Raw JSON report machine-readable
{
"data": {
"repo": {
"topics": [
"ai-agents",
"cli",
"code-search",
"developer-tools",
"github",
"golang",
"mcp"
],
"is_fork": false,
"size_kb": 8080,
"has_wiki": true,
"homepage": "https://www.npmjs.com/package/@gkoreli/ghx",
"languages": {
"Go": 1986731,
"Shell": 4575,
"JavaScript": 1460
},
"pushed_at": "2026-07-19T16:16:33Z",
"created_at": "2026-03-08T04:08:37Z",
"owner_type": "User",
"updated_at": "2026-07-19T16:16:37Z",
"description": "Agent-first GitHub code exploration. GraphQL batching, code maps (~92% token reduction), AND search, repo discovery with README previews. Codemode TypeScript sandbox, MCP server. Go.",
"is_archived": false,
"is_disabled": false,
"license_spdx": "MIT",
"default_branch": "mainline",
"license_spdx_raw": "MIT",
"primary_language": "Go",
"significant_languages": [
"Go"
]
},
"owner": {
"blog": "gkoreli.com",
"name": "Goga Koreli",
"type": "User",
"login": "gkoreli",
"company": null,
"location": null,
"followers": 0,
"avatar_url": "https://avatars.githubusercontent.com/u/243085293?v=4",
"created_at": "2025-11-10T08:36:47Z",
"is_verified": null,
"public_repos": 5,
"account_age_days": 259
},
"license": {
"state": "standard",
"spdx_id": "MIT",
"raw_spdx": "MIT",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v2.9.0",
"kind": "minor",
"published_at": "2026-07-08T02:49:04Z"
},
{
"tag": "v2.8.0",
"kind": "minor",
"published_at": "2026-07-07T18:25:34Z"
},
{
"tag": "v2.7.0",
"kind": "minor",
"published_at": "2026-07-07T14:10:39Z"
},
{
"tag": "v2.6.0",
"kind": "minor",
"published_at": "2026-07-07T06:41:57Z"
},
{
"tag": "v2.5.0",
"kind": "minor",
"published_at": "2026-07-07T00:09:18Z"
},
{
"tag": "v2.4.2",
"kind": "patch",
"published_at": "2026-07-06T21:47:37Z"
},
{
"tag": "v2.4.1",
"kind": "patch",
"published_at": "2026-07-06T20:58:28Z"
},
{
"tag": "v2.4.0",
"kind": "minor",
"published_at": "2026-07-06T20:27:01Z"
},
{
"tag": "v2.3.2",
"kind": "patch",
"published_at": "2026-07-06T16:37:37Z"
},
{
"tag": "v2.3.1",
"kind": "patch",
"published_at": "2026-07-06T16:31:37Z"
},
{
"tag": "v2.1.19",
"kind": "patch",
"published_at": "2026-07-02T18:23:33Z"
},
{
"tag": "v2.1.18",
"kind": "patch",
"published_at": "2026-07-02T17:49:23Z"
},
{
"tag": "v2.1.17",
"kind": "patch",
"published_at": "2026-06-09T21:04:34Z"
},
{
"tag": "v2.1.16",
"kind": "patch",
"published_at": "2026-04-15T06:57:19Z"
},
{
"tag": "v2.1.15",
"kind": "patch",
"published_at": "2026-04-15T06:50:57Z"
},
{
"tag": "v2.1.14",
"kind": "patch",
"published_at": "2026-04-15T06:39:11Z"
},
{
"tag": "v2.1.13",
"kind": "patch",
"published_at": "2026-04-01T22:20:15Z"
},
{
"tag": "v2.1.12",
"kind": "patch",
"published_at": "2026-04-01T18:50:18Z"
},
{
"tag": "v2.1.11",
"kind": "patch",
"published_at": "2026-04-01T18:36:09Z"
},
{
"tag": "v2.1.10",
"kind": "patch",
"published_at": "2026-04-01T18:23:42Z"
},
{
"tag": "v2.1.9",
"kind": "patch",
"published_at": "2026-04-01T18:19:27Z"
},
{
"tag": "v2.1.8",
"kind": "patch",
"published_at": "2026-04-01T17:53:42Z"
},
{
"tag": "v2.1.7",
"kind": "patch",
"published_at": "2026-03-30T23:58:07Z"
},
{
"tag": "v2.1.6",
"kind": "patch",
"published_at": "2026-03-29T19:16:21Z"
},
{
"tag": "v2.1.5",
"kind": "patch",
"published_at": "2026-03-29T18:41:54Z"
},
{
"tag": "v2.1.4",
"kind": "patch",
"published_at": "2026-03-21T03:27:17Z"
},
{
"tag": "v2.1.3",
"kind": "patch",
"published_at": "2026-03-21T03:24:47Z"
},
{
"tag": "v2.1.2",
"kind": "patch",
"published_at": "2026-03-21T03:23:27Z"
},
{
"tag": "v2.1.1",
"kind": "patch",
"published_at": "2026-03-21T03:19:00Z"
},
{
"tag": "v2.1.0",
"kind": "minor",
"published_at": "2026-03-21T03:11:36Z"
},
{
"tag": "v2.0.2",
"kind": "patch",
"published_at": "2026-03-21T02:59:30Z"
},
{
"tag": "v2.0.1",
"kind": "patch",
"published_at": "2026-03-21T02:55:07Z"
},
{
"tag": "v0.2.1",
"kind": "patch",
"published_at": "2026-03-20T23:50:16Z"
},
{
"tag": "v0.2.0",
"kind": "minor",
"published_at": "2026-03-08T20:59:43Z"
},
{
"tag": "v0.1.4",
"kind": "patch",
"published_at": "2026-03-08T17:10:19Z"
},
{
"tag": "v0.1.3",
"kind": "patch",
"published_at": "2026-03-08T17:08:23Z"
},
{
"tag": "v0.1.2",
"kind": "patch",
"published_at": "2026-03-08T17:06:37Z"
}
],
"recent_commits": [
{
"oid": "719cb293a61532b9db6771e631ecf16e687f495b",
"body": null,
"is_bot": false,
"headline": "docs: normalize engineering record spacing",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-19T16:16:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bbf57fbc4d33e8363a435f8d91740423e335d721",
"body": null,
"is_bot": false,
"headline": "docs: add ghx engineering record links",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-19T16:16:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "78b97544d859f0fadf59d6cb0a756aa1b2263904",
"body": "Agent-experience hardening from the v2.8.0 dogfood:\n- CLI failure exit codes classified in core (ADR-0034 ph1-2): read 404 0->3,\n read-missing 0->1, explore/read/tree/grep malformed slug ->2, 401/403 name\n the gh auth login fix; substring matcher deleted.\n- Resolved commit SHA surfaced to agents (\n[…]\nghx-sidecar profile (ADR-0032.2): type\n unified, drop fixed, argv-derived path-scope; byte-identical dedup, measured\n 0 host-verdict changes.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore(release): v2.9.0",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-08T02:47:49Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "78b51e7dc87334abdb43ef18e21c4b6aaceb4447",
"body": "…A-0001 cross-family DISCHARGED\n\nShips the product audit's #1-ranked, cheapest, zero-measurement-dependency\nfinding, in the cross-family-cleared SAFE form.\n\nH1 (default adoption surface inverts the north star): .claude-plugin/plugin.json\nshipped only skills/ghx + skills/ghx-mcp (the heavy power-user\n[…]\n, doesn't kill it.\n\nBoth PA threads (0001, 0002) now carry an independent cross-family second opinion;\nthe last owed adjudication debt is paid.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(plugin): ship PA-0001 H1 — recon skill in the default install; P…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-08T02:47:05Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "c59dda14855b039c1f12eaf7e882273544aeebd2",
"body": "Landed as 3a61b63 (worker a3ae99b), verified before merge. Records the\n[]string-only scoping decision, eval-runner (not denyClient) placement, the\ntrace-array-scoped byte-identical proof, and the no-live-smoke caveat.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(adr): ADR-0032.2 implementation record (as-built + honest caveats)",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-08T02:44:35Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "4e41613c276d2e2f8405c6d1a2dbc731e703d933",
"body": "Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(changelog): record ADR-0032.2 sidecar-profile Locations fix",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-08T02:42:09Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "3a61b635cc60ab08c8d46881d3b7fb9b4dc9b188",
"body": "…ecar profile (ADR-0032.2)\n\nImplements ADR-0032.2 (ACCEPTED, full scope). Closes TRUST hole H9: the\nghx-sidecar eval profile silently persisted empty tool-call Locations.\n\nD1 — depend-not-copy. Delete the byte-identical evals copy of\nToolCallTrace/ToolStatusTransition; SAFE now uses the SAF runtime'\n[…]\nuteClassification). Delta\nacross the committed corpus: 1682 execute traces gain path scope, 0 ACP\nlocations overridden, 0 host verdicts change.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(sidecar): unify ToolCallTrace + trustworthy Locations for the sid…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-08T02:41:08Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "62b4d995eb3c5b903de90bcd95e2f13b72cdf15d",
"body": "…elog + friction dispositions\n\nMark ADR-0034 accepted and record what phases 1-2 actually built (core\nFailureClass/ghx.Error/ClassifyUpstream reading structured HTTP/GraphQL\nsignals; CLI class->exit-code mapping with the substring table deleted;\nthe three friction fixes with the byte-identical + no-\n[…]\npendency\nevidence). Add the [Unreleased] Fixed/Changed entries. Update the three\n2026-07-07 exit-code friction dispositions from open to fixed.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(adr): ADR-0034 ACCEPTED + phases 1-2 implementation notes; chang…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-08T02:40:03Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "ae532a6d42bbed81fab70c22734ed73e4dcc931a",
"body": "…rictions (ADR-0034 phase 2)\n\nThe CLI now maps FailureClass -> exit code + affordance by reading the\nghx.Error that core attached at the source (errors.As), instead of\nre-parsing English error strings. Deleted the duplicated upstreamRules /\nupstreamAffordance / upstreamError / ghxCoreError substring\n[…]\ny the two F2 cases (exit 0 -> 3 and 0 -> 1) change. No eval anomaly\ndetector or scorer depends on ghx CLI exit codes. Full suite + -race green.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(cli): source exit-code class from core; fix 3 dogfood exit-code f…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-08T02:37:31Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "64cedae193babc73ce6a6436ff8ec0d61b6007da",
"body": "…(ADR-0034 phase 1)\n\nLift failure-classification into core so every frontend maps one shared\ndomain class to its own idiom instead of re-deriving it from English error\nstrings (ADR-0034 M2; W2's flagged fragility).\n\n- Add FailureClass (ClassNone/ClassNoResults/ClassBadInput/ClassUpstream)\n mirrorin\n[…]\nor. Full suite green; the three friction commands render identically to\npre-change HEAD. Table-driven classifier tests added (failure_test.go).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(ghx): core owns the FailureClass taxonomy + upstream classifier …",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-08T02:36:37Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "b8828ff8c5a3e003562fd263c5418620a5b692b6",
"body": "…conflation, not one number\n\nFollow-up to 9cc1c6f. Goga pointed at skills/ghx/SKILL.md as \"what I meant by\n400\" — which exposed that my previous edit fixed the NUMBER but not the\nartifact/level mapping, and I then briefly over-corrected the other way.\nGround truth, recomputed per file:\n\n- Level 1 (m\n[…]\n (this whole thread took ~4 recompute iterations to land one number —\nexactly why \"recompute the exact quantity, name the artifact\" is a rule).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(skills): fix the persona-tax scope line — \"~400\" is a THREE-way …",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-08T02:31:03Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "9cc1c6fd4c321f2c4acf0a0759debd1a160f7526",
"body": "…-forge\n\nRevisit both skills against the PA-0002 run we just executed (synthesis →\ncross-family OWED → discharged later → corrections folded → governing ADR).\nEarned tightenings, folded into existing sections (no new sections):\n\n- CORRECT a debunked figure the skill still carried: the \"~400-line\n p\n[…]\nready covered), persona-count changes (5-persona scoped run worked),\nremovals for their own sake (density is progressive-disclosure reference).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(skills): fold PA-0002 process lessons into product-audit + skill…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-08T02:23:34Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "b5f5070ade2c16daeaf121503589d92dcd47e632",
"body": "Sibling to the --path grammar-teaching fix; both surfaced dogfooding the\nPA-0002 competitive recon. Code landed in 75579aa.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(changelog): record ghx grep -i + tree --path (v2.8.0 dogfood AX)",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-08T02:12:07Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "75579aac12ec1f6a8c9cc0819e4a78410349ce71",
"body": "…or subtree\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(cli): ghx grep -i (no-op, grep-parity) + ghx tree --path alias f…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-08T02:10:30Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "63e75280337177088085170c709f80dfff48b80a",
"body": "…ases 1-2)\n\nGoga accepted both 2026-07-07:\n- 0032.2 at full scope — Layer A (type unification + drop-fix) AND Layer B\n (D4: argv-derived path-scope), since D2 alone leaves Locations empty at the\n source for the sidecar's execute-driven recon (dogfood FRICTION.md finding 2).\n Still measurement-tou\n[…]\nources class from core, fixes the 3 dogfooded exit-code frictions,\n deletes the substring matcher). Phases 3-4 (MCP, sidecar) sequenced later.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(adr): accept ADR-0032.2 (full: +D4 argv-derive) and ADR-0034 (ph…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-08T02:09:52Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "102f0ccec9116c7b90014bf24935a1ce7c0718e6",
"body": "…off; PA-0002 cross-family DISCHARGED\n\nExecutes the PA-0002 decision (absorb codebase-memory-mcp's ENGINE, gated —\nnot the product; the EVAL precedes the integration) as a governing ADR, and\ndischarges the OWED cross-family adjudication debt.\n\nADR-0024.3 (pre-registered, NOT accepted):\n- local:cbm =\n[…]\ntus.go:41, tool_registry.go:132,\n report.go:45) + tests; effort M, not trivial.\n- vendor headline is 120x fewer tokens (5 queries), not \"99%\".\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(adr): ADR-0024.3 local:cbm tier-2 backend + pre-registered bake-…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-08T02:07:03Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "4a78bcc37a16b0cc88644708d45404744570fc20",
"body": "…ode-mode + --depth exit codes)\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(changelog): record v2.8.0 dogfood AX fixes (Snapshot surfaced, c…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T19:26:40Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "7dd74e0c03396d793632b95d14fb3294bb0a1b71",
"body": "…de fixes (v2.8.0 dogfood)\n\nThree clean agent-experience fixes from the v2.8.0 dogfood run\n(docs/dogfood/FRICTION.md, 2026-07-07 section). None touches the\nmeasurement-bearing sidecar report or internal/sidecar/evals.\n\n1. Surface Snapshot{Repo,SHA} to agents (ADR-0036 B2, agent-facing half).\n read\n[…]\nnal/codemode);\nTestCodeTranspileErrorExitsBadInvocation, TestAskDepthValidationRejectsBogus,\nTestAskDepthValidationAcceptsValid (internal/cli).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(cli): surface Snapshot SHA to agents; code-mode + --depth exit-co…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T19:25:20Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "73fe6130b189d747e02074d1a4132d4018e2328b",
"body": "… ask exits 0 on BLOCKED, etc.)\n\nLive dogfood of v2.8.0 on gjson/p-queue/attrs: depth dial, ADR-0036 B2 Snapshot\nSHA, and the ghx tree panic fix all confirmed working (resolves the prior\nexplore->exit-3 friction). 8 soft frictions, 0 breaking.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(dogfood): v2.8.0 friction log — 8 soft (Snapshot under-surfaced,…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T19:04:48Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "9d66038b39e3a624afdfc6819af79fb32dd43d1f",
"body": "…ST H9\n\nJudge's synthesis of the reusable-core arch-audit (first run of the arch-audit\nskill). Verdict: DO NOTHING structural — the SAF<->SAFE core is a genuine,\ncorrectly-sized shared kernel (telemetry), no framework extraction warranted\n(north-star filter, one product). The one real finding — veri\n[…]\nnd-not-copy + flow Locations), recorded as TRUST H9, NOT fixed as a\ndrive-by. Advances C7 (trust ledger). Everything else watch-list or frozen.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(audit): AA-0002 distillation + ADR-0032.2 pre-registration + TRU…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T18:45:38Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "bd2e63915bde087fcf8253b91b05723c222ad78b",
"body": "… gated\n\nJudge-reconciled verdict on absorbing DeusData/codebase-memory-mcp. Distiller\ncross-validated every load-bearing fact (MIT license; arXiv 83%-vs-92%;\nshell-out seam at tier2/toolrun.go:53 + target src/main.c:9; existing tier-2\nbackends) and discarded the over-reaches as bones.\n\nDECISION: ab\n[…]\nrammar, code-search rate limit, GitHub-only blindness) -> A.\n\nCross-family (Codex) adjudication OWED (capped twice) before any go/no-go or ADR.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "audit(product): PA-0002 synthesis + distillation — absorb cbm ENGINE,…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T18:45:02Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "384742572b571d8547c88644a7a3aa6f53043568",
"body": "Reusable-core extraction (.1), Go architecture & boundaries (.2), domain\nmodeling (.3), YAGNI skeptic (.4, adversary), duplication/coupling metrics\n(.5, opus fallback — GPT usage-capped). Convergent verdict: the SAF<->SAFE\ncore is a GENUINE shared kernel (telemetry), correctly sized — no framework\ne\n[…]\nction warranted (north-star filter). One real bug found: ToolCallTrace\nduplicated + convertSidecarTrace drops Locations (measurement-touching).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(audit): AA-0002 persona artifacts (5) — reusable-core boundary run",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T18:41:36Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "abc56653454ef692e8490c1e67f419ab46af9c4a",
"body": "…p? (5 lenses)\n\nScoped PA-2 audit (focus: should ghx absorb DeusData/codebase-memory-mcp\nentirely). Five read-only persona-agents, each dogfooding ghx to recon the\ntarget, converging from different angles:\n\n- .1 Competitive (generative): ABSORB-PARTS — the engine as a brain-gated\n shell-out tier-2 \n[…]\nO; \"entirely\" rejected; absorb the ENGINE\nnarrowly as a gated tier-2 backend, MEASURED by a ghx bake-off first.\nCross-family adjudication owed.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "audit(product): PA-0002 persona artifacts — absorb codebase-memory-mc…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T18:37:00Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "cf39223adb04b8f0dfcb1d6fe5310159f84c920f",
"body": "… evals<->product shared kernel)\n\nFirst arch-audit run under the new skill. Scope: internal/sidecar (SAF) <->\ninternal/sidecar/evals (SAFE) shared kernel + telemetry substrate. Trigger: the\nframework half of the north star + ADR-0036's runner port. Utility tree:\nreal-shared-kernel-vs-duplication > context-tax reduction > replaceability. Frozen\nmeasurement stack respected; YAGNI adversary mandatory; do-nothing is valid.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(audit): AA-0002 charter — reusable-core boundary (SAF-as-infra &…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T18:27:17Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "0a7ac7f06d88fddf08700dec040bc323c7fa16d1",
"body": "Architecture hardening (ADR-0035 cleanup + ADR-0036 target architecture with the\nconfig-selectable Runner port) + main-agent ergonomics. User-facing: daemon\nconfig tunables, read --line-range alias, --path affordance, Snapshot{Repo,SHA}\nin read/explore, supervisor-hardened daemon, ghx tree malformed\n[…]\nonsolidated turn engine behind the Runner port, typed Depth/Tier/Backend, tool\nregistry) synthesized from the docs/audits/ architecture audits.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore(release): v2.8.0",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T18:24:22Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "606248ab068913b5212dd349c9632288b977ea0b",
"body": "…rrections\n\nInternal evidence agent rendered BuildPersonaSystemPrompt() = 141 lines / 6,858 B\n/ ~1,714 tokens (exact), and caught two uncorrected judge errors. Fixed:\n\n- Judge-step provenance bullet no longer claims \"wc -l=350 contradicts 141\" —\n the persona's 141 was RIGHT; 350 was my non-comparab\n[…]\nructurally blind to\n the native Explore rival's own docs (needed a curl fallback).\n\nCross-family adjudication still owed on the High findings.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "audit(product): PA-0001.8 evidence ledger + decision-grade merge + co…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T18:23:37Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "2ef0b6ac2951f2904e2fb6c109cce1e1dc663455",
"body": "…ews shipped)\n\nSkill-forge loop complete: Round-0 research (5 canons incl. the mandatory Wave-2\nre-pricing) -> Round-1 draft -> Round-2 adversarial review (craft / completeness+fit\n/ meta-redteam) -> Round-3 judge reconciliation (this commit) + provenance shipped.\n\nACCEPTED (verified against the rep\n[…]\nng security/CLI-versioning/supply-chain/observability lenses (R2 — anti-fit or\nalready-owned); FM-4/5 folded into FM-3, not separate additions.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(skill): arch-audit Round-3 reconcile + finalize (research + revi…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T18:22:56Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "9eab3e6f7173e7f85da547aa76539b5b365b1df1",
"body": "Decision-grade external cross-refs for PA-0001: competitors, the native\nalternative, and absorption/OSS-inspiration — all deep hyperlinks verified\n(14 repos, 9 file paths, 3 external URLs resolve).\n\nCorrections fed forward:\n- Claude Code Explore is NO LONGER Haiku-by-default (v2.1.198 inherits main\n\n[…]\ns the one ghx can't reconnoiter.\n\nTop absorption anchors: codebase-memory-mcp knowledge graph, repomix --compress,\naider repomap.py (PageRank).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "audit(product): PA-0001.7 external & OSS-inspiration cross-references",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T18:18:51Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "332d0e3cbd9a528062038ec28efe746a82346c55",
"body": "…avior-identical (ADR-0036 C1)\n\nDefine the harness-neutral Runner port in package sidecar (runner.go: Runner/\nSession/TurnRequest/SteeringSpec/EventSink/Outcome/FailureClass) and make the\nclaude-agent-acp path implement it (acprunner.go): the string-matchers become an\nadapter-internal Outcome mappin\n[…]\nsidecar suite\npasses UNMODIFIED incl. -race (byte-identical proof); the agent that wrote this\ndied pre-commit and Fable salvaged + verified it.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "refactor(sidecar): introduce Runner port; ACP path implements it, beh…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T18:16:27Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "004489e8b138a01e49ed0e342132ee6b7491f3bb",
"body": "The reusable kernel from product-audit's evidence-ledger lesson: sourcing\ndiscipline was strong on the research INPUTS but never reached the OUTPUT, so a\nconclusion could ship as evidence-free prose.\n\n- Guardrail: conclusions aren't decision-ready without consolidated receipts —\n the same sourcing \n[…]\ndence\n ledger.\n\nLeft in product-audit (not copied): the specific evidence classes\n(source/strategy/experiment) and the OSS-absorption framing.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(skill-forge): generalize \"decision-ready = consolidated receipts\"",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T18:16:07Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "412b151197782f950ffbed009022b7f9459868d9",
"body": "…nce ledger\n\nFindings were decision-shaped but not decision-READY — conclusions without the\nreceipts. Fix the workflow so evidence spans every class and is consolidated:\n\n- New synthesis output: \"Evidence & cross-reference ledger (decision-grade)\" —\n per top finding, consolidate SOURCE (file:line +\n[…]\na was inspired or\n absorbed, as a SPECIFIC deep hyperlink (never a bare homepage), verified.\n- Delegation template updated to demand the same.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(product-audit): require a decision-grade evidence & cross-refere…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T18:12:47Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "7dcfc789dc3d94bf4ff6ffe2d9d79dcf189ee189",
"body": "…anon\n\nAuthoring pass (skill-forge Round 1) on the fork's draft, folding in the sourced\nresearch: an ATAM utility-tree front-end to the charter (rank quality attributes\nper scope); complexity x git-churn hotspots + gocognit for the metrics persona\n(not just gocyclo); adversaries run as premortem/Tea\n[…]\nESS FUNCTIONS (committed CI checks)\nso boundaries don't drift back between audits (anti-shelfware). Provenance now\npoints to research/ ledgers.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(skill): arch-audit Round-1 revision — fold in Round-0 research c…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T18:04:06Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "cf1882ed646a19f942262322b429194bf10e1bf6",
"body": "…(4 canons)\n\nskill-forge Round 0 for the arch-audit skill: idiomatic-Go architecture (R1),\nclean-architecture/DDD/reusable-core (R2, Shared-Kernel framing for evals<->product),\ntech-debt detection & metrics (R3, complexity x git-churn hotspots + Go tooling),\narchitecture-audit methodology (R4, ATAM \n[…]\nLM self-preference judge guardrail). 66 deep-URL sources total, degradations\ndisclosed per Source Ledger. Provenance for the SKILL.md revision.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(skill-research): arch-audit Round-0 sourced research provenance …",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T18:01:37Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "3d047dff48418b820b75d907cb7157d7d538eabf",
"body": "…tech-debt audit loop\n\nA repeatable loop for raising ghx's maintainability -> engineering velocity:\npick a scope (whole codebase / module / reusable capability like the Agent\nSidecar Framework or the evals<->ghx shared core / a cross-cutting mindset),\nfan out 4-6 background personas (>=1 adversarial\n[…]\nstack\nrespect, north-star filter / no cathedrals, forward-looking agentic-first lens,\nff-only integration (never --amend on a shared mainline).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(skill): arch-audit — scoped multi-persona architecture/codebase/…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T17:49:23Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "1bcf73bcfb58db5b7b2e43d5ce4a4a8281e44215",
"body": "…-picture rule\n\nPort the reusable parts of the founder's audit-workflow guidance into the meta-\nskill (leaving product-audit-specific bits in product-audit):\n\n- Convergence & distillation is now a first-class step: a loop-table row\n \"Distil (conditional)\" + a dedicated section. When the deliverable\n[…]\nncile: \"no\" outcomes extend to concluding the premise is wrong or that a\n canonical source has gone stale and should be flagged for evolution.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(skill-forge): generalize the convergence/distillation pass + big…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T17:40:37Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "8ae128db9cbb634f697afdb2a949411822129cfe",
"body": "Convergence & distillation pass (Process step 8) mined the intersection and\ncross-validated against the codebase; orchestrator judged it.\n\n- Convergence re-scored by the shared-prior rule: H2's \"two personas agree\" is\n shared-prior (both read corpus-discrimination) — its signal comes from the\n dis\n[…]\n.\n- Bones vetoed: Explore-commoditizes over-reach; SPT \"value-free\" label; SPT\n non-load-bearing; L2 M8. Cross-family adjudication still owed.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "audit(product): PA-0001.9 distillation + judge verdicts; close the loop",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T17:31:30Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "3d31efb8a8e1b1402938e0636d6ee246bd270ab2",
"body": "…(dogfood F3)\n\nDogfood friction F3 (docs/dogfood/FRICTION.md, 2026-07-07) reported a live\n401 on `ghx search` printing the bare \"search failed: HTTP 401: Bad\ncredentials (...)\" with no fix-it affordance. That was a stale-binary\nartifact: the friction binary was v2.6.0 (e8816ec), which predated the A\n[…]\nto 2 and fails the test.\n\nExit codes 0/1/2/3 unchanged. No errors.go change was needed (the 401 rule\nalready exists). Scope: internal/cli only.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(cli): live upstream 401/auth errors name the 'gh auth login' fix …",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T17:29:28Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "0d2d2858513aa30eadab03a5bfc9b1193159c903",
"body": "Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(review): independent review of ADR-0035/0036 refactors",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T17:28:54Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "3ae3c6b9d42fb434499aed7210fae7a2919e08b4",
"body": "Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(arch): runner-adapters integration spec (codex-acp + claude-sdk)",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T17:28:54Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "98492fb7940ab066d6a3bd2cd3b9c95fecbc917c",
"body": "The process retrospective caught the judge (me) comparing prompt.go's 350\nwhole-file lines against the persona's ~141-line RENDERED doctrine — two\nnon-comparable quantities. Re-derived: the recon doctrine is\nBuildPersonaSystemPrompt() (prompt.go:37), ~130-141 lines; the file also holds\nBuildDiscover\n[…]\nd; my dismissal\nwas itself the evidence-drift the new PF1 rule (recompute the exact quantity via\nthe finding's own command) now guards against.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "audit(product): correct PA-0001 L1 — self-caught evidence-drift (PF1)",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T17:27:53Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "a6ca4267f4692bc1ae0e96c51e29073ecbcfa609",
"body": "…eword by specific id, ff-only landings\n\nGoga 2026-07-07 after the amend incident: parallel engineers may be committing\nto mainline in the same tree. Appends are safe; history rewrites are the danger.\nRules: never `git commit --amend` on mainline (it rewrites whatever HEAD points\nat, which may be an\n[…]\n CAS update-ref (never rebase a shared tree holding others'\nuncommitted files); land worker branches by ff-only (retry on race, never\ncorrupt).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(claude): git hygiene on a shared mainline — never blind-amend, r…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T17:27:46Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "a1c3037bef62b67f61757397a66fdb3620e57794",
"body": "…posture, PF1/2/3\n\nFounder guidance + the PA-0001 process retrospective, folded in:\n\n- Process step 8 — Convergence & distillation (final pass): a fresh no-stake\n agent mines the intersection of the fan-out; GENUINE cross-persona convergence\n = high signal, shared-prior convergence discounted; dis\n[…]\ne-drift), order accepted findings by\n leverage not severity alone.\n- skill-forge: convergence/distillation pass noted for multi-agent outputs.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(product-audit): convergence pass, north-star-is-auditable, 2026 …",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T17:27:42Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "ee62a610d950ac1d8554b0ca405b9b2176feff97",
"body": "…e live run)\n\nIndependent review of the audit PROCESS as executed. Caught the orchestrator's\nown judge-step error (compared whole-file 350 lines vs the ~141-line rendered\npersona doctrine — non-comparable) and proposes: PF1 recompute the finding's\nexact quantity via its own command + cite by symbol/\n[…]\nred citability-gated field. Credits what the process did well (genuine\nre-derivation, named shared-prior caution, blocking cross-family state).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(product-audit): PA-0001 process retrospective (meta-review of th…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T17:24:38Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "dec217df201fac52af476689ed8cb63e51dec50f",
"body": "…1.6)\n\nCodex (cross-family) was usage-capped, so per directive 5 a fresh no-stake\nClaude adjudicator re-derived C1-C5 from raw files (partial mitigation;\ncross-family still owed). It confirmed the spine of all three High findings and\nsharpened four, folded into an \"Adjudication outcome\" section:\n\n- \n[…]\nt).\n- M3 severity -> Medium.\n\nStatus: High findings self-verified + same-family-adjudicated; cross-family\ncheck still owed before any go/no-go.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "audit(product): PA-0001 judge step — same-family adjudication (PA-000…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T17:19:03Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "03601262243b2e208e34aff7074a4084bf1acf10",
"body": "…judicator fallback\n\nFounder guidance (2026-07-07): an audit needs a declared focus, not a\nfrom-inception sweep every run — but scoped != narrow-minded.\n\n- New Prime Directive 6: every audit declares a focus/attack surface (a\n milestone/feature/goal/vision/surface); do NOT re-audit the whole produc\n[…]\nmitigation (removes stake/shared-context bias, not same-family bias);\n flag findings checked only same-family. Same note added to skill-forge.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(product-audit): require a scoped focus/attack-surface; Claude ad…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T17:13:46Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "14660c8aa9a20cf7882540ead366971c0028113b",
"body": "Orchestrator synthesis over the 5 persona artifacts. Judge step: Fable\nre-derived every load-bearing fact from raw artifacts (plugin.json,\ncorpus-discrimination table, report.go schemaVersion, handleRecon, prompt.go\nsize — which contradicted a persona's \"141 lines\" claim, rejected); competitor\nrepos\n[…]\nlus M1-M4, L1-L2, a strong \"what is actually fine\" (eval honesty; brain works\nlive, HIC 0), absorption candidates, and adjacent-idea proposals.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "audit(product): PA-0001 synthesis — judge-reconciled ghx product audit",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T16:33:29Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "18f6170f9138f44f45824a1149758af374b0b2ae",
"body": "First real run of the product-audit skill on ghx. Five read-only adversarial\npersona-agents (opus), each a threaded PA-0001.k artifact under docs/product-audit/:\n\n- PA-0001.1 Agent Experience — default install ships the heavy CLI skill,\n inverting \"zero ghx knowledge\"; read-of-missing-repo returns \n[…]\nalready say.\n\nSynthesis (PA-0001) follows after orchestrator judge step: self re-derivation\n(done) + Codex cross-family adjudication (running).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "audit(product): PA-0001 persona artifacts (live product-audit skill run)",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T16:29:54Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "03e24be20e5a2eba0ecaa7ba0c95a48e9a0be903",
"body": "… ADR-threaded\n\nProduct audits now live in docs/product-audit/ (kept separate from the code\naudits in docs/audits/), numbered and threaded like ADRs: a round is PA-000N\nwith per-persona artifacts PA-000N.k-<persona>.md and a PA-000N-<focus>.md\nsynthesis. Establishes the convention the first live run (PA-0001) uses.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(product-audit): output convention — docs/product-audit/ PA-000N,…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T16:16:54Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "e0a37499198097586782c90f33ae20579ba49613",
"body": "Captures Goga's steering (2026-07-07) in the two places asked:\n\nAGENTS.md (Open Source Leverage tenet) — two binding rules:\n- Competitive analysis is generative, not defensive: study of OSS/real-world\n competitors never triggers retreat; it doubles down on our advantages and\n surfaces things to AB\n[…]\nlement, not just threat lists); the delegation template + process now dogfood\nghx for any GitHub/OSS exploration and log friction as a finding.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: competitive analysis is generative; dogfood ghx for exploration",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T16:10:55Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "acd5fb1e7cb27e42e7f892a92e858cfb8da4abf1",
"body": "…ct 07)\n\nRound-4 steals (Picasso, with attribution), the one bounded change the recon\njustified — convert two umbrella scopes into checklists:\n\n- Phase 6 gains axprobe's AX report contract (goal_reached, human-intervention\n count, false_errors, a 5-class friction taxonomy) and its weak-driver metho\n[…]\nmiss trace-mining; Evals\n scope gains deepeval's agentic sub-metrics.\n\nDeclined: a third (DX) consumer axis and ax-audit's web-crawler rubric.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(product-audit): absorb AX-tooling rubrics from OSS recon (artifa…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T16:09:00Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "321e2f9857be3a92b3ad326944ab3632dd96d99f",
"body": "… recon",
"is_bot": false,
"headline": "docs(product-audit): research artifact 07 — OSS PM-agent / AX-tooling…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T16:08:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "230882b70499214602e8ada6eeee7b08cc35d980",
"body": "…ctions\n\nUpdate TRUST.md hole H7 (ceiling effects) with the workstream-C7 corpus-\ndiscrimination finding: the corpus's discrimination power rests on only 2 of\nits 6 tasks (express-router-location, openai-node-streaming); gin/hono/flask\nsit at ceiling and ghx-mapengine is contamination-confounded, wi\n[…]\nDR-0032.1 (S2 fix is on HEAD; the execute-kind nuance remains).\n- F5 (token metric undercounts) = OPEN, folds into ADR-0036 Phase D real-token.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(trust): update H7 from corpus-discrimination; triage dogfood fri…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T16:07:49Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "cdb81ae65da59cae31de4bcf6236dbf2c3335d19",
"body": "…le validators (ADR-0036 B3)\n\nReplace stringly-typed Depth/Tier/Backend usage in the sidecar with value\ntypes (depth.go/tier_value.go/backend.go), each with one canonical parser/valid\nset, consumed by session_options/tier/reportsink/tool_registry and the CLI/MCP\ndepth boundary. Each frontend's curre\n[…]\ntity untouched: the\npersona, backend-ID, and TierUsed goldens pass unmodified. AskRequest keeps\nstring/[]string at the public boundary for now.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "refactor(sidecar): introduce Depth/Tier/Backend value types with sing…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T16:02:52Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "e4d7a1f6d2033a16daab7c9cec14ad42d349fde2",
"body": "…(ADR-0036 B2)\n\nAdd ghx.Snapshot{Repo,SHA} and record the commit oid a core read actually\nresolved (defaultBranchRef.target.oid) as an additive field on read/explore\nresults, so evidence surfaces which commit was read and two reads in one\ninvestigation can be checked against a moving HEAD. Phase 1 is\nobservability-only — additive, behavior-preserving; pinning reads to the SHA is\ndeferred to an ADR-gated Phase 2.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(ghx): capture the resolved commit SHA into read/explore results …",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T16:00:46Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "c0381bdc32bfdbaf7e5cfb41dd515cc357146a57",
"body": "Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(changelog): record daemon supervisor hardening (ADR-0036 A1)",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T15:55:43Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "d2870137cf40f600e2a51f518f6cbf073c53afdd",
"body": "… propagation, graceful drain (ADR-0036 A1)\n\nThree reliability fixes to the resident daemon (resilience audit H2/H3/M1):\nper-request recover() so one turn's panic returns a JSON-RPC error to that\ncaller instead of killing the daemon and all warm sessions; request-scoped\ncontext + connection-closed w\n[…]\norker); signal-aware graceful drain implementing ADR-0030 D6.\nBehavior changes only on failure/shutdown paths; +181 lines of tests; race green.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(sidecar): daemon supervisor hardening — panic isolation, context…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T15:53:10Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "396e7912f08d1aefdd800cdfaa45dc1d89fe8d19",
"body": "…t the edge (ADR-0036 B1)\n\nCore recon ops (Explore/Read/Tree/Repos/Glob/Search) now RECEIVE a typed\nghx.Repo instead of re-parsing an owner/repo string internally; ParseRepo runs\nonce at the CLI (ghx.go) and MCP (serve.go) edges. \"Parse at the boundary,\nflow the type inward.\" Behavior-preserving for\n[…]\nll surfaces the \"invalid repo\" substring so a bad slug maps to exit 2.\nCodemode wrappers keep string parsing (they are the JS string boundary).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "refactor(ghx): thread ghx.Repo across the core boundary; parse once a…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T15:51:37Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "bec5b3af1662221817ccf659843c4636cce971e2",
"body": "…-0 step\n\nEncodes the run's own top lesson: the contrarian \"does this wisdom hold in OUR\ncontext?\" lens must be a standing default, not an angle you hope to notice.\nRound 0 is now two waves — wave 1 maps the canon, wave 2 is a mandatory agent\nthat reads the wave-1 artifacts and audits them (HOLDS/AD\n[…]\n the worked example this pass\n(the agentic-first lens) was the single highest-leverage step and only happened\nbecause it was caught mid-flight.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(skill-forge): make the context re-pricing pass a mandatory Round…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T15:48:14Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "aacb58b40c02a815ae943afac9c08ee92e510920",
"body": "…ewed skill creation\n\nCodifies the loop that produced .claude/skills/product-audit: Round 0 wide\ndelegated research (distinct angles incl. a contrarian/\"does the wisdom hold in\nour context\" lens) -> Round 1 orchestrator authors the draft (authorship not\ndelegated) -> Round 2 adversarial review on di\n[…]\n76) by verifying\nload-bearing claims and cross-family-checking the highest stakes. Owns the loop;\ndefers command mechanics to fable-delegation.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(skill-forge): meta-skill for research-driven, adversarially-revi…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T15:31:59Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "0ac85f2a7fce45c45fc88766177f385c53388532",
"body": "… reviews\n\nCritically reconciled R1-R4 (accepted the verified/high-value subset; declined\ncargo-cult and scope-creep). Changes:\n\n- Judge independence (R4-F1): directive 5 + Process step 5 now require, for\n High/thesis-invalidating findings, self re-derivation + an independent\n cross-family check (\n[…]\nd: reliability-as-its-own-lens (covered by AX/token-econ; SRE-adjacent)\nand full Tier-B->AX-pillar collapse (kept distinct as more actionable).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(product-audit): round-3 revision — incorporate the 4 adversarial…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T15:30:23Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "f17053982ec72fcac82f07af4eac6e4c0c04ea44",
"body": "Four independent critiques of the draft skill, each a ranked, DH5/DH6,\nseverity-tagged review with an honesty guard and specific-URL sourcing:\n\n- R1 skill-craft: run-spine buried past the token-retention line; ship a\n copyable persona-delegation template; cut the anti-pattern self-tax.\n- R2 pm-comp\n[…]\nvals.\n Cap scopes/surfaces, route dispositions to ADRs/workstreams. Net: keep.\n\nRound-3 revision incorporating the accepted subset lands next.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(product-audit): round-2 adversarial review artifacts (4 reviewers)",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T15:28:06Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "a1de230b981a6750ff95c4d7781b31903a448db4",
"body": "…ot, domain flow (synthesis of 5 vision audits)\n\nStrategic architecture ADR (ADR-0035 was tactical). Four decisions: (D1) a\nconsumer-defined Runner port in a leaf internal/sidecar/runner package so the\nagentic runtime is a config-selected adapter — claude-acp / codex-acp /\nclaude-sdk (in-process ant\n[…]\non-rewrite: A foundations, B domain, C runner port (supersedes ADR-0035 item\n5), D the SDK runtime (ADR-gated, changes token source). PROPOSED.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(adr): ADR-0036 target architecture — Runner port, composition ro…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T15:26:34Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "8bdbe482af1dff1d4c921e40fd8dd8bceb3674a1",
"body": "Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(arch): runner port & pluggable runtimes — target design",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T15:23:40Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "479749e684812f91a0ec0d18a7df2aaf07ee1d6d",
"body": "Idiomatic-Go package-architecture audit (Ben Johnson Standard Package\nLayout, Go Proverbs, Kat Zien) building on ADR-0035 and the five\n2026-07-07 audits. Answers Goga's singletons-vs-services question,\nidentifies the missing composition root (H1) and the core->codemode\ndependency-direction edge (H2), and proposes a concrete non-rewrite\ntarget layout + phased sequence toward P3/P4. Read-only; no code changes.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(arch): Go architecture & boundaries — target design",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T15:22:22Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "167d20d6c5ef3b3821e074f5e87ae3381cc3ce73",
"body": "Read-only reliability/runtime audit of ghx under failure. Maps the current\nresilience architecture (ADR-0027 wrap-up/watchdog/stale-session/peer-closed/\nreport-retry, the acp.go marker strings, the ADR-0034 proposed failure-class\nmodel, and the B4 eval-anomaly derivation from persisted error strings\n[…]\n-layer target that preserves the frozen marker contract, and\ngives a phased non-rewrite sequence. No code changed; measurement stack untouched.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(arch): resilience & runtime robustness — target design",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T15:20:45Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "a54fba38a708f841460f9670798e67456a04c46a",
"body": "Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(arch): domain model & ubiquitous language — target design",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T15:18:24Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "778b2aea9d26427daee2a6744bedd5168161daa3",
"body": "Adds .claude/skills/product-audit/SKILL.md — an orchestrator playbook for\nauditing ghx from the product-manager lens: adversarial PM personalities ×\nscopes × surfaces, grounded in the north star, agentic-first (primary consumer\nis an AI agent, so classic PM advice is re-priced HOLDS/ADAPT/INVERTED b\n[…]\nope boundary (defers code/security/eval-mechanics to their homes);\ncargo-cult anti-patterns; report output contract matching docs/audits style.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(product-audit): draft the product-audit skill (round 1)",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T15:15:55Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "8a2a8d462ffeea39e42751d93483a61b148bfca4",
"body": "…tique [AA5]\n\nCounterweight persona (GPT-5.5): argues against over-engineering ghx as a solo\nGo product. Thesis: keep the bug/testability fixes, add only a narrow runner\nseam, reject core/shared/domain layering and framework extraction until a\nsecond runner implementation proves the shape. Grounded in Go Proverbs / Go\nCode Review Comments / Ben Johnson standard package layout.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(arch): adversarial YAGNI skeptic — minimal-path architecture cri…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T15:12:47Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "65e0695b170ca2378b5b0f54ac58cf7b36cbccfd",
"body": "… pivotal]\n\nAudits the classic-PM corpus (01-05) for a product whose primary consumer is\nan AI agent, not a human. Labels each load-bearing framework HOLDS / ADAPT /\nOUTDATED-OR-INVERTED, grounded in 13 agentic-first sources (5 Anthropic\nengineering posts, the MCP spec, OpenAI function-calling, Biil\n[…]\niability)\n- what still HOLDS: outcomes-over-output, JTBD, 7-Powers, red-team stack,\n four-big-risks, PM craft/personas, market/business scopes\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(product-audit): research artifact — the agentic-first lens [6th,…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T15:12:45Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "67ae414131bbe8b45295996c77ff699681299ad2",
"body": "…stry (ADR-0035 T2.4)\n\nDefaultToolRegistry() is now the single source of truth for the sidecar's\ntool set; the persona menu (prompt.go), backend vocabulary/local-backend\nchecks (tier.go, reportsink.go), and CLI backend IDs (cli/tier2.go) all derive\nfrom it instead of scattered hardcoded lists. Perso\n[…]\nPersonaByteStable, golden unchanged); backend\nidentity string pinned additively. P3 tool absorption's identity surface is\nnow one registration.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "refactor(sidecar): centralize the sidecar tool set in a ToolSpec regi…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T15:10:15Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "1bda8848e7e5469c32ac3d413c94fa7c30a2a9f5",
"body": "…ial red-team [5/5]\n\nCompletes the Round-0 research corpus for the product-audit skill.\n\n- 02-pm-personalities.md: 15 audit-persona blocks (worldview / optimizes-for /\n signature questions / blind spots / what-good-looks-like), each grounded in a\n named authority (Perri, Torres, Verna, Chu, Fourni\n[…]\n\nAn agentic-first lens artifact (06) — auditing this classic-PM advice for a\nproduct whose primary consumer is an AI agent — is in flight next.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(product-audit): research artifacts — PM personalities & adversar…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T15:02:09Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "43ea6e9f03c9ef87eca1a094b77c7ddf58bb7048",
"body": "…s, strategic scopes [3/5]\n\nSourced provenance for the forthcoming product-audit skill. Each artifact\ncarries specific deep-URL citations with per-claim rationale; degradations\n(paywalls, 403s, unOCR'd scans) are disclosed in-document, not smoothed over.\n\n- 01-pm-excellence.md: PM competency models,\n[…]\n,\n north-star alignment, gaps, adjacency, monetization, moat); 31 refs.\n\nPersonalities (02) and adversarial red-team (05) artifacts land next.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(product-audit): research artifacts — PM excellence, audit method…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T14:57:29Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "26ae9ef442509838e0ca416a0a7b041e0224cfd7",
"body": "…thTurnRunner (ADR-0035 T1.3)\n\nThe one-shot (acp.go RunTurnWithOptions) and warm (daemon_worker.go\nAgentWorker.RunTurn) paths duplicated the liveness watchdog, the four-way\nprompt select, and NewSession/LoadSession meta re-assertion. Extract one shared\nturn primitive (turn.go: startACPWatchdog/confi\n[…]\ntural refactor — ~244 lines of duplication removed; the full sidecar test\nsuite passes UNMODIFIED, incl. -race (byte-identical behavior proof).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "refactor(sidecar): extract shared ACP turn primitive; decompose askWi…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T14:54:08Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "b972c4b157bcdcc34fcb21add786c6018a0c44a5",
"body": "…e core recon (ADR-0035 T1.2)\n\nCore ops (explore/read/repos/glob/search) newed up api.DefaultGraphQLClient()/\nNewRESTClient() inline, so no test could exercise a network path. Introduce\nminimal graphQLDoer/restGetter interfaces + a package-level githubClients\nprovider (defaults to the real go-gh clients) that tests override. Public\nsignatures and CLI/MCP behavior unchanged; adds an offline fake-client test\ndriving Explore with no network.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "refactor(ghx): inject GitHub client behind a seam for offline-testabl…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T14:49:55Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "fc889fe7cc6eacd6c6abee9e2376a19a9cc90ccf",
"body": "…-0035 T1.1)\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(changelog): record ghx tree/explore/read malformed-slug fix (ADR…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T14:46:37Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "9e4a10e427488d38bd7e3df43eaab15e06497a4c",
"body": "…formed slug (ADR-0035 T1.1)\n\nUnify the three divergent owner/repo validators (explore/read/inspect/glob)\ninto a single ghx.ParseRepo. Fixes a real crash: `ghx tree noslash` panicked\nvia an unchecked slice index (glob.go); it now returns a clean bad-input error\n(exit 2). explore/read/tree route core\n[…]\nrepo maps to exit 2 instead of exit 3 (also fixes dogfood friction F1).\nBehavior-preserving for valid inputs; ParseRepo + no-panic tests added.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "refactor(ghx): introduce Repo value object; fix ghx tree panic on mal…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T14:45:45Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "5e92633d13d77a364900c3fff2660dc3dee2dd63",
"body": "…uence (synthesis of 5 audits)\n\nConsolidates the original architecture audit + 4 new adversarial audits\n(design-patterns, complexity-metrics via GPT-5.5, coupling/testability,\nroadmap red-team) into one ranked, tiered refactor sequence. Ranks by\ncross-auditor convergence x impact x tractability. Eva\n[…]\nots\ndeferred behind a pre-registered eval ADR (frozen-measurement rule);\nframework extraction rejected now per the north-star filter. PROPOSED.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(adr): ADR-0035 architecture hardening — prioritized refactor seq…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T14:38:12Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "b39ffa542a5302617ccade0d4c86c46054bf1bb4",
"body": "Read-only contrarian audit ranking tech debt by velocity-cost against the\nP3/P4 roadmap. Companion to architecture-2026-07-07.md; does not repeat its\nactioned findings (acp.go split; ADR-0034 failure taxonomy).\n\nFindings (ranked by 1-3 month velocity-cost):\n- V1 (High): no sidecar tool registry — P3\n[…]\n won't move; domain models are portable), a recommended sequence,\nand a Method/auditability section. Every file:line verified; no code changed.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(audit): adversarial velocity red-team — roadmap-blocking tech debt",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T14:35:31Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "cf3428c69d5dae7132d73d9330bbc3fbb21f19db",
"body": "Read-only audit through the coupling/cohesion/testability lens. Two High\nfindings: core recon has no GitHub-client injection seam (Explore/Search/\nRepos/Read/Tree untestable without live network), and the ACP turn engine is\nduplicated across acp.go + daemon_worker.go (plus two eval copies). Mediums:\n[…]\nDigest + dropped request context in daemon dispatch. Matches the\narchitecture-2026-07-07 audit format; cross-references rather than repeats it.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(audit): coupling / cohesion / testability audit — ranked refactors",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T14:34:20Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "3b1051861ed9db486658dbd3373e3857ec52c144",
"body": "Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(audit): design-patterns & domain-modeling audit — ranked refactors",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T14:34:20Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "5b731289b1f1879fa046e5f3ebe4561caa676df0",
"body": "…near history)\n\nGoga 2026-07-07: the per-worker `git merge --no-ff` left a merge bubble per\nephemeral branch, making the log noisy. New rule (AGENTS.md \"Integrating\nDelegated Work\" + fable-delegation skill): workers commit-and-stop on their\nbranch; the orchestrator lands each branch by rebasing onto mainline and\nfast-forwarding — no squash (each worker commit preserved), no merge commit.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(agents): land delegated work by rebase+ff, not merge commits (li…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T14:34:20Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "4d521467e486d500b2174aeb99e0a865e81aefda",
"body": "…efactors [AUD2/codex]\n\ngocyclo/wc/fmt.Errorf pass. Top new debt: askWithTurnRunner cyclo 40\n(runtime.go:273); CLI inline RunE god-files; repeated MCP handler plumbing;\nRead control-density; repomap buildEdges. Eval hotspots flagged ADR-gated.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(audit): complexity & maintainability metrics hotspots — ranked r…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T14:32:52Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "a13187f0b15aa85141161ae25255775e188fb6fd",
"body": "…ocations\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(dogfood): friction log 2026-07-07 — depth dial + affordances + L…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T14:32:52Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "ff43a4d6824bc091543da943c5441f0e8bdf4ca1",
"body": "…--path affordances (W1/W2); fix stray XML in failure-class audit\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(changelog): record daemon config tunables + read --line-range / …",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T14:32:52Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "262e7764201ed330bac36f38ddc058495e84d6e1",
"body": "… directly, never a parking sub-agent\n\nIncident 2026-07-07: a Claude sub-agent (isolation: worktree) that launched\ncodex as a background job then parked raced the worktree GC — the harness\nauto-cleaned the \"unchanged\" worktree out from under the running codex, losing\ntwo delegations. Rule: run `codex exec` directly from Fable's own session into\na hand-created (non-harness) git worktree; Fable verifies/commits/merges.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(skill): capture background-codex delegation rule — run the shell…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T14:32:52Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "6d4d9873f83f6c5a6eb865a928066cdd457a01e6",
"body": "… explore/search (A2/A4)\n\nMined from production/eval traces: agents type `ghx read --line-range` (real\n`unknown flag` failure in ~/.ghx/sessions/letta-ai-letta/logs.jsonl) and\n`--path` on explore/search. Add --line-range as a hidden alias of --lines\n(byte-identical output, conflict-checked), and teach the unknown-flag\naffordance to name the correct invocation for --path on explore and search.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(cli): read --line-range alias for --lines; --path affordance for…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T14:32:52Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "c2bf8df98c9f7c858428a6c03f2540cf2cb05cd5",
"body": "…d config (ADR-0030 follow-up)\n\nTwo daemon runtime tunables that were hardcoded (30m warm-worker idle TTL,\ncross-session concurrency 4) become optional ~/.ghx/config.json fields:\ndaemonWorkerIdleTTLMinutes and daemonMaxConcurrent. Nil preserves today's\ndefaults byte-identically; <=0 is rejected with a field-named error; both\nparticipate in ConfigDigest so a running daemon stale-replaces on change (D6).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(sidecar): expose daemon idle-TTL and max-concurrency as validate…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T14:32:52Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "f6134a44aec3318d57f9aeabc8c0ada2910d0def",
"body": "…DR-0034)\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(audit): failure-class inventory across frontends (evidence for A…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T14:32:52Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "b5364fabfffc2750f6aa7f29b64396ee8a95d7ae",
"body": "… (C7)\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(evals): corpus discrimination analysis toward H7 ceiling refresh…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T14:32:52Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "d2cda8a3553dfe379f33dd60c72baf1daa97ca57",
"body": "Main-agent ergonomics + architecture/eval-trust hardening: MCP recon depth\ndial, CLI error affordances, host-task eval corpus (ADR-0032.1 S1-S4),\nToolCallTrace.Locations populated from ACP notifications, acp.go god-file\ndecomposition, ADR-0034 failure-class model (proposed).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore(release): v2.7.0",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T14:09:21Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "4d9a3e1103e5b7414e065893b4e5be4406f653a5",
"body": "…on on release\n\nGoga: maintain a changelog for each version — captured as a standing rule in\nAGENTS.md (Changelog section + Release Flow step 1).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(agents): require a changelog entry per user-facing change; versi…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T14:08:16Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "47e2b7cce522a589c56fd405cd3d41672504841d",
"body": "…affordances, host-task corpus, Locations fix, acp.go/callTool cleanup, ADR-0034)\n\nMakes the 20 commits staged since v2.6.0 reviewable ahead of the next release.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(changelog): document staged Unreleased changes (depth dial, CLI …",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T07:31:14Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "5aec071e22dede01633a4455d090ed1564ec6ecc",
"body": "…ifications (ADR-0032.1 S2)\n\nToolCallTrace.Locations was declared and JSON-tagged but never written, yet\nthe host-task attribution classifier reads it for rule R6 (path-scope of\nread/edit/delete/move/search tools). The R6 detector ran on always-empty data\nand reported false-clean — a visibility/trut\n[…]\n it now lives in denyclient.go after\nthe acp.go decomposition, so the change was re-applied there rather than\nmerged from the stale-base branch.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(sidecar): populate ToolCallTrace.Locations from ACP tool-call not…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T07:15:40Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "de3f7ad117f5ec4f52c8e20b9e63c928f9dd94d7",
"body": "…POSED; audit M2)\n\nLift failure-class from the CLI frontend into core internal/ghx so MCP\n(16 opaque NewToolResultError flattenings) and the sidecar report (83\nad-hoc fmt.Errorf) can map from one taxonomy — makes the A4 recovery\naffordances universal, not CLI-only. Proposed autonomously; cross-frontend\nrefactor awaits Goga acceptance before build (phased migration registered).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(adr): ADR-0034 unified failure-class model across frontends (PRO…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T07:11:21Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "a49ce76fd4cdcc7e77300e93ecca11c1f5471ebb",
"body": "…dit H2; pure relocation, byte-identical)",
"is_bot": false,
"headline": "merge: decompose acp.go god-file into cohesive sibling files (arch au…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T07:03:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1d3294820980f3915cec8fc2ab1bc80bd8e1f9c5",
"body": "…(audit H2)\n\nPure code-organization refactor of the 1012-line internal/sidecar/acp.go\ninto intent-revealing sibling files in the same `sidecar` package. Moves\ndeclarations verbatim — no renames, no signature/logic changes. Verified\nbyte-identical: every meaningful code line in the original appears e\n[…]\nd ShutdownAgent.\n\ngo build ./..., go vet ./internal/sidecar, go test ./internal/sidecar/...,\nand go test -race ./internal/sidecar/... all green.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "refactor(sidecar): decompose acp.go god-file along its concern seams …",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T07:03:00Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "73d092deb9ea1f6421e57971884696a7d0264d87",
"body": "…pability-3]\n\n# Conflicts:\n#\tinternal/sidecar/recontool.go",
"is_bot": false,
"headline": "merge: expose depth dial (cheap|normal|deep) on MCP recon tool [B2/ca…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T07:01:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3765cd44de59cd7a9015e3ab31bc0f1297b193a6",
"body": "…TAR cap 3)\n\nThe CLI has `--depth cheap|normal|deep` but the MCP recon tool hardcoded\ndepth=\"normal\", leaving the main-agent consumer path unable to steer recon\nbudget. Add a `depth` param to ReconMCPTool and forward it through the same\nAskRequest.Depth field the CLI uses (session_options.go depthBu\n[…]\nr.ReconMCPTool())). The eval tests\nassert hash recomputability + shape, not a frozen value, so they stay green\n(TestMockHostTrialArmB verified).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(sidecar): expose recon depth dial on the MCP recon tool (NORTH_S…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T06:59:19Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "45d4ee2c51524aacf1a28a8ebd0a8f06e827e2c9",
"body": "…lices complete; docker grader + ≤5-ep smoke owed on a docker machine\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(adr): ADR-0032.1 S4 implementation note — corpus landed, all 4 s…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T06:56:49Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "66e0e67261b2d985d872ed71b9979cb35c85af00",
"body": "…ement (ADR-0032.1 S4)",
"is_bot": false,
"headline": "merge: host-task eval corpus S4 — 6 verified fixtures + canary enforc…",
"author_name": "Goga Koreli",
"author_login": "gkoreli",
"committed_at": "2026-07-07T06:55:57Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 37,
"commits_last_year": 598,
"latest_release_at": "2026-07-08T02:49:04Z",
"latest_release_tag": "v2.9.0",
"releases_from_tags": false,
"days_since_last_push": 8,
"active_weeks_last_year": 12,
"days_since_latest_release": 20,
"mean_days_between_releases": 0.2
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": false,
"health_percentage": 42,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "github.com/gkoreli/ghx/v2",
"exists": true,
"license": null,
"keywords": [],
"ecosystem": "go",
"matches_repo": true,
"registry_url": "https://pkg.go.dev/github.com/gkoreli/ghx/v2",
"is_deprecated": false,
"latest_version": "v2.9.0",
"repository_url": "https://github.com/gkoreli/ghx",
"versions_count": 34,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": null,
"first_published_at": null,
"latest_published_at": "2026-07-08T02:47:49Z",
"latest_version_yanked": null,
"days_since_latest_publish": 20
},
{
"name": "@gkoreli/ghx",
"exists": true,
"license": "MIT",
"keywords": [
"github",
"cli",
"code-exploration",
"agent",
"graphql",
"code-map"
],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/@gkoreli/ghx",
"is_deprecated": false,
"latest_version": "2.9.0",
"repository_url": "https://github.com/gkoreli/ghx",
"versions_count": 29,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 2137,
"first_published_at": "2026-03-08T16:51:39.704000Z",
"latest_published_at": "2026-07-08T02:50:31.403000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 20
}
]
},
"popularity": {
"forks": 0,
"stars": 0,
"watchers": 0,
"fork_history": {
"days": [],
"complete": true,
"collected": 0,
"total_forks": 0
},
"star_history": {
"days": [],
"complete": true,
"collected": 0,
"total_stars": 0,
"collected_at": null
},
"open_issues_and_prs": 0
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": false,
"bootstrap_files": [
".mise.toml"
],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [],
"toolchain_manifests": [
"go.mod"
],
"largest_source_bytes": 35342,
"source_files_sampled": 245,
"oversized_source_files": 0,
"agent_instruction_files": [
"AGENTS.md",
"CLAUDE.md"
],
"agent_instruction_max_bytes": 19522
},
"dependencies": {
"manifests": [
"go.mod",
"package.json"
],
"advisories": {
"error": null,
"scope": "published_package",
"source": "osv",
"findings": [],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 6,
"malicious_count": 0,
"assessed_package": "npm:@gkoreli/ghx@2.9.0",
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"go",
"npm"
],
"dependencies": [
{
"name": "github.com/bmatcuk/doublestar/v4",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v4.10.0"
},
{
"name": "github.com/cli/go-gh/v2",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v2.13.0"
},
{
"name": "github.com/coder/acp-go-sdk",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.13.5"
},
{
"name": "github.com/dop251/goja",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20260311135729-065cd970411c"
},
{
"name": "github.com/evanw/esbuild",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.27.4"
},
{
"name": "github.com/mark3labs/mcp-go",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.45.0"
},
{
"name": "github.com/odvcencio/gotreesitter",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.13.4"
},
{
"name": "github.com/spf13/cobra",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.10.2"
},
{
"name": "go.opentelemetry.io/otel",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.44.0"
},
{
"name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.44.0"
},
{
"name": "go.opentelemetry.io/otel/sdk",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.44.0"
},
{
"name": "go.opentelemetry.io/otel/trace",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.44.0"
},
{
"name": "go.opentelemetry.io/proto/otlp",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.10.0"
},
{
"name": "google.golang.org/protobuf",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.36.11"
},
{
"name": "gopkg.in/yaml.v3",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v3.0.1"
}
],
"all_dependencies": {
"error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
"source": null,
"packages": [],
"collected": false,
"truncated": false,
"total_count": null,
"direct_count": null,
"indirect_count": null
}
},
"maintainership": {
"issues": {
"open_prs": 0,
"merged_prs": 6,
"open_issues": 0,
"closed_ratio": null,
"closed_issues": 0,
"closed_unmerged_prs": 0
},
"bus_factor": 1,
"bot_contributors": 0,
"top_contributors": [
{
"type": "User",
"login": "gkoreli",
"commits": 598,
"avatar_url": "https://avatars.githubusercontent.com/u/243085293?v=4"
}
],
"contributors_sampled": 1,
"top_contributor_share": 1
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"auto-tag.yml"
],
"has_docs_dir": true,
"linter_configs": [],
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"go.sum",
"pnpm-lock.yaml"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 0,
"reason": "branch protection not enabled on development/release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 0,
"reason": "0 out of 1 merged PRs checked by a CI test -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/29 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 0,
"reason": "project has 0 contributing companies or organizations -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 0,
"reason": "no update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": 10,
"reason": "packaging workflow detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 0,
"reason": "dependency not pinned by hash detected -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 0,
"reason": "SAST tool is not run on all commits -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 0,
"reason": "security policy file not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": 0,
"reason": "Project has not signed or included provenance with any releases.",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 6,
"reason": "4 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "719cb293a61532b9db6771e631ecf16e687f495b",
"ran_at": "2026-07-28T07:43:35Z",
"aggregate_score": 3.5,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": false,
"has_dependabot_config": false
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-19T16:16:35Z",
"oldest_open_prs": [],
"last_merged_pr_at": "2026-07-19T16:16:34Z",
"ci_last_conclusion": null,
"oldest_open_issues": []
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/gkoreli/ghx",
"host": "github.com",
"name": "ghx",
"owner": "gkoreli"
},
"metrics": {
"overall": {
"key": "overall",
"band": "moderate",
"name": "Overall health",
"note": null,
"notes": [],
"value": 55,
"inputs": {
"security": 48,
"vitality": 75,
"community": 32,
"governance": 46,
"engineering": 69
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 75,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "moderate",
"name": "Development activity",
"note": null,
"notes": [],
"value": 65,
"inputs": {
"commits_last_year": 598,
"human_commit_share": 1,
"days_since_last_push": 8,
"active_weeks_last_year": 12
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 8 days ago",
"points": 28.8,
"status": "partial",
"details": [
{
"code": "push_recency",
"params": {
"days": 8
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "12/52 weeks with commits",
"points": 8.3,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 12
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "598 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 598
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"releases_count": 37,
"latest_release_tag": "v2.9.0",
"releases_from_tags": false,
"days_since_latest_release": 20,
"mean_days_between_releases": 0.2
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "37 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 37
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 20 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 20
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~0.2 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 0.2
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "repository_too_young",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "at_risk",
"name": "Community & Adoption",
"value": 32,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "critical",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 1,
"inputs": {
"forks": 0,
"stars": 0,
"watchers": 0,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "0 stars",
"points": 0,
"status": "missed",
"details": [
{
"code": "stars",
"params": {
"count": 0
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "0 forks",
"points": 0,
"status": "missed",
"details": [
{
"code": "forks",
"params": {
"count": 0
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "0 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 0
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "moderate",
"name": "Community health",
"note": null,
"notes": [],
"value": 50,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": false,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (MIT)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "MIT"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
},
{
"key": "ecosystem_adoption",
"band": "moderate",
"name": "Ecosystem adoption (downloads)",
"note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"registry_dependents"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 56,
"inputs": {
"packages": [
"github.com/gkoreli/ghx/v2",
"@gkoreli/ghx"
],
"dependents": null,
"ecosystems": "go, npm",
"total_downloads": null,
"monthly_downloads": 2137
},
"components": [
{
"key": "monthly_downloads",
"name": "Monthly downloads",
"detail": "2,137 downloads/month across go, npm",
"points": 44.4,
"status": "partial",
"details": [
{
"code": "downloads_monthly",
"params": {
"count": 2137,
"ecosystems": "go, npm"
}
}
],
"max_points": 80
},
{
"key": "registry_dependents",
"name": "Registry dependents",
"detail": "not reported by this ecosystem",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_reported_by_this_ecosystem",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "at_risk",
"name": "Sustainability & Governance",
"value": 46,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 10,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 1,
"top_contributor_share": 1
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 100% of commits",
"points": 0,
"status": "missed",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 100
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "1 contributors",
"points": 1.4,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 1
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 0 contributing companies or organizations -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "good",
"name": "Issue & PR responsiveness",
"note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"issue_resolution"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 72,
"inputs": {
"merged_prs": 6,
"open_issues": 0,
"closed_issues": 0,
"issue_closed_ratio": null,
"closed_unmerged_prs": 0
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "no issues or no data",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_issues_or_data",
"params": {}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "6/6 decided PRs merged",
"points": 38.2,
"status": "met",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 6,
"decided": 6
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/29 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "critical",
"name": "Ownership & stewardship",
"note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"verified_domain"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 21,
"inputs": {
"followers": 0,
"owner_type": "User",
"is_verified": null,
"owner_login": "gkoreli",
"public_repos": 5,
"account_age_days": 259
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "personal (user) account",
"points": 10,
"status": "partial",
"details": [
{
"code": "owner_personal",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": "not applicable to user accounts",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_applicable_to_user_accounts",
"params": {}
}
],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "0 followers of gkoreli",
"points": 0,
"status": "missed",
"details": [
{
"code": "owner_followers",
"params": {
"count": 0,
"login": "gkoreli"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "5 public repos, account ~0 yr old",
"points": 7.1,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 5
}
},
{
"code": "account_age_years",
"params": {
"years": 0
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"github.com/gkoreli/ghx/v2",
"@gkoreli/ghx"
],
"ecosystems": "go, npm",
"any_deprecated": false,
"min_days_since_publish": 20
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "2 package(s) on go, npm",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 2,
"ecosystems": "go, npm"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 20 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 20
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "34 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 34
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "moderate",
"name": "Engineering Quality",
"value": 69,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "at_risk",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 48,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "1 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 1
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "0 out of 1 merged PRs checked by a CI test -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "excellent",
"name": "Documentation",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"topics": [
"ai-agents",
"cli",
"code-search",
"developer-tools",
"github",
"golang",
"mcp"
],
"has_wiki": true,
"homepage": "https://www.npmjs.com/package/@gkoreli/ghx",
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": "https://www.npmjs.com/package/@gkoreli/ghx",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": "7 topics",
"points": 10,
"status": "met",
"details": [
{
"code": "topics_count",
"params": {
"count": 7
}
}
],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "at_risk",
"name": "Security",
"value": 48,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "at_risk",
"name": "Security posture",
"note": null,
"notes": [],
"value": 35,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 18,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 0,
"scorecard_aggregate": 3.5
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection not enabled on development/release branches",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "0 out of 1 merged PRs checked by a CI test -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/29 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 0 contributing companies or organizations -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "no update tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is not run on all commits -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file not detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "4 existing vulnerabilities detected",
"points": 4.5,
"status": "partial",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "excellent",
"name": "Dependency advisories",
"note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:@gkoreli/ghx@2.9.0 runtime dependency closure — what installing the published package pulls in — 6 packages. Reachability is not analyzed.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"no_advisories_left_outstanding"
]
}
},
{
"code": "weights_renormalized",
"params": {}
},
{
"code": "advisories_scope_published",
"params": {
"package": "npm:@gkoreli/ghx@2.9.0",
"assessed": 6
}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 100,
"inputs": {
"source": "osv",
"advisories": 0,
"affected_packages": 0,
"assessed_packages": 6,
"unassessed_packages": 0,
"affected_by_severity": "none",
"direct_affected_packages": 0
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "no direct dependency carries a known advisory",
"points": 35,
"status": "met",
"details": [
{
"code": "no_direct_advisories",
"params": {}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "no indirect dependency carries a known advisory",
"points": 25,
"status": "met",
"details": [
{
"code": "no_indirect_advisories",
"params": {}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "no advisory carries a publication date",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_no_publication_date",
"params": {}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "excellent",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 6,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "good",
"name": "AI Readiness",
"value": 81,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "excellent",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 85,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 1,
"agent_instruction_files": [
"AGENTS.md",
"CLAUDE.md"
],
"agent_instruction_max_bytes": 19522
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "AGENTS.md, CLAUDE.md",
"points": 45,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "AGENTS.md, CLAUDE.md"
}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "100 of 100 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 100,
"sampled": 100
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "good",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 71,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"go.sum",
"pnpm-lock.yaml"
],
"has_dockerfile": false,
"typed_language": true,
"bootstrap_files": [
".mise.toml"
],
"has_devcontainer": false,
"has_linter_config": false,
"typecheck_configs": [],
"agent_commit_share": 0.94,
"toolchain_manifests": [
"go.mod"
],
"dependency_bot_commit_share": 0
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": ".mise.toml",
"points": 18,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".mise.toml"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "Go (statically typed)",
"points": 11,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "94 of the last 100 commits agent-authored or agent-credited",
"points": 10,
"status": "met",
"details": [
{
"code": "agent_authored_commits",
"params": {
"count": 94,
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "no automated dependency updates observed",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_dependency_automation",
"params": {}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"primary_language": "Go",
"largest_source_bytes": 35342,
"source_files_sampled": 245,
"oversized_source_files": 0
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Go (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "0/245 source files over 60KB",
"points": 55,
"status": "met",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 245,
"oversized": 0
}
}
],
"max_points": 55
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
],
"report_type": "repository",
"generated_at": "2026-07-28T07:43:44.484985Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/g/gkoreli/ghx.svg",
"full_name": "gkoreli/ghx",
"license_state": "standard",
"license_spdx": "MIT"
}