do…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-06T14:11:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b7166574b613accf20a48fc71a5b7a3018885f69",
          "body": "Bumps [@inertiajs/vue3](https://github.com/inertiajs/inertia/tree/HEAD/packages/vue3) from 3.3.0 to 3.3.1.\n- [Release notes](https://github.com/inertiajs/inertia/releases)\n- [Changelog](https://github.com/inertiajs/inertia/blob/3.x/CHANGELOG.md)\n- [Commits](https://github.com/inertiajs/inertia/commi\n[…]\nrect:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump @inertiajs/vue3 in /docker/host-app (#133)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-06T14:10:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7e553700c991f451a22e12b2467a893da443c0ec",
          "body": "Bumps [tailwindcss](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/tailwindcss) from 4.2.4 to 4.3.0.\n- [Release notes](https://github.com/tailwindlabs/tailwindcss/releases)\n- [Changelog](https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md)\n- [Commits](https://github.co\n[…]\nrect:development\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump tailwindcss in /docker/host-app (#132)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-06T14:09:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a64ee25714b3a9a3c3867e960624ee647875858f",
          "body": "… (#130)\n\nBumps [axios](https://github.com/axios/axios) from 1.15.2 to 1.17.0.\n- [Release notes](https://github.com/axios/axios/releases)\n- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)\n- [Commits](https://github.com/axios/axios/compare/v1.15.2...v1.17.0)\n\n---\nupdated-dependenci\n[…]\nrect:development\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump axios from 1.15.2 to 1.17.0 in /docker/host-app…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-06T14:09:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c7a95c06522fd05b77c429d61b6dd1da6c2a2213",
          "body": "Bumps [@escalated-dev/escalated](https://github.com/escalated-dev/escalated) from 0.8.0 to 0.9.0.\n- [Release notes](https://github.com/escalated-dev/escalated/releases)\n- [Changelog](https://github.com/escalated-dev/escalated/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/escalated-dev/escal\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump @escalated-dev/escalated from 0.8.0 to 0.9.0 (#131)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-06T14:09:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "890c6bf893c2f33c109c19d5cc75b1363caa5a8b",
          "body": "- enable ESCALATED_ENABLE_NEWSLETTERS via .env.docker (artisan serve does not\n  forward OS-only env vars to its php -S worker, so it must live in .env)\n- apk add git in the assets stage: @escalated-dev/escalated pulls\n  @escalated-dev/locale via a github: URL, which npm needs git to resolve\n- bump demo host-app frontend to @escalated-dev/escalated ^0.9.0",
          "is_bot": false,
          "headline": "chore(docker): showcase newsletters in the demo",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-06-04T06:43:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "66d8a7624a2e5f883eab5ab7d67bb84a7e03f18b",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): 1.5.1",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-06-04T05:28:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d1de53acce794716c4c061c2ef2f1f17945aecbe",
          "body": "…lls (Composer 2.9 blocks advisory-affected packages)",
          "is_bot": false,
          "headline": "ci: ignore laravel/framework 11.x advisories so the L^11 matrix insta…",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-06-04T05:25:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dfd3637347cf7f14786f577dac8b073da15e23f2",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): 1.5.0",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-06-04T05:10:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8a2484bf77061360795c3ad3d8d0074c30f804a8",
          "body": "…#129)\n\n* feat(newsletters): enforce newsletters.manage on admin route group + newsletters.send on send actions\n\n* feat(permissions): expose escalated.permissions in Inertia shared props for frontend gating\n\n---------\n\nCo-authored-by: Matt Gros <mpge@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(newsletters): enforce newsletters.manage/.send on admin routes (…",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-06-04T05:09:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cb6a62990c47571e867427f56942c8b20a839944",
          "body": "…#128)\n\ncreated_by/added_by/sent_by used unsignedBigInteger, reintroducing the integer-only host-user-key assumption. Use Escalated::userForeignColumn (unsignedBigInteger by default -> identical schema for integer hosts; uuid/ulid/string for those hosts), like ticket_followers.user_id and tickets.assigned_to. FK columns (list_id/contact_id/template_id) stay bigint. 35 newsletter tests pass; Pint clean.\n\nCo-authored-by: Matt Gros <mpge@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(newsletter): UUID-safe user-id columns in newsletter migrations (…",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-06-02T15:47:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "93856711150310efd088ca3cd25169a6217d5f72",
          "body": "…ence) (#103)\n\n* feat(newsletters): add config keys (disabled by default)\n\n* feat(newsletters): create newsletter_lists table\n\n* feat(newsletters): create newsletter_list_members table\n\n* feat(newsletters): create newsletter_templates table\n\n* feat(newsletters): create newsletters table\n\n* feat(news\n[…]\ne\n  backoff writes were silently dropped without it).\n\nAdds dispatcher tests for rate-limit, backoff-skip, and first-N auto-pause.\n\n---------\n\nCo-authored-by: Matt Gros <mpge@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(newsletters): admin-only broadcast system (Wave 1, Laravel refer…",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-06-02T03:34:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d71664ea1537602cfda8731935451117aa3cede9",
          "body": "… (#127)\n\nPorts add_follower from the NestJS reference (escalated-nestjs#61). Laravel already has the ticket_followers pivot + Ticket::follow() (syncWithoutDetaching, idempotent), so this wires the executor case + validation allowlist only. Value is a host user key, trimmed and skipped when empty/0, mirroring assign_agent. Realizes discussion #88. Tests: follow + idempotent + empty-skip; 49 WorkflowEngine tests pass; Pint clean.\n\nCo-authored-by: Matt Gros <mpge@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(workflow): add_follower action - auto-subscribe ticket followers…",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-06-02T02:14:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "973ef89b9b397f2aed2fd94e9e928f97ae75c23e",
          "body": "CodeQL (actions/missing-workflow-permissions) flagged the run-tests\nworkflow for having no explicit `permissions` block, which leaves\nGITHUB_TOKEN at the repository default (often read/write). The test job\nonly checks out and runs Pest, so it needs nothing beyond `contents:\nread`. lint.yml (contents: write for auto-commit) and fossa.yml\n(contents: read) already declare explicit scopes.\n\nCo-authored-by: Matt Gros <mpge@users.noreply.github.com>",
          "is_bot": false,
          "headline": "ci: set least-privilege permissions on run-tests workflow (#126)",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-06-02T01:55:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b2bbc67e5b7add002d6d2119da533808d3017818",
          "body": "…9) (#122)\n\nTickets can now reference one or more host-app entities they are *about*\n(Project, Customer, asset, …), distinct from the requester (the person).\n\n- New Contracts\\TicketSubject (title/subtitle/url/color/icon) + a\n  PresentsAsTicketSubject trait with sane defaults.\n- escalated_ticket_subj\n[…]\na config allowlist\n  (escalated.ticket_subjects.types) so request input can't resolve an\n  arbitrary class.\n- Pest tests; README + CHANGELOG.\n\nCo-authored-by: Matt Gros <mpge@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(tickets): attachable ticket subjects + presentation contract (#8…",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-05-31T05:55:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "07f6b3eee1adef79b17c04bd149edf4316dfd2fe",
          "body": "…#124)\n\nbroadcastWith() read $reply->user_id / $reply->user, which don't exist on\nthe Reply model (it uses the polymorphic author_type/author_id + author()).\nEvery .reply.created payload therefore shipped author_id/author_name = null,\nrendering 'Unknown' for any consumer of the real-time event. Read\n[…]\nauthor relation (Ticketable display name, Users + Contacts) and add a\nnested author{id,name} mirroring ReplyResource. +Pest regression tests.\n\nCo-authored-by: Matt Gros <mpge@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(replies): include real author in ReplyCreated broadcast payload (…",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-05-31T05:54:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a9ab0605de35c38b65998297f7c6b7d023dde85f",
          "body": "- Add guarded migration to backfill skills routing columns that v1.4.0\n  added by editing an already-run create migration (broke skill save on\n  upgraded installs).\n- Restore agent existence validation in AssignTicketRequest (422 not 500),\n  keeping int|string acceptance.\n- Make AssignmentService $s\n[…]\nk)\n  to keep the v1.3.0 single-arg constructor working.\n- CHANGELOG: 1.4.1 + upgrade notes for the int|string TicketDriver/Ticket\n  widening.\n\nCo-authored-by: Matt Gros <mpge@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix: upgrade-safety regressions found in v1.4.0 audit (#120)",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-05-29T11:51:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "acf98d9ca1d47fb1cfc7f5cc6702e3364e77a00d",
          "body": "…#116)\n\nBumps [vue](https://github.com/vuejs/core) from 3.5.33 to 3.5.35.\n- [Release notes](https://github.com/vuejs/core/releases)\n- [Changelog](https://github.com/vuejs/core/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/vuejs/core/compare/v3.5.33...v3.5.35)\n\n---\nupdated-dependencies:\n- de\n[…]\nrect:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump vue from 3.5.33 to 3.5.35 in /docker/host-app (…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-29T03:48:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a80c1ff7d804402e8213f3786260df0d565187ef",
          "body": "Co-authored-by: Matt Gros <mpge@users.noreply.github.com>",
          "is_bot": false,
          "headline": "docs: add Packagist version badge linking to the package page (#119)",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-05-29T03:44:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "42edaf46ba48387a5c8470d6d5696872dc2a5421",
          "body": "…pp (#118)\n\nBumps [postcss](https://github.com/postcss/postcss) from 8.5.13 to 8.5.15.\n- [Release notes](https://github.com/postcss/postcss/releases)\n- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/postcss/postcss/compare/8.5.13...8.5.15)\n\n---\n\n[…]\nrect:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump postcss from 8.5.13 to 8.5.15 in /docker/host-a…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-29T03:39:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0fd5fe9075550d69b15e87b55aa5ecdd3728544f",
          "body": "Bumps [@escalated-dev/escalated](https://github.com/escalated-dev/escalated) from 0.7.1 to 0.8.0.\n- [Release notes](https://github.com/escalated-dev/escalated/releases)\n- [Changelog](https://github.com/escalated-dev/escalated/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/escalated-dev/escal\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump @escalated-dev/escalated in /docker/host-app (#117)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-29T03:39:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f368bf6a4465f508bb45854a35efff19cf02bbfb",
          "body": "…(#115)\n\nBumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 8.0.10 to 8.0.14.\n- [Release notes](https://github.com/vitejs/vite/releases)\n- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)\n- [Commits](https://github.com/vitejs/vite/commits/v8.0.1\n[…]\nrect:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump vite from 8.0.10 to 8.0.14 in /docker/host-app …",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-29T03:39:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3cfc96ae28477a112d3bd178c4e742f281d43fcf",
          "body": "Bumps [@vitejs/plugin-vue](https://github.com/vitejs/vite-plugin-vue/tree/HEAD/packages/plugin-vue) from 6.0.6 to 6.0.7.\n- [Release notes](https://github.com/vitejs/vite-plugin-vue/releases)\n- [Changelog](https://github.com/vitejs/vite-plugin-vue/blob/main/packages/plugin-vue/CHANGELOG.md)\n- [Commit\n[…]\nrect:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump @vitejs/plugin-vue in /docker/host-app (#114)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-29T03:39:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "525db5497cd5e0398c1f27854b47c7f731a19360",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): 1.4.0",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-05-29T02:46:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a05bcefbd34af6501c8f765567f224a41b23f530",
          "body": "qs 6.15.1 (transitive via @inertiajs/core in the demo host-app) is\naffected by CVE-2026-8723 (NULL pointer dereference, medium 6.3). 6.15.2\nis a patch fix with identical dependencies (side-channel ^1.1.0), so this\nis a minimal lockfile-only bump.\n\nCo-authored-by: Matt Gros <mpge@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(deps): bump qs 6.15.1 -> 6.15.2 (CVE-2026-8723) (#113)",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-05-29T01:30:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ec8d65dc100bfd07c933d14742527afcac779403",
          "body": "* feat(users): auto-detect host user key type for migration columns\n\nBuilds on the int|string fix (#109/#110): the package's user-referencing\ncolumns now match the host user model's key type automatically, so UUID/ULID/\nstring-keyed apps migrate with no manual edits.\n\n- Escalated::userKeyType() refl\n[…]\ndel uses HasUuids/HasUlids.\n\nAdds assign() regression tests (string id happy-path + clean\nInvalidArgumentException on unknown id).\n\n---------\n\nCo-authored-by: Matt Gros <mpge@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(users): auto-detect host user key type for migration columns (#112)",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-05-29T01:14:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e091c670707423e77b0451c0abe5c22f9d523f9d",
          "body": "Fixes a TypeError 500 (Argument #2 ($userId) must be of type int, string given)\nwhen host apps with UUID/string user primary keys open /support/admin/tickets.\n\n- SavedView::scopeForUser now takes (Builder $query, int|string $userId): Builder,\n  mirroring Mention::scopeForUser (immediate bug).\n- Rela\n[…]\ncolumns (publish migrations + switch to uuid/string).\n- Regression test: SavedView::forUser() and Mention::forUser() with a UUID.\n\nRefs #109.\n\nCo-authored-by: Matt Gros <mpge@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(users): support UUID/string host user keys throughout (#110)",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-05-29T01:08:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fd9eaa57fb7d4c0b25628a454fa3e67ef4db5323",
          "body": "Replace the hardcoded English \"Custom action dispatched.\" string in the\nagent and API ticket controllers with the\nescalated::messages.ticket.custom_action_dispatched lang key, matching the\ni18n convention used by every other ticket flash/response message\n(macro_applied, tags_updated, etc.). Adds the key to all 14 locales.\n\nFollow-up to #107.\n\nCo-authored-by: Matt Gros <mpge@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(tickets): localize custom action dispatched message (#108)",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-05-28T21:08:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0e4585fd11f0446a2cf83fc68c413109ebe7ad77",
          "body": "* WIP Custom Actions\n\n* Custom Actions",
          "is_bot": false,
          "headline": "feat(tickets): custom ticket actions via events (#107)",
          "author_name": "Matthew Weber",
          "author_login": "matalaweb",
          "committed_at": "2026-05-28T19:20:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4eb9be196428d09aaa43efd2674ce6f6ae8c99eb",
          "body": "Co-authored-by: Matt Gros <mpge@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Clarify final setup steps (#106)",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-05-27T01:12:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dd460200bec043bd71ac1070d6d75bdaf21bcd76",
          "body": "Co-authored-by: Matt Gros <mpge@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(api): add mobile customer and guest support api (#104)",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-05-26T02:41:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f3dd0f7572ca6fb5c5138edd8ebcde8bf09ded68",
          "body": null,
          "is_bot": false,
          "headline": "style: pint binary_operator_spaces on plugin install test fixture",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-05-19T17:00:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "48704cbb926847e4ab534064ab00b1c579c83176",
          "body": "…eypair\n\ntests/Fixtures/rsa.priv contained a real RSA-2048 private key, and\nescalated-laravel is a public repo (escalated-dev/escalated-laravel).\nThat made the keypair leaked from the moment the original commit\n(11846df, Phase 2.2f) hit GitHub. Treat both halves as compromised\n— never trust them as \n[…]\ns public key into\ntheir plugin trust-anchor config \"because the test fixture showed\nhow\", they should rotate immediately — the corresponding private\nkey is in public GitHub history and will remain so.",
          "is_bot": false,
          "headline": "fix(tests): rotate plugin-install RSA fixtures to runtime-generated k…",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-05-19T15:55:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "11846df5dfb63deeb7bf06a824b7225f9aefe6a7",
          "body": "Phase 2.2e shipped the publish side (esc-plugin publish + cloud\nMarketplacePluginVersionController). This adds the consumer-side\ncounterpart for backend Laravel hosts:\n\n    php artisan escalated:plugin:install <publisher>/<slug>\n\nThe command resolves the marketplace manifest envelope (defaults to\nth\n[…]\nha256 mismatch, marketplace 404,\nexisting-dir without --force, --force overwrite, valid RSA\nsignature, and signature mismatch — using an RSA fixture keypair\ncopied from the existing SSO test fixtures.",
          "is_bot": false,
          "headline": "feat(plugins): add verified marketplace install command (Phase 2.2f)",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-05-19T03:03:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "94224f1d5fe559705bf37ee4e6133d22cf8f6c6b",
          "body": "Bumps [@escalated-dev/escalated](https://github.com/escalated-dev/escalated) from 0.7.1 to 0.8.0.\n- [Release notes](https://github.com/escalated-dev/escalated/releases)\n- [Changelog](https://github.com/escalated-dev/escalated/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/escalated-dev/escal\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump @escalated-dev/escalated in /docker/host-app (#102)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-16T02:17:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f27f53b2c2441674003d83a3fe40e1ab9bdd83f0",
          "body": "Bumps [@escalated-dev/escalated](https://github.com/escalated-dev/escalated) from 0.7.1 to 0.8.0.\n- [Release notes](https://github.com/escalated-dev/escalated/releases)\n- [Changelog](https://github.com/escalated-dev/escalated/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/escalated-dev/escal\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump @escalated-dev/escalated from 0.7.1 to 0.8.0 (#101)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-16T02:17:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a620b064b489692e4ec074fd3d19ad242dd2dfbb",
          "body": "…le-bearing users (#100)\n\n- DB::transaction now wraps store() and update() so a syncAgents() failure\n  rolls back the skill row's name + routing JSON changes. Previously a\n  partial failure left the skill mutated but with stale agent_skill rows.\n- agents.*.user_id validation now rejects user IDs tha\n[…]\n\n  (host hasn't adopted the convention) the check is skipped so behaviour\n  is unchanged for those hosts.\n- New feature test covers the role-rejection branch.\n\nSurfaced by post-merge review of PR #95.",
          "is_bot": false,
          "headline": "fix(skills): wrap store/update in transactions; restrict agents to ro…",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-05-13T20:32:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d8804079ec81f6434427a52f78215d2a5e17be0f",
          "body": null,
          "is_bot": false,
          "headline": "fix(2fa): show recovery codes after successful confirmation (#97)",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-05-11T01:39:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "97ca3db485502b220612dee667566dfe44a10769",
          "body": "* feat(skills): implement skills-based routing\n\n* style: apply Pint auto-fixes",
          "is_bot": false,
          "headline": "feat: implement skills-based routing (#95)",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-05-11T01:39:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9ec32cd5af6d3da5eba4ad8815c135c99bd6c3a1",
          "body": null,
          "is_bot": false,
          "headline": "feat(sso): expand provider configuration surface (#96)",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-05-11T01:39:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1b2c5b3e16a68056f1f9f90a6df6c733393a4519",
          "body": "* feat(admin): users-management page with admin/agent role toggles\n\nThe admin panel had no UI for granting or revoking admin/agent access on\nhost users — admins had to drop into tinker or run a seeder. New\nUserController surfaces the host User table (paged, searchable) and a\nPATCH endpoint flips is_\n[…]\nolumns the install command tells hosts to add). Hosts\nthat wire the gates differently (Spatie roles, custom pivots) should\noverride this controller in their own routes.\n\n* style: apply Pint auto-fixes",
          "is_bot": false,
          "headline": "feat(admin): users-management page with admin/agent role toggles (#94)",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-05-10T21:49:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6c8ce2058388d94c3280d30495dc5d1198a15c11",
          "body": "Bumps [@inertiajs/vue3](https://github.com/inertiajs/inertia/tree/HEAD/packages/vue3) from 2.3.23 to 3.1.1.\n- [Release notes](https://github.com/inertiajs/inertia/releases)\n- [Changelog](https://github.com/inertiajs/inertia/blob/3.x/CHANGELOG.md)\n- [Commits](https://github.com/inertiajs/inertia/comm\n[…]\nrect:development\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump @inertiajs/vue3 in /docker/host-app (#93)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-10T13:35:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0389bc5613122a0fd01588e005297f3afca68364",
          "body": "Resolves #88 root cause. The reporter's `migrate -vvv` output showed:\n\n  SQLSTATE[HY000]: General error: 1005 Can't create table\n  `yog_stock`.`escalated_macros` (errno: 150 \"Foreign key constraint\n  is incorrectly formed\")\n\nThis is the legacy MariaDB / MySQL 5.x error wording for FK column-type\ninc\n[…]\n— anyone with a successful prior\ninstall keeps their existing FK constraints (Laravel doesn't re-run\nmigrations once recorded). Anyone hit by #88 sees migrations 14+ run\ncleanly on their next attempt.",
          "is_bot": false,
          "headline": "fix(migrations): drop FK constraints to host `users` table (#92)",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-05-07T14:21:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bdeb56e057491619a6934e587789728ed6ac6f80",
          "body": "…m (#91)\n\nIssue #88 reported a \"table doesn't exist\" failure at the seeder step. The deeper cause was a migration earlier in the chain failing in the user's environment, but `runMigrations()` was using `callSilently('migrate')` and the `task` component, which together hide the actual SQL error — the\n[…]\nool — but the install flow now refuses to seed if migrate failed, which it already did, and shows step_seed in the printed instructions when seed didn't happen.\n\nNo translation key changes.\n\nRefs #88.",
          "is_bot": false,
          "headline": "fix(install): surface migrate / seed errors instead of swallowing the…",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-05-07T14:09:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1791741be1c829e31987c04608af43d4657a8988",
          "body": "* feat(i18n): bridge install translations from escalated-dev/locale\n\nThe central `escalated-dev/locale` package was already declared as a composer dep and \"loaded\" by the service provider, but it wasn't actually serving any translations: its JSON files use camelCase keys (matching the Vue frontend c\n[…]\n `CentralLocaleBridgeTest` locks in the behavior: bridge populates the loaded array, resolved values match central JSON exactly, and placeholder syntax rewriting works.\n\n* style: apply Pint auto-fixes",
          "is_bot": false,
          "headline": "feat(i18n): bridge install translations from escalated-dev/locale (#90)",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-05-07T03:42:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "94e5c44245e6b2a606e46451d67dd222cd33b022",
          "body": "Resolves #88. The install command was publishing migration files but never running them, then immediately invoking `PermissionSeeder` which inserts into `escalated_permissions` — a table that didn't exist yet. Every clean install hit `SQLSTATE[42S02]: Base table or view not found` at the seeder step\n[…]\nage's `resources/lang/{locale}/commands.php` fallback files; the central JSON files are loaded but don't actually resolve any of the namespaced PHP-side keys. Aligning the two is a separate follow-up.",
          "is_bot": false,
          "headline": "fix(install): run migrations before seeding permissions (#89)",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-05-07T01:47:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "34d747c540f987718621313e625442e057e33d99",
          "body": "The auto-generated index name is escalated_delayed_actions_execute_at_executed_cancelled_index (61 chars). That fits MySQL's 64-char limit with the default `escalated_` prefix, but anyone configuring `escalated.table_prefix` to a value longer than 13 characters would hit the same \"Identifier name to\n[…]\nfix.\n\nBackwards compatible: the migration runs only once. Anyone for whom it already succeeded has the long auto-generated name in their schema; the new short name only takes effect on fresh installs.",
          "is_bot": false,
          "headline": "fix(migration): assign explicit name to delayed_actions index (#87)",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-05-05T23:42:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "679f47f73f8e7f1fb5325d69b259c0cdcca9978f",
          "body": "Resolve the following SQL error\r\n\r\nSyntax error or access violation: 1059 Identifier name 'escalated_ticket_links_parent_ticket_id_child_ticket_id_link_type_unique' is too long",
          "is_bot": false,
          "headline": "Resolve Unique Index name too long error (#86)",
          "author_name": "Matthew Weber",
          "author_login": "matalaweb",
          "committed_at": "2026-05-05T23:39:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "16b8be56bb7e89decda1100a8c5ff884780a77b5",
          "body": "* build(deps): require escalated-dev/locale ^0.1.0\n\nAdd central translations package as a dependency. Resolves to vendor/escalated-dev/locale/locales/{locale}/{group}.php after composer install.\n\nBlocked on escalated-dev/escalated-locale v0.1.0 publish — composer install will fail until then; that i\n[…]\ncalated-dev/escalated-locale via vcs repository. Once the\npackage is submitted to Packagist this block can be removed; until then\nthis lets composer install work today (verified: pest 606 tests pass).",
          "is_bot": false,
          "headline": "feat(i18n): consume central translations from escalated-dev/locale (#85)",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-05-02T19:19:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "71e8e86f3a314d89f5f9e6e388bd896df2338517",
          "body": "Bundles dependabot PRs #80, #81, #82, #83.\nTailwind 4 migration: @tailwind directives -> @import; @tailwindcss/postcss; remove redundant autoprefixer.",
          "is_bot": false,
          "headline": "chore(deps): modernize host-app frontend (Vite 8 + Tailwind 4) (#84)",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-05-02T00:32:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "de9f3bc82c054ed9796d269a00c12e95ea6e2b9e",
          "body": "Bumps [@escalated-dev/escalated](https://github.com/escalated-dev/escalated) from 0.6.0 to 0.7.1.\n- [Release notes](https://github.com/escalated-dev/escalated/releases)\n- [Changelog](https://github.com/escalated-dev/escalated/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/escalated-dev/escal\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump @escalated-dev/escalated in /docker/host-app (#79)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-01T18:28:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c31bf886f212f98bb0439afa840144fb06f30d10",
          "body": "Bumps [stefanzweifel/git-auto-commit-action](https://github.com/stefanzweifel/git-auto-commit-action) from 5 to 7.\n- [Release notes](https://github.com/stefanzweifel/git-auto-commit-action/releases)\n- [Changelog](https://github.com/stefanzweifel/git-auto-commit-action/blob/master/CHANGELOG.md)\n- [Co\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump stefanzweifel/git-auto-commit-action from 5 to 7 (#76)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-01T18:28:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0616f47b994e173ab27dd71be2cbb71ebb771ffc",
          "body": "…alated-0.7.1",
          "is_bot": false,
          "headline": "Merge pull request #78 from dependabot/npm_and_yarn/escalated-dev/esc…",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-05-01T13:56:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9e815eeafdc8fd5f635d4776afb2ba5ab1fab401",
          "body": null,
          "is_bot": false,
          "headline": "Merge pull request #77 from dependabot/github_actions/actions/checkout-6",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-05-01T13:52:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fb3903a056b01e7ae4fa1049d3366923b3b05b32",
          "body": "Bumps [@escalated-dev/escalated](https://github.com/escalated-dev/escalated) from 0.6.0 to 0.7.1.\n- [Release notes](https://github.com/escalated-dev/escalated/releases)\n- [Changelog](https://github.com/escalated-dev/escalated/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/escalated-dev/escal\n[…]\ncy-name: \"@escalated-dev/escalated\"\n  dependency-version: 0.7.1\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump @escalated-dev/escalated from 0.6.0 to 0.7.1",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-01T13:27:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e82930eee6f95a79a5b6b654b6f63057159a8d1d",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 6.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/v4...v6)\n\n---\nupdated-dependenc\n[…]\n:\n- dependency-name: actions/checkout\n  dependency-version: '6'\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/checkout from 4 to 6",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-01T13:18:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "08be4742756c52f9a1cb9c56d3293203998e610a",
          "body": null,
          "is_bot": false,
          "headline": "ci: add dependabot config",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-05-01T13:12:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4bbdbafa74cdd3a21678672d8eacdb454957b3e8",
          "body": null,
          "is_bot": false,
          "headline": "ci(fossa): add FOSSA workflow + badges across READMEs",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-05-01T02:52:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4285e760e0f1526e2bcfd6efd1f9721b08e2b95b",
          "body": "The admin settings page (PublicTicketsSettingsController) has been\npersisting guest_policy_mode / guest_policy_user_id /\nguest_policy_signup_url_template to EscalatedSettings, but\nWidgetController::createTicket wrote guest_name / guest_email /\nguest_token unconditionally regardless of mode — so the \n[…]\nver: unassigned mode (regression test for the\ndefault path), guest_user with valid user id, guest_user with missing\nuser id fallback, prompt_signup path. Full WidgetControllerTest suite\n13 → 13 green.",
          "is_bot": false,
          "headline": "fix(widget): honor guest_policy_mode on public ticket creation (#72)",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-04-27T00:44:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0b1dda2768531bfed3b0cdbdaecdf3ce82df0320",
          "body": "…To verification (#75)\n\nWires MessageIdUtil (#68) into InboundEmailService.findTicketByEmail\nso inbound mail routes to the correct ticket via four resolution\nstrategies, in priority order:\n\n  1. In-Reply-To header parsed via MessageIdUtil — the reply is\n     threading off a Message-ID we issued (col\n[…]\ny-To rejection (wrong secret → no ticket match)\n\nThe signed Reply-To branch only activates when\nescalated.email.inbound_secret is configured — safe default of\nskipping when the admin hasn't set a key.",
          "is_bot": false,
          "headline": "feat(inbound): MessageIdUtil-based Message-ID parsing + signed Reply-…",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-04-27T00:36:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3dea62c0e6f1cf82ab711a8da11513758207f39f",
          "body": "* feat(mail): wire MessageIdUtil into all 7 ticket notifications\n\nAdds NotificationThreading helper that centralizes the RFC 5322\nthreading headers + signed Reply-To so every outbound notification\ncarries consistent headers:\n\n- NewTicketNotification: applyAnchor (Message-ID = <ticket-id@domain>)\n- T\n[…]\n parametric test at the end iterates every notification class and\nasserts the signed Reply-To is present, catching regressions if a\nnew notification is added but forgets to call NotificationThreading.",
          "is_bot": false,
          "headline": "feat(mail): wire MessageIdUtil into all 7 ticket notifications (#74)",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-04-26T01:40:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "209f05b861d31d99fffc0624f86b6b2f301f1297",
          "body": "…s (#73)\n\nSecond wave of the widget/settings-disconnection sweep — same bug that\nwe just fixed across 6 frameworks for widget/guest submissions also\naffects inbound email. InboundEmailService::createNewTicket wrote\nguest_name / guest_email / guest_token unconditionally when the sender\nwasn't a regis\n[…]\n.\n\n3 new Pest cases added to InboundEmailServiceTest — guest_user routing,\nmisconfigured fallback, prompt_signup path. All 15 service tests still\ngreen.\n\nMirrors the NestJS fix in escalated-nestjs#28.",
          "is_bot": false,
          "headline": "fix(inbound): honor guest_policy_mode on inbound-email-created ticket…",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-04-26T01:39:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f8f00a199e929c60abe5731463939fce33e76d12",
          "body": "* feat(admin): PublicTicketsSettingsController for guest policy\n\nAdds a controller + two routes that back the\nAdmin/Settings/PublicTickets.vue page in the shared escalated\nfrontend package. Persists `guest_policy_mode`,\n`guest_policy_user_id`, and `guest_policy_signup_url_template`\nvia the existing \n[…]\ns can switch\nthe public-ticket ownership mode at runtime without a redeploy.\n\nMatches the CsatSettings / SsoSettings / DataRetentionController\npattern already in place.\n\n* style: apply Pint auto-fixes",
          "is_bot": false,
          "headline": "feat(admin): PublicTicketsSettingsController for guest policy (#71)",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-04-26T01:38:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0b5e333df4709f6b38ca8c735365541895b37d36",
          "body": "Ports the NestJS email/message-id.ts helpers to Laravel. Mirrors the\nSpring / WordPress / .NET / Phoenix ports.\n\nAPI:\n  buildMessageId(ticketId, replyId, domain)\n  parseTicketIdFromMessageId(raw)\n  buildReplyTo(ticketId, secret, domain)\n  verifyReplyTo(address, secret)\n\nUses hash_hmac('sha256', ...)\n[…]\ntNotification / SlaBreachNotification\ninline Message-ID building to this util, wire signed Reply-To into the\noutbound headers, and extend the Mailgun / Postmark inbound adapters\nto call verifyReplyTo.",
          "is_bot": false,
          "headline": "feat(mail): add MessageIdUtil for RFC 5322 + signed Reply-To (#68)",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-04-26T01:38:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6f1e0b63290bb232723f4c6e84c6d769e688b804",
          "body": "* feat(contact): add Contact model for public-ticket dedupe (Pattern B convergence)\n\nBrings Laravel in line with the Pattern B design shipped in\nescalated-nestjs PR #17: a first-class Contact entity identifies\nguest requesters by email, enabling dedupe across tickets and a\nclean promote-to-user flow\n[…]\nat submissions (different casing, same email)\n    onto a single Contact row with both tickets linked\n\nFull suite: 568 passed (+2 new), 1 pre-existing risky (unrelated).\n\n* style: apply Pint auto-fixes",
          "is_bot": false,
          "headline": "feat(contact): Contact model for public-ticket dedupe (Pattern B) (#67)",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-04-26T01:31:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3e4494961b31db49bb487c33c1e8ab36f353c44b",
          "body": "* fix(customer): pass priority (and other visible filters) through to the driver\n\nCloses #64\n\nThe Customer `TicketController@index` was dropping the `priority`\nURL param before it reached the driver:\n\n    $request->only(['status', 'search', 'sort_by', 'sort_dir'])\n    //              ^^^ priority mi\n[…]\ny priority (the actual regression — fails\n  on `main`, passes after this PR)\n\nAll 4 pass. The 7 existing `Feature/Customer/TicketControllerTest`\ncases continue to pass.\n\n* style: apply Pint auto-fixes",
          "is_bot": false,
          "headline": "fix(customer): pass priority filter through to the driver (#64) (#66)",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-04-20T15:19:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "70ada066b351a9a7713781d797ec35637224157b",
          "body": "…ured display column (#65)\n\nCloses #63\n\nEscalated's ticket search (agent + customer areas) assumed a `name`\ncolumn on the `users` table and would either raise\n\"column users.name does not exist\" against Postgres or silently\nreturn an empty result against sqlite when the column was absent.\nHosts that \n[…]\nlyUserSearch` no longer references the\n  missing column\n- `Escalated::userOptions()` pivots to email when the display\n  column is gone\n\nAll pass. Existing admin + agent ticket suites continue to pass.",
          "is_bot": false,
          "headline": "fix: fall back to email-only search when users table lacks the config…",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-04-20T14:41:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9cad531a54c96f079ccb3b5d40340aadef4d5ddf",
          "body": "Laravel's publishesMigrations() stamps a fresh timestamp onto each file on\nevery invocation, so running escalated:install twice duplicated all 53\npackage migrations and caused migrate to fail with \"table already exists\".\nThe --force flag did not help because the duplicate filenames differ by\ntimesta\n[…]\n-force is set; with --force it first deletes the stale\ncopies so the new batch replaces the old. Adds 4 unit tests and a new\nmigrations_already_published translation key in all 14 locales.\n\nCloses #61",
          "is_bot": false,
          "headline": "fix(install): skip publishing migrations when already published (#62)",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-04-19T16:15:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5b521be94ad68f03abc1465c665fbac79b64a691",
          "body": null,
          "is_bot": false,
          "headline": "chore: changelog for v1.2.1",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-04-19T00:17:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1d1de13ef372172c1eef90aa9a42ba84e5afc2e0",
          "body": "fix(reporting): emit Postgres-compatible SQL for date/time helpers",
          "is_bot": false,
          "headline": "Merge pull request #60 from escalated-dev/fix/postgres-date-functions",
          "author_name": "Matt Gros",
          "author_login": "mpge",
          "committed_at": "2026-04-18T17:49:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 13,
      "commits_last_year": 292,
      "latest_release_at": "2026-06-04T05:29:13Z",
      "latest_release_tag": "v1.5.1",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 24,
      "days_since_latest_release": 56,
      "mean_days_between_releases": 5.1
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 62,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "escalated-dev/escalated-laravel",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "support",
            "laravel",
            "tickets",
            "helpdesk",
            "customer-support"
          ],
          "ecosystem": "packagist",
          "matches_repo": true,
          "registry_url": "https://packagist.org/packages/escalated-dev/escalated-laravel",
          "is_deprecated": false,
          "latest_version": "v1.5.1",
          "repository_url": "https://github.com/escalated-dev/escalated-laravel",
          "versions_count": 26,
          "total_downloads": 5848,
          "dependents_count": 1,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 2063,
          "first_published_at": null,
          "latest_published_at": "2026-06-04T05:28:48Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 56
        }
      ]
    },
    "popularity": {
      "forks": 7,
      "stars": 27,
      "watchers": 3,
      "fork_history": {
        "days": [
          {
            "date": "2026-02-09",
            "count": 1
          },
          {
            "date": "2026-02-17",
            "count": 1
          },
          {
            "date": "2026-03-02",
            "count": 1
          },
          {
            "date": "2026-03-23",
            "count": 1
          },
          {
            "date": "2026-04-04",
            "count": 1
          },
          {
            "date": "2026-06-19",
            "count": 1
          },
          {
            "date": "2026-07-27",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 7,
        "total_forks": 7
      },
      "star_history": null,
      "open_issues_and_prs": 1
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [],
      "largest_source_bytes": 46189,
      "source_files_sampled": 582,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "composer.json",
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm",
        "packagist"
      ],
      "dependencies": [
        {
          "name": "escalated-dev/locale",
          "manifest": "composer.json",
          "ecosystem": "packagist",
          "version_constraint": "^0.1.8"
        },
        {
          "name": "illuminate/contracts",
          "manifest": "composer.json",
          "ecosystem": "packagist",
          "version_constraint": "^11.0|^12.0|^13.0"
        },
        {
          "name": "inertiajs/inertia-laravel",
          "manifest": "composer.json",
          "ecosystem": "packagist",
          "version_constraint": "^2.0|^3.0"
        },
        {
          "name": "league/commonmark",
          "manifest": "composer.json",
          "ecosystem": "packagist",
          "version_constraint": "^2.0"
        },
        {
          "name": "symfony/dom-crawler",
          "manifest": "composer.json",
          "ecosystem": "packagist",
          "version_constraint": "^6.0|^7.0"
        },
        {
          "name": "@escalated-dev/escalated",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.9.0"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 1,
        "merged_prs": 133,
        "open_issues": 0,
        "closed_ratio": 1,
        "closed_issues": 16,
        "closed_unmerged_prs": 14
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "mpge",
          "commits": 231,
          "avatar_url": "https://avatars.githubusercontent.com/u/3311227?v=4"
        },
        {
          "type": "User",
          "login": "matalaweb",
          "commits": 18,
          "avatar_url": "https://avatars.githubusercontent.com/u/4079247?v=4"
        },
        {
          "type": "User",
          "login": "marufmax",
          "commits": 4,
          "avatar_url": "https://avatars.githubusercontent.com/u/7222229?v=4"
        },
        {
          "type": "User",
          "login": "codearachnid",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/755025?v=4"
        }
      ],
      "contributors_sampled": 4,
      "top_contributor_share": 0.906
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "laravel.yml",
        "lint.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "25 out of 25 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/5 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 11 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 7 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 10,
            "reason": "SAST tool is run on all commits",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 9,
            "reason": "1 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "db7d6832c2738a67fc294a59071d7fc757d90eae",
        "ran_at": "2026-07-30T10:35:57Z",
        "aggregate_score": 6.1,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-30T10:35:08Z",
      "oldest_open_prs": [
        {
          "number": 163,
          "created_at": "2026-07-24T03:24:22Z",
          "last_comment_at": "2026-07-24T03:24:22Z",
          "last_comment_author": "dependabot"
        }
      ],
      "last_merged_pr_at": "2026-07-30T10:33:00Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/escalated-dev/escalated-laravel",
    "host": "github.com",
    "name": "escalated-laravel",
    "owner": "escalated-dev"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "good",
      "name": "Overall health",
      "note": "The weighted overall 66 is calibrated to 77 on the published index scale (record calibration 2026-08-02).",
      "notes": [
        {
          "code": "overall_calibration",
          "params": {
            "raw": 66,
            "calibrated": 77,
            "calibration": "2026-08-02"
          }
        }
      ],
      "value": 77,
      "inputs": {
        "security": 61,
        "vitality": 89,
        "community": 41,
        "governance": 60,
        "calibration": "2026-08-02",
        "engineering": 81,
        "ai_readiness": 43,
        "weighted_overall_raw": 66
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 89,
        "weight": 0.21,
        "metrics": [
          {
            "key": "development_activity",
            "band": "excellent",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 81,
            "inputs": {
              "commits_last_year": 292,
              "human_commit_share": 0.62,
              "days_since_last_push": 0,
              "active_weeks_last_year": 24
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "24/52 weeks with commits",
                "points": 16.6,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 24
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "292 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 292
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 7 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "exceptional",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 13,
              "latest_release_tag": "v1.5.1",
              "releases_from_tags": false,
              "days_since_latest_release": 56,
              "mean_days_between_releases": 5.1
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "13 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 13
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 56 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 56
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~5.1 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 5.1
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "exceptional",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "weak",
        "name": "Community & Adoption",
        "value": 41,
        "weight": 0.17,
        "metrics": [
          {
            "key": "popularity",
            "band": "at_risk",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 31,
            "inputs": {
              "forks": 7,
              "stars": 27,
              "watchers": 3,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "27 stars",
                "points": 23,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 27
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "7 forks",
                "points": 6.5,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "3 watchers",
                "points": 1.7,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "readme_badges": null,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "readme_badge_services": [],
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "weak",
            "name": "Ecosystem adoption (downloads)",
            "note": null,
            "notes": [],
            "value": 46,
            "inputs": {
              "packages": [
                "escalated-dev/escalated-laravel"
              ],
              "dependents": 1,
              "ecosystems": "packagist",
              "total_downloads": 5848,
              "monthly_downloads": 2063
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "2,063 downloads/month across packagist",
                "points": 44.2,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 2063,
                      "ecosystems": "packagist"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "1 packages depend on it",
                "points": 2,
                "status": "partial",
                "details": [
                  {
                    "code": "registry_dependents",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 60,
        "weight": 0.23,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "at_risk",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 26,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 4,
              "top_contributor_share": 0.906
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 91% of commits",
                "points": 2.1,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 91
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "4 contributors",
                "points": 5.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 11 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Newcomer PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "newcomer_pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 79,
            "inputs": {
              "merged_prs": 133,
              "open_issues": 0,
              "closed_issues": 16,
              "prs_merged_7d": null,
              "prs_decided_7d": null,
              "prs_merged_30d": null,
              "prs_decided_30d": null,
              "issue_closed_ratio": 1,
              "closed_unmerged_prs": 14,
              "first_time_authors_30d": null,
              "first_time_prs_merged_30d": null,
              "first_time_prs_decided_30d": null
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "100% of issues closed",
                "points": 42,
                "status": "met",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 42
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "133/147 decided PRs merged",
                "points": 27.1,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 133,
                      "decided": 147
                    }
                  }
                ],
                "max_points": 30
              },
              {
                "key": "newcomer_pr_acceptance",
                "name": "Newcomer PR acceptance",
                "detail": "no first-time contributor's PR decided in 30d",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_newcomer_prs",
                    "params": {
                      "days": 30
                    }
                  }
                ],
                "max_points": 13
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/5 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "weak",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 49,
            "inputs": {
              "followers": 10,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "escalated-dev",
              "public_repos": 31,
              "account_age_days": 173
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "10 followers of escalated-dev",
                "points": 7.5,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 10,
                      "login": "escalated-dev"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "31 public repos, account ~0 yr old",
                "points": 11.9,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 31
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "exceptional",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "escalated-dev/escalated-laravel"
              ],
              "ecosystems": "packagist",
              "any_deprecated": false,
              "min_days_since_publish": 56
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on packagist",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "packagist"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 56 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 56
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "26 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 26
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "excellent",
        "name": "Engineering Quality",
        "value": 81,
        "weight": 0.19,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "2 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "25 out of 25 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "exceptional",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "topics": [
                "laravel"
              ],
              "has_wiki": true,
              "homepage": "https://escalated.dev/framework/laravel",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://escalated.dev/framework/laravel",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "1 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 61,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Packaging, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "packaging",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 61,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 6.1
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "25 out of 25 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/5 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 11 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 7 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is run on all commits",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "1 existing vulnerabilities detected",
                "points": 6.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "exceptional",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "commit_weight_rule": {
                "min_commits": 50,
                "min_commit_share": 0.1
              },
              "review_only_matches": 0,
              "below_threshold_exposures": [],
              "assessed_self_published_locations": 6
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "weak",
        "name": "AI Readiness",
        "value": 43,
        "weight": 0.04,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "weak",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.968,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "60 of 62 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 60,
                      "sampled": 62
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "weak",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "package-lock.json"
              ],
              "has_dockerfile": true,
              "typed_language": false,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0.38
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "38 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 38,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "moderate",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 55,
            "inputs": {
              "primary_language": "PHP",
              "largest_source_bytes": 46189,
              "source_files_sampled": 582,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "PHP without a type-check config",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_typecheck_config_language",
                    "params": {
                      "language": "PHP"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/582 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 582,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? Carries a deliberately small weight: agent tooling is a real maintenance signal, but its absence must never gate the top of the scale (calibration saturates at raw 91, so 100/100 remains reachable with AI Readiness at zero)."
      }
    ],
    "classification": {
      "top": [
        "library"
      ],
      "labels": [
        "library"
      ],
      "scores": {
        "plugin": 2,
        "library": 6
      },
      "primary": "library",
      "evidence": [
        {
          "tier": "distribution",
          "label": "library",
          "source": "registry:packagist",
          "weight": 6
        },
        {
          "tier": "description",
          "label": "plugin",
          "source": "description:plugin",
          "weight": 2
        }
      ],
      "artifacts": [],
      "confidence": "medium",
      "host_extension": false,
      "runs_as_process": false,
      "consumed_by_code": true
    },
    "metrics_version": "2.5.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-30T10:36:13.132773Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/e/escalated-dev/escalated-laravel.svg",
  "full_name": "escalated-dev/escalated-laravel",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v2.5.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsPackagist.