Public record
Software health reportschema 0.27.0 · metrics 1.13.0 · 2026-07-23 19:16 UTC

godx-jp / godxjp-ui

GoDX Forge unified design system — maintained via submodule from godx-admin. Published to npm as @godxjp/ui.

TypeScript · JavaScriptNo license detected★ 0 stars⑂ 0 forkssince May 2026View on GitHub ↗

godx-jp/godxjp-ui holds a health index of 56 out of 100, placing it in the Moderate band. It scores highest on Vitality (77/100) and lowest on Community & Adoption (26/100). It was last updated 5 days ago. A single contributor accounts for most of its recent work.

56
overall / 100
Moderate

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

56
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

godx.jpOrganization
1 follower10 public repossince Apr 2026

This repository is backed by an organization — shared, accountable stewardship that can outlive any single maintainer.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publishTags
npm@godxjp/ui18.4.08,7341145 days ago
npm@godxjp/ui-mcp18.4.03,829565 days agomcpmodel-context-protocolgodxjpuidesign-systemreactclaudecursor

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

77Good · 22% of overall
How it's scored
36/36Push recency — last push 5 days ago
7.6/36Commit cadence — 11/52 weeks with commits
18/18Commit volume — 804 commits in the last year
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Inputs used
commits_last_year804
human_commit_share0.95
days_since_last_push5
active_weeks_last_year11

Release discipline

100Excellent
How it's scored
27/27Ships releases — 2 releases published
36/36Release recency — latest release 23 days ago
27/27Release cadence — a release every ~0.5 days
0/10OpenSSF Scorecard: Signed-Releases — no data
Inputs used
releases_count2
latest_release_tagv16.7.2
releases_from_tagsno
days_since_latest_release23
mean_days_between_releases0.5
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

26Critical · 18% of overall
How it's scored
0/60Stars — 0 stars
0/25Forks — 0 forks
0/15Watchers — 0 watchers
Inputs used
forks0
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
How it's scored
22.5/22.5README
0/22.5License — no license file detected
0/18CONTRIBUTING guide
0/13.5Code of conduct
0/7.2Issue template
0/6.3PR template
Inputs used
has_readmeyes
has_licenseno
has_contributingno
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno
How it's scored
54.7/80Monthly downloads — 12,563 downloads/month across npm
0/20Registry dependents — not reported by this ecosystem
Inputs used
packages@godxjp/ui, @godxjp/ui-mcp
dependents
ecosystemsnpm
total_downloads
monthly_downloads12,563
Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

56Moderate · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
2/22.5Commit distribution — top contributor authored 91% of commits
2.7/13.5Contributor breadth — 2 contributors
6/10OpenSSF Scorecard: Contributors — project has 2 contributing companies or organizations -- score normalized to 6
Inputs used
bus_factor1
contributors_sampled2
top_contributor_share0.913
How it's scored
44.8/46.8Issue resolution — 96% of issues closed
36.6/38.3PR acceptance — 132/138 decided PRs merged
0/15OpenSSF Scorecard: Code-Review — Found 0/27 approved changesets -- score normalized to 0
Inputs used
merged_prs132
open_issues3
closed_issues68
issue_closed_ratio0.958
closed_unmerged_prs6
How it's scored
30/30Ownership backing — organization-owned
0/20Verified domain
2.2/25Owner reach — 1 followers of godx-jp
8.2/25Track record — 10 public repos, account ~0 yr old
Inputs used
followers1
owner_typeOrganization
is_verified
owner_logingodx-jp
public_repos10
account_age_days107
How it's scored
25/25Published & resolvable — 2 package(s) on npm
35/35Publish recency — latest publish 5 days ago
20/20Version history — 114 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packages@godxjp/ui, @godxjp/ui-mcp
ecosystemsnpm
any_deprecatedno
min_days_since_publish5

Engineering Quality

Are baseline engineering and documentation practices in place?

76Good · 20% of overall
How it's scored
24/24CI workflows — 5 workflow(s)
24/24Tests present
16/16Linter config — eslint.config.js
0/9.6Pre-commit hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 13 out of 13 merged PRs checked by a CI test -- score normalized to 10
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configyes
has_precommit_configno

Documentation

65Moderate
How it's scored
30/30README
25/25Documentation directory
0/15Documentation / homepage site
10/10Repository description
0/10Topics
0/10Wiki
Inputs used
topics
has_wikino
homepage
has_readmeyes
has_docs_diryes
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

38At risk · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
2.5/2.5CI-Tests — 13 out of 13 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/27 approved changesets -- score normalized to 0
1.5/2.5Contributors — project has 2 contributing companies or organizations -- score normalized to 6
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
0/2.5License — license file not detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
0/5Packaging — no data
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — no data
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 14 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate2.3
Excluded from scoring (no data or not applicable): packaging, signed_releases. Remaining weights renormalized.
How it's scored
35/35Direct dependencies free of known advisories — no direct dependency carries a known advisory
25/25Indirect dependencies free of known advisories — no indirect dependency carries a known advisory
0/40No advisories left outstanding — no advisory carries a publication date
Inputs used
sourceosv
advisories0
affected_packages0
assessed_packages86
unassessed_packages0
affected_by_severitynone
direct_affected_packages0
Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:@godxjp/ui@18.4.0 runtime dependency closure — what installing the published package pulls in — 86 packages. Reachability is not analyzed.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

75Good · 0% of overall
How it's scored
45/45Agent instructions — CLAUDE.md
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 94 of 95 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share0.989
agent_instruction_filesCLAUDE.md
agent_instruction_max_bytes6,321
How it's scored
0/18One-command bootstrap
22/22Automated tests
11/11Lint / format config — eslint.config.js
11/11Static type checking — mcp/tsconfig.json, tsconfig.json
10/10Reproducible environment — lockfile
10/10Demonstrated agent practice — 28 of the last 100 commits agent-authored or agent-credited
0/8Automated maintenance — no automated dependency updates observed
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Inputs used
has_nixno
has_testsyes
lockfilespnpm-lock.yaml
has_dockerfileno
typed_languageyes
bootstrap_files
has_devcontainerno
has_linter_configyes
typecheck_configsmcp/tsconfig.json, tsconfig.json
agent_commit_share0.28
toolchain_manifests
dependency_bot_commit_share0
How it's scored
45/45Type-checkable code — TypeScript (statically typed)
54.8/55Manageable file sizes — 3/860 source files over 60KB
Inputs used
primary_languageTypeScript
largest_source_bytes507,078
source_files_sampled860
oversized_source_files3
How it's scored
0/40API schema (OpenAPI/GraphQL/proto)
20/20MCP server
40/40Runnable examples — examples
Inputs used
example_dirsexamples
has_mcp_signalyes
api_schema_files

Key facts

0GitHub stars
2contributors
804commits, last 12 months
5days since last push
2releases
1bus factor
3open issues
npmpackage ecosystems

Data collection warnings

  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

More detail

OpenSSF Scorecard 2.3 / 10
2.3aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-23 19:16 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
10CI-Tests13 out of 13 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/27 approved changesets -- score normalized to 0
6Contributorsproject has 2 contributing companies or organizations -- score normalized to 6
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
0Licenselicense file not detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
n/aPackagingpackaging workflow not detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
n/aSigned-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities14 existing vulnerabilities detected
Direct dependencies 46
RegistryPackageVersion constraintManifest
npm@modelcontextprotocol/sdk^1.29.0mcp/package.json
npmzod^4.4.3mcp/package.json
npm@date-fns/tz^1.5.0package.json
npm@fontsource/m-plus-2^5.2.9package.json
npm@fontsource/noto-sans-jp^5.2.9package.json
npm@radix-ui/react-accordion^1.2.16package.json
npm@radix-ui/react-alert-dialog^1.1.19package.json
npm@radix-ui/react-aspect-ratio^1.1.11package.json
npm@radix-ui/react-avatar^1.2.2package.json
npm@radix-ui/react-checkbox^1.3.7package.json
npm@radix-ui/react-collapsible^1.1.16package.json
npm@radix-ui/react-context^1.2.0package.json
npm@radix-ui/react-context-menu^2.3.3package.json
npm@radix-ui/react-dialog^1.1.19package.json
npm@radix-ui/react-dropdown-menu^2.1.20package.json
npm@radix-ui/react-hover-card^1.1.19package.json
npm@radix-ui/react-label^2.1.11package.json
npm@radix-ui/react-menubar^1.1.20package.json
npm@radix-ui/react-navigation-menu^1.2.18package.json
npm@radix-ui/react-popover^1.1.19package.json
npm@radix-ui/react-radio-group^1.4.3package.json
npm@radix-ui/react-scroll-area^1.2.14package.json
npm@radix-ui/react-select^2.3.3package.json
npm@radix-ui/react-separator^1.1.11package.json
npm@radix-ui/react-slider^1.4.3package.json
npm@radix-ui/react-slot^1.3.0package.json
npm@radix-ui/react-switch^1.3.3package.json
npm@radix-ui/react-tabs^1.1.17package.json
npm@radix-ui/react-toggle^1.1.14package.json
npm@radix-ui/react-toggle-group^1.1.15package.json
npm@radix-ui/react-tooltip^1.2.12package.json
npm@tanstack/react-table^8.21.3package.json
npmclass-variance-authority^0.7.1package.json
npmclsx^2.1.1package.json
npmcmdk^1.1.1package.json
npmdate-fns^4.1.0package.json
npmembla-carousel-react^8.6.0package.json
npminput-otp^1.4.2package.json
npmlucide-react^1.25.0package.json
npmqrcode.react4.2.0package.json
npmreact-day-picker^10.0.1package.json
npmreact-resizable-panels^4.12.2package.json
npmsonner^2.0.7package.json
npmtailwind-merge^3.5.0package.json
npmtailwindcss-animate^1.0.7package.json
npmvaul^1.1.2package.json
All dependencies not collected

The resolved dependency set could not be collected for this report: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Dependency advisories 0

Installing npm:@godxjp/ui@18.4.0 pulls in 86 packages, direct and transitive: 0 carry known advisories, of which 0 are direct dependencies.

No known advisories affect the assessed dependencies.

An advisory means the version recorded in the dependency graph falls inside an advisory’s affected range. Reachability is not analysed, and the graph includes development and test pins — a finding may concern tooling rather than shipped software.

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 18770,
      "has_wiki": false,
      "homepage": null,
      "languages": {
        "CSS": 224427,
        "HTML": 4848,
        "JavaScript": 342141,
        "TypeScript": 2704017
      },
      "pushed_at": "2026-07-18T11:48:46Z",
      "created_at": "2026-05-11T01:40:01Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-18T11:48:49Z",
      "description": "GoDX Forge unified design system — maintained via submodule from godx-admin. Published to npm as @godxjp/ui.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": null,
      "default_branch": "main",
      "license_spdx_raw": null,
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript",
        "JavaScript"
      ]
    },
    "owner": {
      "blog": null,
      "name": "godx.jp",
      "type": "Organization",
      "login": "godx-jp",
      "company": null,
      "location": null,
      "followers": 1,
      "avatar_url": "https://avatars.githubusercontent.com/u/274176004?v=4",
      "created_at": "2026-04-07T04:40:06Z",
      "is_verified": null,
      "public_repos": 10,
      "account_age_days": 107
    },
    "license": {
      "state": "absent",
      "spdx_id": null,
      "raw_spdx": null,
      "file_present": false,
      "scorecard_found": false,
      "profile_has_license": false
    },
    "activity": {
      "releases": [
        {
          "tag": "v16.7.2",
          "kind": "patch",
          "published_at": "2026-06-30T04:58:17Z"
        },
        {
          "tag": "v16.7.0",
          "kind": "minor",
          "published_at": "2026-06-29T16:24:16Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "929463cc04b7afc323dba2eeb706f0299e59e494",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): @godxjp/ui@18.4.0 · @godxjp/ui-mcp@18.4.0",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-18T11:48:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5bd81609d9806b22eeb9ab6a02670adba21957e8",
          "body": "Restore DXS design-system fidelity",
          "is_bot": false,
          "headline": "Merge pull request #209 from godx-jp/fix/design-system-fidelity",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-18T11:30:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1b0784ab017959ce24ffd064e8d06eb4b840ee16",
          "body": null,
          "is_bot": false,
          "headline": "fix: restore DXS design-system fidelity (#208)",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-18T11:29:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f004638f2afac6aa85a8dd8a8f497bf386aae9bf",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): @godxjp/ui@18.3.0 · @godxjp/ui-mcp@18.3.0",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-18T09:38:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8499147cb3be69e5c4f71ba56361caa23046d33f",
          "body": "…ntrast\n\nfix(feedback): preserve contrast on toned dialog headers",
          "is_bot": false,
          "headline": "Merge pull request #207 from godx-jp/codex/fix-overlay-description-co…",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-18T09:14:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "920fa166c740a59977631fd5ca9c6648f92a839a",
          "body": null,
          "is_bot": false,
          "headline": "fix(feedback): preserve contrast on toned dialog headers",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-18T09:13:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9cdacf2acd704470d619d0b813daedd3dabb4b5d",
          "body": "feat(data-display): add secure QR code primitive",
          "is_bot": false,
          "headline": "Merge pull request #206 from godx-jp/codex/qr-code-primitive",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-18T09:01:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f47a4314da583d55c4d30fa1407430a3d05e4f50",
          "body": null,
          "is_bot": false,
          "headline": "feat(data-display): add secure QR code primitive",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-18T09:01:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "18638f29920ab985fcd03f7ce3c44912e29ac5ec",
          "body": "Manual publish (CI-bypass per request): batch #193-197 + #189/#190 + #199/#200\nnow shipped. Minor bump (new CredentialReveal component). verify:release passed\nlocally (build/typecheck/lint/guards/contrast/visual-audit/full suite/frame-axe).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): @godxjp/ui@18.2.0 · @godxjp/ui-mcp@18.2.0",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-18T01:51:58Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "07cb35d95d86178a1ca0ea6d8bb12ca8fe8c263b",
          "body": "…eProp broke typecheck:docs, blocked #193-197 publish) (#203)\n\nCo-authored-by: Pham Thai Duong <ecsol@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(showcase): org-switcher Badge tone attention→warning (invalid Ton…",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-18T01:26:21Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "c3d4f13b81c411a0b2cc6d4c9b7178882b399329",
          "body": "…202)\n\n* feat(feedback): DangerConfirm recipe — typed challenge + step-up on AlertDialog (#193)\n\nExtend the existing AlertDialog destructive-confirm preset instead of adding a\nduplicate DangerConfirm component (it already owns type-to-confirm + destructive\ntone + pending). Adds:\n\n- `challenge` — sem\n[…]\n: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Pham Thai Duong <ecsol@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat+fix: batch #193-197 (DXS component requests) — Gate-0 triaged (#…",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-18T01:12:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c71586faab437a7c3fb3aac6620db2c16eac5dac",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): @godxjp/ui@18.1.1 · @godxjp/ui-mcp@18.1.1",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-18T00:51:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8b767a685f981f27f360decd6dd6ec1ce257aeb8",
          "body": "…ery surface (#199) (#201)\n\nDark default destructive sat at 4.54:1 (on the AA floor) and hover/active drifted\nLIGHTER (52→58→64% L) cutting contrast against the light label; downstream axe\nmeasured 4.12:1. Root causes:\n- Hover/active used an ALPHA fill (--destructive/0.9) that composites with the\n  \n[…]\nutton +\n  AlertDialog in DARK theme (the gap that let this slip).\n\nCo-authored-by: Pham Thai Duong <ecsol@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(a11y): destructive Button clears WCAG AA contrast with margin, ev…",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-18T00:36:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8ebe3173301dca280b41cb0731f3b603d484c0eb",
          "body": null,
          "is_bot": false,
          "headline": "chore: refresh component API manifest",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-18T00:34:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ed29ef7f6c578c5057650ed07ee9de8dea182e94",
          "body": null,
          "is_bot": false,
          "headline": "fix: separate desktop sidebar and mobile drawer controls",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-18T00:24:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0c66e737e75dddc45cc6985a216d655a926cf25a",
          "body": "…ln (dependabot) (#198)\n\n- Bump all within-major minor/patch: Radix UI (1.2.x→latest), react/react-dom 19.2.7,\n  vitest 4.1.10, vite 8.1.5, lucide-react 1.25, @hookform/resolvers 5.4, recharts 3.9,\n  react-router-dom 7.18, typescript-eslint 8.64, @tanstack/react-query 5.101, etc.\n- Fix dependabot GH\n[…]\nuse-client · rtl · full suite 338 files / 1796 tests — all green.\n\nCo-authored-by: Pham Thai Duong <ecsol@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(deps): refresh safe (non-major) deps to latest + fix esbuild vu…",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-17T13:57:10Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "14581110df2817b567f7eff8dd9560c09d975888",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): @godxjp/ui@18.1.0 · @godxjp/ui-mcp@18.1.0",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-17T09:45:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a3063b5299829b7e0bd834bf41415bdbf22e2365",
          "body": "…binding (#190) (#192)\n\nFormRoot/FormFieldControl are no longer hard-coupled to react-hook-form.\nFormRoot accepts EITHER form (RHF+Zod client path, unchanged) OR adapter — a\nsmall FormStateAdapter (getValue/setValue/getError/isSubmitting/onBlur?/getValues?)\n— so a server-driven form library plugs in\n[…]\nrtia unit tests (incl. 0 axe), docs Inertia login page, CHANGELOG\n\nCo-authored-by: Pham Thai Duong <ecsol@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(form): framework-agnostic FormStateAdapter + @godxjp/ui/inertia …",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-17T09:15:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "162fc6e0f17b9b53e90727da1eb926dd229a0f25",
          "body": "… page shell (#189) (#191)\n\n* feat(layout): CenteredShell — authenticated no-sidebar centred-column page shell (#189)\n\nThird layout shell filling the gap between AppShell (requires a sidebar; its\npadded topbar chrome is a grid area beside the rail) and AuthShell (the\nunauthenticated root — a narrow \n[…]\n: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Pham Thai Duong <ecsol@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(layout): CenteredShell — authenticated no-sidebar centred-column…",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-17T09:14:24Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "67a5a3f5aab79a00e8f5a2253d360673a8684da5",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): @godxjp/ui@18.0.3 · @godxjp/ui-mcp@18.0.3",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-15T15:55:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4dba526d5de78ec4d7c29cca98fafc3c00b0f25f",
          "body": "… bundle 1.8MB→696K (#188)\n\nMCP-only optimization (4 phases):\n- Phase 1: response gọn — get_component có verbose param (token compact mặc định), trim descriptions\n- Phase 2: search intent-based — tokenize+score theo name/tagline/useCases/usage/related\n- Phase 3: perf — tsup minify + no sourcemap, bu\n[…]\n frame (interaction-semantics RTL-Tabs-focus + geometry) flaky/pre-existing từ #186, render src/ — không thể do thay đổi mcp-only.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "perf(mcp): tối ưu @godxjp/ui-mcp — response gọn, search intent-based,…",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-15T15:24:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "12a282dd0833e048511deaa2b4e85a0ececd1383",
          "body": "* ci: move remaining actions to Node 24 runtimes\n\n* ci: move pnpm setup to Node 24 runtime\n\n---------\n\nCo-authored-by: Pham Thai Duong <ecsol@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Move remaining GitHub Actions off Node 20 (#187)",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-15T15:10:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5e79767941fff3836b51b9c8783a0d2db7e1aedc",
          "body": "* feat(a11y): enforce real screen reader evidence matrix\n\n* audit(ui): derive component prop coverage from TypeScript contracts\n\n* test(data-entry): record exact public prop evidence\n\n---------\n\nCo-authored-by: Pham Thai Duong <ecsol@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Make component and screen-reader coverage fail closed (#186)",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-15T14:22:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9fc9969ab2c5f6cb046949ddc33e3f480be019dd",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): @godxjp/ui@18.0.2 · @godxjp/ui-mcp@18.0.2",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-15T10:31:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ba4def9816edf98741782342b917330c43f7f207",
          "body": "* fix(button): normalize icon-xs glyph sizing\n\n* fix(data-table): keep page-size footer labels intact\n\n* fix(button): enforce coarse icon-xs target\n\n* test(data-table): gate pagination footer geometry\n\n* docs(issue-184): add pagination visual evidence\n\n---------\n\nCo-authored-by: Pham Thai Duong <ecsol@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Fix icon-xs sizing and DataTable pagination wrapping (#185)",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-15T10:07:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ff481a0edac8a6b544cf0c0f358aea603ebda6fd",
          "body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01QAd3g7dPPnwTBG5YF3Eah5",
          "is_bot": false,
          "headline": "chore(ci): mark setup-runner-deps.sh executable",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-13T13:26:54Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b019bf5f67f97f6aa448a0b0d80302dfb3c80dcb",
          "body": "Ghi lại toàn bộ migration Frame CI sang self-hosted runner AlmaLinux 10:\n5 khác biệt so với ubuntu-latest (public-repo runner-group gate, no\n--with-deps trên RHEL, pnpm dest isolation, PREVIEW_BASE/PORT port\nisolation chung host, font Noto CJK/RTL cho geometry baseline).\n\n- .github/SELF-HOSTED-RUNNE\n[…]\np-runner-deps.sh — cài font + verify Chromium, idempotent.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01QAd3g7dPPnwTBG5YF3Eah5",
          "is_bot": false,
          "headline": "docs(ci): self-hosted runner setup + font deps script (famgia-linux)",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-13T10:48:18Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "75b3185c017888b5adc4b04709231119ea62ce2d",
          "body": "…-linux\n\nCI giờ chạy bắt buộc trên self-hosted famgia-linux (AlmaLinux 10). navigation-pagination\nrender rộng hơn ~1px ở 768 so với ubuntu-latest (khác font hinting/subpixel dù cùng Noto\nSans CJK) → overflow baseline. Đã cài Noto CJK+Arabic+Hebrew trên runner (fix RTL tabs);\nframe còn lại là chênh f\n[…]\nn runner, chỉ\nthêm 768 vào 1 frame, mọi frame khác y hệt).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01QAd3g7dPPnwTBG5YF3Eah5",
          "is_bot": false,
          "headline": "ci(frame): baseline geometry navigation-pagination@768 cho env famgia…",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-13T10:29:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "82ad191e7c39edce764c0a5c658c63c1fc19995d",
          "body": "…chung host\n\nGeometry sweep fail trên self-hosted: 892 infra errors ERR_CONNECTION_REFUSED. Gốc\n(frame-harness.mjs:74): ensurePreviewServer thấy server 'reachable' ở 6008 thì TÁI\nDÙNG server của job khác (axe/coverage cùng port 6008); job đó xong gọi cleanup() giết\nserver → geometry mất server giữa \n[…]\ntrix cấp 6011/6021/6031 + concurrency cho frame-contracts.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01QAd3g7dPPnwTBG5YF3Eah5",
          "is_bot": false,
          "headline": "ci(frame): port preview riêng mỗi job — hết va chạm trên self-hosted …",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-13T09:38:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "97333dc27fa0c5329574713721675c451c3e3dac",
          "body": "…sted\n\n3 runner famgia-linux chung HOME=/home/satoshi; pnpm/action-setup dest mặc định\n~/setup-pnpm CỐ ĐỊNH → nhiều job frame concurrent cùng ghi/đọc 1 package.json →\nENOENT race (static-contracts fail). Đặt dest=${{ runner.temp }}/setup-pnpm (unique\nmỗi job) → cách ly hoàn toàn.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01QAd3g7dPPnwTBG5YF3Eah5",
          "is_bot": false,
          "headline": "ci(frame): dest riêng cho pnpm/action-setup — chống race trên self-ho…",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-13T09:11:17Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a37c779ced5fd4c718000aea99d9864b05c5556c",
          "body": "Empty commit để phát lại frame-contracts + frame-a11y dưới runner-group policy mới\n(public repo được dùng self-hosted famgia-linux; fork-PR approval=all_external).",
          "is_bot": false,
          "headline": "ci: re-trigger frame CI trên self-hosted (allows_public đã bật)",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-13T09:06:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f5a01749798e90052ade5efc6ae9098a434a464a",
          "body": "…eps)\n\nfamgia-linux-01 là runner bắt buộc (AlmaLinux 10). --with-deps dùng apt → fail trên\nRHEL; đã verify Chromium launch headless OK với system libs sẵn có (libnss3/atk/gbm/\nasound đủ) nên chỉ cần `playwright install chromium`. Browser cache ~/.cache/\nms-playwright persist giữa job trên runner non-ephemeral → nhanh dần.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01QAd3g7dPPnwTBG5YF3Eah5",
          "is_bot": false,
          "headline": "ci(frame): self-hosted famgia-linux + playwright install (bỏ --with-d…",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-13T08:48:31Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "e266cc845b4feb20163bc636fffc5d164487cae4",
          "body": "…n job\n\nRunner famgia-linux-01/-r3/-r4 online + idle + label [self-hosted,Linux,X64] khớp\n+ group Default visibility=all (godxjp-ui được phép), NHƯNG 6 job queued >3 phút, 0\njob dispatch. Vấn đề phía runner agent (không SSH được để chẩn). Revert giữ CI xanh;\nbật lại = đổi 1 dòng runs-on khi runner xác nhận nhận job cho repo này.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01QAd3g7dPPnwTBG5YF3Eah5",
          "is_bot": false,
          "headline": "ci(frame): tạm revert về ubuntu-latest — self-hosted famgia không nhậ…",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-13T08:44:12Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "bac3334b002b0c7f3f6070a6dd77af9e673a312d",
          "body": "…test\n\nRunner GitHub-hosted tốn phí + chậm; org đã có 3 runner self-hosted Linux online\n(famgia-linux-01/-r3/-r4, label [self-hosted,Linux,X64] — kintai-web CI đã dùng).\nChuyển 2 workflow browser-heavy (frame-contracts + frame-a11y) sang đó → nhanh + free.\nplaywright install --with-deps chromium giữ nguyên (cần runner cho phép apt/sudo).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01QAd3g7dPPnwTBG5YF3Eah5",
          "is_bot": false,
          "headline": "ci(frame): chạy trên self-hosted Linux runner (famgia) thay ubuntu-la…",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-13T08:37:56Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3876c3ffb551cbc5a1d9409987eedee1f658ad18",
          "body": "Frame contracts shard layout-touch-rtl fail DETERMINISTIC (không phải flaky):\nrun-final-touch-rtl.mjs locate region '指標カード' nhưng demo carousel đầu tiên\naria-label='月次 KPI カルーセル' → locator không khớp → isDisabled auto-wait 30s\nTimeoutError. Sửa region name khớp demo + thêm waitFrame(page) sau mọi go\n[…]\n\n(giảm timeout trên runner chậm). Verify shard local XANH.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01QAd3g7dPPnwTBG5YF3Eah5",
          "is_bot": false,
          "headline": "fix(ci): layout-touch-rtl shard — region name stale + chờ frame mount",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-13T08:35:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b6a0ed3a8ebe8f9780a9f9f81c1a06a58cad2cc9",
          "body": "…ge gaps\n\nSau merge v17 epic, 4 gate đỏ — vá gốc rễ (verify:release + frame-geometry XANH):\n\n- search-select: nút renderLoadMore nằm trong cmdk root → Enter bị cmdk nuốt (chọn\n  option active) → slot load-more KHÔNG dùng được bằng bàn phím (a11y bug thật).\n  Fix: stopPropagation keydown ở footer → E\n[…]\nne export phải render trong doc) + tài liệu hoá tính năng.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01QAd3g7dPPnwTBG5YF3Eah5",
          "is_bot": false,
          "headline": "fix(select,card,empty-state,tooltip): reconcile dev-merge test/covera…",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-13T08:13:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0032c206dc3055d9c77ae83bb51c4f08f91abe08",
          "body": "…me scripts\n\n4 script rendered-runtime của v17 có `catch {}` rỗng (poll server / action\nfallback cố ý nuốt lỗi) → eslint no-empty fail verify:static (lint). Thêm comment\ngiải thích trong mỗi block (no-empty bỏ qua block có comment).",
          "is_bot": false,
          "headline": "fix(scripts): comment cho empty catch (no-empty lint) trong v17 runti…",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-13T07:18:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "67926e387ede5381599066a822d050bd35c93265",
          "body": "…unique)\n\nrendered-runtime (layout-touch-rtl) axe fail: 2 SplitPane trong 'container stress'\ndemo dùng chung asideLabel='補助パネル' → 2 landmark <aside> trùng tên. Đổi thành\n'補助パネル(狭い埋め込み)' / '(広い埋め込み)' theo context narrow/wide.",
          "is_bot": false,
          "headline": "fix(docs/split-pane): distinct asideLabel cho 2 embed demo (landmark-…",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-13T07:11:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "416bc9f422c0a3133cf2a34d7ca3e2ec6a0fdc0f",
          "body": "6 geometry + 4 axe regression do frame mới của v17 không đạt gate. Sửa THẬT\n(không giấu baseline):\n- input-otp: bỏ autoFocus (input focused tràn 6px past frame ở 320-390).\n- card-index: rút gọn ghost label + extra để CardBar fit 320 (hết focusable off-frame).\n- select-async, button-index: CardTitle \n[…]\nlandmark-unique).\nBaseline CO LẠI (shrink-only): geometry 17→12 frame, axe xoá 7 rule stale đã fixed.\nChỉ docs/** + baseline, không đụng src. Verify: frame-geometry ✓ · frame-axe ✓ · typecheck:docs ✓.",
          "is_bot": false,
          "headline": "fix(frames): geometry clip + axe a11y regressions from v17 merge",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-13T06:59:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7ef1895a7a8cbadf0bfdab491085a8029762eaa0",
          "body": "…erge)\n\nMerge dev (v17) lộ 2 lỗi: (1) docs/data-entry/select-async-contracts dùng API\nkhông tồn tại (retryLabel/loadMoreLabel/searchValue/onSearchValueChange +\nfilterOption đảo params) → sửa khớp API shipped (search/onSearchChange,\nfilterOption(option,query)). (2) EmptyState catalog trùng prop titleAs (merge\ngiữ cả 2 bản) → xoá bản cũ. Còn geometry+axe của frame v17 xử lý ở commit sau.",
          "is_bot": false,
          "headline": "fix(merge): select-async doc API + EmptyState catalog dup (post-dev-m…",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-13T05:35:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "661a6506d9857d7543dda4ffa4b5d27ea35b94d1",
          "body": null,
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'origin/dev'",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-13T05:15:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3f4860bfe8c3ab6bf7abc22760d4fa1f43e99332",
          "body": "…lds & tests\n\n#181 tách verify:release → verify:static; guardrail test assert literal 'build'/'test'\ntrong verify:release nên fail (build/test giờ ở verify:static). Fix: assert chuỗi hiệu\ndụng (verify:release + verify:static). Bug lọt vì auto-merge #181 nhả trước khi job\nVerify chạy xong (Verify chưa phải required check).",
          "is_bot": false,
          "headline": "test(guardrails): assert effective release chain (release+static) bui…",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-13T05:02:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9a3da474a4b5b10b1209f3a321e73878e0d31d7e",
          "body": "…label' + ariaLabel prop\n\nMerge v17↔main tạo destructure trùng identifier. Giữ cả 2 public prop (không phá API bên nào):\n'aria-label' ưu tiên → fallback ariaLabel → default localized.",
          "is_bot": false,
          "headline": "fix(sidebar): resolve merge-duplicate ariaLabel — union giữ cả 'aria-…",
          "author_name": "Fujiwara Satoshi",
          "author_login": "ecsol",
          "committed_at": "2026-07-13T04:56:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "26127db6b331492c96c6c855cc19c87efca1d99e",
          "body": null,
          "is_bot": false,
          "headline": "merge: #171 screen-reader evidence runbook vào dev",
          "author_name": "Fujiwara Satoshi",
          "author_login": "ecsol",
          "committed_at": "2026-07-13T04:53:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "afeadd696ef2df3bc32c53875430dc89064598ac",
          "body": "…on #181 verify:static + v17 frame-contracts)",
          "is_bot": false,
          "headline": "merge: v17 epic reconcile (#173) vào dev — resolve verify script (uni…",
          "author_name": "Fujiwara Satoshi",
          "author_login": "ecsol",
          "committed_at": "2026-07-13T04:53:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3b09f9176a92a9321683564bc0ac0ae8a576053f",
          "body": "Runbook để người test tạo bằng chứng VoiceOver/NVDA THẬT: worklist, tổ hợp AT bắt buộc,\nquy trình per-frame, lược đồ 12-field bản ghi, definition-of-done. KHÔNG bịa evidence —\nexport giữ untested cho tới khi người nghe AT thật. Infra gate (screen-reader-evidence.json\n+ check-screen-reader-evidence.mjs) đến cùng #173/#182.\n\nRefs #171\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(a11y): screen-reader evidence runbook for #171 (human AT testing)",
          "author_name": "Fujiwara Satoshi",
          "author_login": "ecsol",
          "committed_at": "2026-07-13T04:45:43Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "ec351d2487940d9727db5fa7e4e6cd4cb936d65f",
          "body": "…đang gate\n\n36 conflict đã resolve (union: giữ fix hành vi #175/select/tabs ở main + contract/frame test v17).\nFull gate (typecheck/test/build/check:*) đang chạy — CHƯA merge tới khi xanh.\nRefs #173.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "merge: v17 epic (#173) reconcile với main (#175/#178/#179/@18) — WIP …",
          "author_name": "Fujiwara Satoshi",
          "author_login": "ecsol",
          "committed_at": "2026-07-13T04:40:38Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "dbd7befdf91e3079a1468c0ecfe6f17bc573811c",
          "body": "…#181)\n\nTrước đây build/typecheck/lint/test + ~18 guard (prop-vocabulary, token-tiers,\ncontrast, visual-audit…) CHỈ chạy trong verify:release lúc npm publish, và\ngeometry sweep skip trên PR → PR merge xanh vẫn có thể vỡ lúc publish/main-push\n(TableProps #179 → chặn publish 18.0.1; 11 geometry regres\n[…]\n frame-a11y.yml: thêm job \"verify\" chạy verify:static trên PR+push; bỏ điều kiện\n  skip geometry trên PR. Giờ PR xanh = publish-ready.\n\nCo-authored-by: Pham Thai Duong <ecsol@users.noreply.github.com>",
          "is_bot": false,
          "headline": "ci: gate PRs with verify:static + geometry (close publish-only gap) (…",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-13T04:39:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3bc33f31687d9d62b1a50d5a7730749a0e8b0ad9",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): @godxjp/ui@18.0.1 · @godxjp/ui-mcp@18.0.1",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-13T04:30:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9cdee39803735b2283d69cb538b2121161182bb5",
          "body": "…publish)\n\n#179 thêm `export type TableProps` (HTMLAttributes passthrough + `scrollable`)\nnhưng chưa governed → check:prop-vocabulary (chỉ chạy trong verify:release lúc\npublish, KHÔNG có trong PR CI) fail → chặn npm publish 18.0.1. Thêm vào\nCOMPONENT_TYPE_ALLOWLIST như InputProps/SkeletonProps (cùng dạng passthrough).",
          "is_bot": false,
          "headline": "fix(guard): govern TableProps in prop-vocabulary allowlist (unblocks …",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-13T04:01:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9fc207a020dce3ea80f704ab9cd8fd83f3f2c77e",
          "body": "…fault + disabled TagInput contrast (#180)\n\n- AppSettingPicker: kind=\"locale\" now DEFAULTS to the compact icon-only trigger\n  (product contract) with its localized aria-label; other kinds stay labeled.\n  Overridable via appearance=\"labeled\" (settings-form rows). Drops the disclosure\n  chevron via th\n[…]\n#177), Tabs disabled-fallback + long-label scroll (#176), disabled\npassword aria-label + EmptyState valid heading order (#174/#169).\n\nRefs #175\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(app,data-entry): remaining #175 contract defects — locale icon de…",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-13T03:28:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "feff7843178e05035b402b3bbf66ab8305da096c",
          "body": "…/390) (#179)\n\n- Table: `scrollable` prop (default true). DataTable sets `scrollable={false}`\n  vì `.ui-data-table-scroll` đã sở hữu overflow + tab-stop → bỏ nested scroll\n  container + duplicate keyboard tab-stop (fix query-button-refetch,\n  query-data-state clipped ở 320/375/390).\n- AppShell demo \n[…]\ns: doc prop `scrollable` (đồng bộ MCP theo API).\n\nVerify: check:frame-geometry ✓ no regressions · typecheck ✓ · data-display 215/215 ✓\n\nCo-authored-by: Pham Thai Duong <ecsol@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(geometry): narrow-width topbar + DataTable nested-scroll (320/375…",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-13T03:16:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9347fa09f3f5401925c34f801a251a22c0f82f6a",
          "body": "Expand docs/FRAME-A11Y-CI.md with everything a contributor needs to run,\nregenerate, and extend the check:frame-axe gate that shipped in #174/#157:\n\n- How to run locally (Playwright chromium install, AXE_FRAMES_LIMIT/AXE_RUNS,\n  reading the evidence JSON, regenerating/shrinking the baseline).\n- A ro\n[…]\nOPMENT.md (verify + see-also),\nand docs/COMPONENTS.md's \"Adding a new component\" checklist. Docs only — no\ncomponent/baseline changes.\n\nCo-authored-by: Pham Thai Duong <ecsol@users.noreply.github.com>",
          "is_bot": false,
          "headline": "docs(a11y): document the per-frame axe CI gate end to end (#157) (#178)",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-13T02:22:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bc2379dff030b1c574620b899515173e2361d9ef",
          "body": null,
          "is_bot": true,
          "headline": "chore(release): @godxjp/ui@18.0.0 · @godxjp/ui-mcp@18.0.0",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-13T02:01:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4ad7bbf77c3d87daa6b89e035d8e42e5a79492db",
          "body": "…ess (#157, #163) (#174)\n\n* feat(preview,ci): per-frame axe gate + preview-contract coverage harness (#157, #163)\n\nMeta-infrastructure for the /frame contract suite (a11y CI gate + coverage\nharness). No src/components or per-component example content is touched.\n\n#157 — per-frame accessibility CI:\n-\n[…]\nttps://claude.ai/code/session_01QAd3g7dPPnwTBG5YF3Eah5\n\n---------\n\nCo-authored-by: Pham Thai Duong <ecsol@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(preview,ci): per-frame axe gate + preview-contract coverage harn…",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-13T01:31:54Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1ef05bea037b970db04c229fe4c8c7c73a5e91c9",
          "body": "…r API (#175) (#177)\n\nDataSelect (searchable mode) was silently dropping props to the SearchSelect\nengine it delegates to. Forward FormField-injected aria-* plus controlled\nopen/onOpenChange, search/onSearchChange, readOnly, size, filterOption, and\ncustom renderError/renderLoadMore slots — preservin\n[…]\n-Session: https://claude.ai/code/session_01QAd3g7dPPnwTBG5YF3Eah5\n\nCo-authored-by: Pham Thai Duong <ecsol@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(select): DataSelect prop/aria forwarding + SelectTrigger indicato…",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-13T01:05:11Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "78c1c3ba8e38eb6cedf4d3126789a95a409e4f1e",
          "body": "Tabs' fallback selection could target a disabled first item — now it\nresolves to the first ENABLED item (uncontrolled defaultValue, unknown/\ndisabled defaultValue, or a controlled value that starts unset), and\nselects nothing when every item is disabled. The horizontal TabsList is\nnow width-bounded \n[…]\n-Session: https://claude.ai/code/session_01QAd3g7dPPnwTBG5YF3Eah5\n\nCo-authored-by: Pham Thai Duong <ecsol@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(tabs): skip disabled fallback + scrollable long labels (#175) (#176)",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-13T01:05:01Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "da17e63cf8e0d7eb4c34ddc21368ae2d863db672",
          "body": "…ocus target (#164) (#172)\n\nFormField clones id + aria-labelledby/-describedby/-errormessage/-invalid/-required\nonto its control child, but many custom controls neither declared nor forwarded that\ncontract to their real semantic focus target — so the visible label/helper/error was\nsilently disconnec\n[…]\n-Session: https://claude.ai/code/session_01QAd3g7dPPnwTBG5YF3Eah5\n\nCo-authored-by: Pham Thai Duong <ecsol@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(data-entry): forward FormField a11y contract to every control's f…",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-12T22:32:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "17104980f396b7a1e4ee4c6de780168f26511cf9",
          "body": "…nation (#165, #153) (#170)\n\n#153 Pagination\n- Drop `flex-wrap: wrap` from `.ui-pagination`: desktop is now ONE horizontal row\n  that never wraps; the page-number strip scrolls on overflow, the total truncates.\n- `hideOnSinglePage` (default true): hide for zero items and single pages; opt in\n  with \n[…]\n-Session: https://claude.ai/code/session_01QAd3g7dPPnwTBG5YF3Eah5\n\nCo-authored-by: Pham Thai Duong <ecsol@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(layout,pagination): explicit responsive contracts + no-wrap pagi…",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-12T22:29:36Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4f9ef3a3a6eccd4eeb0ea3943cacf049c9e50ebd",
          "body": "…ader contract (#169)\n\nContract-only accessibility fixes across Card, EmptyState, and DataTable — no\nchange to existing visual styling or defaults.\n\n#154 — CardTitle + EmptyState configurable heading level\n- CardTitle: add `level` (1–4, default 3 — unchanged) + `as` override\n  (h1–h4/p/div). Renders\n[…]\n-Session: https://claude.ai/code/session_01QAd3g7dPPnwTBG5YF3Eah5\n\nCo-authored-by: Pham Thai Duong <ecsol@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(data-display): semantic heading levels + accessible DataTable he…",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-12T22:26:52Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b7555a3dc8d84ed8a4757d0081ad462d3b2c7212",
          "body": "…patterns + release-sync guard (#168)\n\nConsumer AI agents copy MCP patterns verbatim, so a pattern that imports a\nremoved export or names an undefined CSS class ships broken code. This makes\nthat class of drift a CI failure and rewrites the affected patterns.\n\n#156 — remove ALL stale Stack/Inline la\n[…]\n-Session: https://claude.ai/code/session_01QAd3g7dPPnwTBG5YF3Eah5\n\nCo-authored-by: Pham Thai Duong <ecsol@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(mcp,docs): purge removed Stack API + real settings/async/account …",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-12T22:26:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "09763d17c2a8c8ccb0b366d16906326c162f7660",
          "body": null,
          "is_bot": false,
          "headline": "ci(ui): shard rendered frame matrices",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-12T20:23:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7b9c2b99a9f100283fe06a7e36f5a81fb48edee5",
          "body": null,
          "is_bot": false,
          "headline": "ci: separate browser gates and move actions to Node 24",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-12T20:15:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dc26cd360323bb81e1cf4b0c0b2baab066cb640e",
          "body": null,
          "is_bot": false,
          "headline": "fix(layout): make mobile page chrome and tabs responsive",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-12T20:12:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "630213ecfe67031830617246143fc9d9749aa279",
          "body": null,
          "is_bot": false,
          "headline": "ci(a11y): require real AT evidence for screen-reader pass",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-12T20:00:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "87ae88605e70cf1155d13f4dd58a452e47082094",
          "body": null,
          "is_bot": false,
          "headline": "ci(ui): stabilize isolated frame runtime gates",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-12T19:57:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "925b16c1d461226baf30909a73d5afcc658fcace",
          "body": null,
          "is_bot": false,
          "headline": "fix(tree-select): remove nested clear button markup",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-12T15:59:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "50d0a7baebb409691c9049ebd18847c383c20320",
          "body": null,
          "is_bot": false,
          "headline": "test(ui): align regression assertions with verified contracts",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-12T15:50:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "04260273bc8a03f3786865640c216ec9853ea5d5",
          "body": null,
          "is_bot": false,
          "headline": "test(ui): close final automated touch and RTL gaps",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-12T15:41:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0dc19d2b6986d3a338839b5745694b666d704a2c",
          "body": null,
          "is_bot": false,
          "headline": "test(query): close observable touch recovery journeys",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-12T15:37:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9df1c6c3b9895297da7a86b6ef6188e9a2cca57b",
          "body": null,
          "is_bot": false,
          "headline": "ci(ui): enforce frame contracts and runtime matrices",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-12T15:37:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a305dd42a9d647be0ea44e16b30a9156add50bfa",
          "body": null,
          "is_bot": false,
          "headline": "test(layout): classify journey and touch ownership",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-12T15:32:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2d54a90cd9ff73fe665d28667ef4ddbfe304dffd",
          "body": null,
          "is_bot": false,
          "headline": "audit: close verified feedback query compositions",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-12T15:28:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ed2831bdecd2557114383903526afff781aa89ef",
          "body": null,
          "is_bot": false,
          "headline": "audit: restore verified data-entry coverage groups",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-12T15:27:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "014221a74436c2cb563e59c29c7b2f8e129003ff",
          "body": null,
          "is_bot": false,
          "headline": "test(ui): close observable touch action contracts",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-12T15:24:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "748bdf9d206831b7b823031dff23021d837941fe",
          "body": null,
          "is_bot": false,
          "headline": "test(data-entry): close executable coverage dimensions",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-12T15:24:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3d50b2cbd6c5e80b4f7f3ce244e468614bdfa347",
          "body": null,
          "is_bot": false,
          "headline": "test(layout): execute RTL and coarse-pointer closure",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-12T15:22:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c9975b877bcc98416c617c036703337a6b012879",
          "body": null,
          "is_bot": false,
          "headline": "test(toast): close public lifecycle and touch coverage",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-12T15:13:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "42a865e3ca79b43fd8789a5ff4ccea595653f194",
          "body": null,
          "is_bot": false,
          "headline": "test(layout): execute legacy shell and router adapter cases",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-12T15:12:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "488b5a5d06671df252e015f8326eac51bb2d7c92",
          "body": null,
          "is_bot": false,
          "headline": "test(layout): close remaining owner evidence",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-12T15:10:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "435c3f86db7676b569f01b14481ab2183a04dffd",
          "body": null,
          "is_bot": false,
          "headline": "test(ui): record owner coarse-pointer evidence",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-12T15:06:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "57546e208e4ee2cb41bdd1ee3d2ca552e8b177c3",
          "body": null,
          "is_bot": false,
          "headline": "test(ui): map completed owner prop contracts",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-12T15:06:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3a9545724dd0fa971897200a34c2bcfed40401d8",
          "body": null,
          "is_bot": false,
          "headline": "test(data-entry): close aliased owner evidence",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-12T15:06:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "131f95f1d9f912e7fe1e18f54b8c7cc5ef9f288a",
          "body": null,
          "is_bot": false,
          "headline": "test(data-entry): classify owner and prop evidence",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-12T15:05:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ba581b3c3f960944f7485ef4e637ec88ccc59c4a",
          "body": null,
          "is_bot": false,
          "headline": "test(navigation): record owner prop and coarse-pointer evidence",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-12T15:03:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "98508ede4d51e3d8fd84f1932ec7ba6dd5b3ad06",
          "body": null,
          "is_bot": false,
          "headline": "audit: keep real screen-reader evidence untested",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-12T14:58:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "43af3e2f85c3da3d2386980f4de622c08c0d7186",
          "body": null,
          "is_bot": false,
          "headline": "test(navigation): lock compound owner cases",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-12T14:56:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1fae3499495fdfa54510ea388894d257a5808a43",
          "body": null,
          "is_bot": false,
          "headline": "test(data-entry): add prop touch and aria-tree evidence",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-12T14:56:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "44212add29a661d59467793eb95d433200b55863",
          "body": null,
          "is_bot": false,
          "headline": "test(popover): verify coarse-pointer open and close journey",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-12T14:55:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e18131ee96f44c53c40720964bd8b6d6539568c5",
          "body": null,
          "is_bot": false,
          "headline": "fix(navigation): close owner landmark coverage",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-12T14:55:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2c4901bc945804a843bd1664e2888e9f55f1c691",
          "body": null,
          "is_bot": false,
          "headline": "test(display): classify complete public owner contracts",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-12T14:53:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6ce2bd7efdd5cad52667df46171d9d6093035d53",
          "body": null,
          "is_bot": false,
          "headline": "fix(layout): close structural landmark coverage",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-12T14:52:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6436af137a670e86bac5f210303c50517d317453",
          "body": null,
          "is_bot": false,
          "headline": "audit: track props touch and screen-reader evidence separately",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-12T14:49:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3069627c29eeebf2e8aba9036ff078e48a59a827",
          "body": null,
          "is_bot": false,
          "headline": "test(layout): audit expanded resizable state",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-12T14:48:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "51b09070ab95c1d08af82bf02223652f5bc641e2",
          "body": null,
          "is_bot": false,
          "headline": "test(query): verify provider and async lifecycle frames",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-12T14:47:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "184c18c2528f736b4fb6af6a86564b45efe40397",
          "body": null,
          "is_bot": false,
          "headline": "test(select): close popup evidence matrix",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-12T14:45:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ba12aaf75f262f65bf5b494dd9f32c82d7a79b98",
          "body": null,
          "is_bot": false,
          "headline": "fix(layout): close shell accessibility evidence",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-12T14:45:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a5a50accdb873acac93e2eefc09e79a4a4a9b36e",
          "body": null,
          "is_bot": false,
          "headline": "test(select): cover complete compound owner case",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-12T14:41:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3e4720e9f68e4dc852478c84f38a998268584a4f",
          "body": null,
          "is_bot": false,
          "headline": "test(feedback): close compound runtime frame coverage",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-12T14:41:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3a78f0f4926e8276ba705cedafdd0c8360f805bc",
          "body": null,
          "is_bot": false,
          "headline": "test(data-entry): assert compound owner source coverage",
          "author_name": "Pham Thai Duong",
          "author_login": "ecsol",
          "committed_at": "2026-07-12T14:39:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 2,
      "commits_last_year": 804,
      "latest_release_at": "2026-06-30T04:58:17Z",
      "latest_release_tag": "v16.7.2",
      "releases_from_tags": false,
      "days_since_last_push": 5,
      "active_weeks_last_year": 11,
      "days_since_latest_release": 23,
      "mean_days_between_releases": 0.5
    },
    "community": {
      "has_readme": true,
      "has_license": false,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 25,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "@godxjp/ui",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": null,
          "registry_url": "https://www.npmjs.com/package/@godxjp/ui",
          "is_deprecated": false,
          "latest_version": "18.4.0",
          "repository_url": null,
          "versions_count": 114,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 8734,
          "first_published_at": "2026-04-14T23:02:36.378000Z",
          "latest_published_at": "2026-07-18T11:48:28.839000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        },
        {
          "name": "@godxjp/ui-mcp",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [
            "mcp",
            "model-context-protocol",
            "godxjp",
            "ui",
            "design-system",
            "react",
            "claude",
            "cursor"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@godxjp/ui-mcp",
          "is_deprecated": false,
          "latest_version": "18.4.0",
          "repository_url": "https://github.com/godx-jp/godxjp-ui",
          "versions_count": 56,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 3829,
          "first_published_at": "2026-05-19T00:17:03.287000Z",
          "latest_published_at": "2026-07-18T11:48:37.286000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0,
        "collected_at": null
      },
      "open_issues_and_prs": 3
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": true,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "mcp/tsconfig.json",
        "tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 507078,
      "source_files_sampled": 860,
      "oversized_source_files": 3,
      "agent_instruction_files": [
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 6321
    },
    "dependencies": {
      "manifests": [
        "mcp/package.json",
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 86,
        "malicious_count": 0,
        "assessed_package": "npm:@godxjp/ui@18.4.0",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "@modelcontextprotocol/sdk",
          "manifest": "mcp/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.29.0"
        },
        {
          "name": "zod",
          "manifest": "mcp/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.4.3"
        },
        {
          "name": "@date-fns/tz",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.5.0"
        },
        {
          "name": "@fontsource/m-plus-2",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.2.9"
        },
        {
          "name": "@fontsource/noto-sans-jp",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.2.9"
        },
        {
          "name": "@radix-ui/react-accordion",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.2.16"
        },
        {
          "name": "@radix-ui/react-alert-dialog",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.19"
        },
        {
          "name": "@radix-ui/react-aspect-ratio",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.11"
        },
        {
          "name": "@radix-ui/react-avatar",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.2.2"
        },
        {
          "name": "@radix-ui/react-checkbox",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.3.7"
        },
        {
          "name": "@radix-ui/react-collapsible",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.16"
        },
        {
          "name": "@radix-ui/react-context",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.2.0"
        },
        {
          "name": "@radix-ui/react-context-menu",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.3.3"
        },
        {
          "name": "@radix-ui/react-dialog",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.19"
        },
        {
          "name": "@radix-ui/react-dropdown-menu",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.1.20"
        },
        {
          "name": "@radix-ui/react-hover-card",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.19"
        },
        {
          "name": "@radix-ui/react-label",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.1.11"
        },
        {
          "name": "@radix-ui/react-menubar",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.20"
        },
        {
          "name": "@radix-ui/react-navigation-menu",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.2.18"
        },
        {
          "name": "@radix-ui/react-popover",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.19"
        },
        {
          "name": "@radix-ui/react-radio-group",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.4.3"
        },
        {
          "name": "@radix-ui/react-scroll-area",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.2.14"
        },
        {
          "name": "@radix-ui/react-select",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.3.3"
        },
        {
          "name": "@radix-ui/react-separator",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.11"
        },
        {
          "name": "@radix-ui/react-slider",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.4.3"
        },
        {
          "name": "@radix-ui/react-slot",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.3.0"
        },
        {
          "name": "@radix-ui/react-switch",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.3.3"
        },
        {
          "name": "@radix-ui/react-tabs",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.17"
        },
        {
          "name": "@radix-ui/react-toggle",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.14"
        },
        {
          "name": "@radix-ui/react-toggle-group",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.15"
        },
        {
          "name": "@radix-ui/react-tooltip",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.2.12"
        },
        {
          "name": "@tanstack/react-table",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^8.21.3"
        },
        {
          "name": "class-variance-authority",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.7.1"
        },
        {
          "name": "clsx",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.1.1"
        },
        {
          "name": "cmdk",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.1"
        },
        {
          "name": "date-fns",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.1.0"
        },
        {
          "name": "embla-carousel-react",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^8.6.0"
        },
        {
          "name": "input-otp",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.4.2"
        },
        {
          "name": "lucide-react",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.25.0"
        },
        {
          "name": "qrcode.react",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "4.2.0"
        },
        {
          "name": "react-day-picker",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^10.0.1"
        },
        {
          "name": "react-resizable-panels",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.12.2"
        },
        {
          "name": "sonner",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.0.7"
        },
        {
          "name": "tailwind-merge",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.5.0"
        },
        {
          "name": "tailwindcss-animate",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.0.7"
        },
        {
          "name": "vaul",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.2"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 132,
        "open_issues": 3,
        "closed_ratio": 0.958,
        "closed_issues": 68,
        "closed_unmerged_prs": 6
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "ecsol",
          "commits": 728,
          "avatar_url": "https://avatars.githubusercontent.com/u/26842626?v=4"
        },
        {
          "type": "User",
          "login": "claude",
          "commits": 69,
          "avatar_url": "https://avatars.githubusercontent.com/u/81847?v=4"
        }
      ],
      "contributors_sampled": 2,
      "top_contributor_share": 0.913
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "frame-a11y.yml",
        "frame-contracts.yml",
        "npm-publish.yml",
        "preview-pages.yml",
        "release-integrity.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        "eslint.config.js"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "pnpm-lock.yaml"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "13 out of 13 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/27 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 6,
            "reason": "project has 2 contributing companies or organizations -- score normalized to 6",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 0,
            "reason": "license file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "14 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "929463cc04b7afc323dba2eeb706f0299e59e494",
        "ran_at": "2026-07-23T19:16:04Z",
        "aggregate_score": 2.3,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-23T06:03:13Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-18T11:30:24Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 163,
          "created_at": "2026-07-12T10:45:54Z",
          "last_comment_at": "2026-07-16T06:25:11Z",
          "last_comment_author": "ecsol"
        },
        {
          "number": 171,
          "created_at": "2026-07-12T19:58:37Z",
          "last_comment_at": "2026-07-16T08:05:42Z",
          "last_comment_author": "ecsol"
        },
        {
          "number": 204,
          "created_at": "2026-07-18T02:01:36Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/godx-jp/godxjp-ui",
    "host": "github.com",
    "name": "godxjp-ui",
    "owner": "godx-jp"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 56,
      "inputs": {
        "security": 38,
        "vitality": 77,
        "community": 26,
        "governance": 56,
        "engineering": 76
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 77,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 62,
            "inputs": {
              "commits_last_year": 804,
              "human_commit_share": 0.95,
              "days_since_last_push": 5,
              "active_weeks_last_year": 11
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "11/52 weeks with commits",
                "points": 7.6,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 11
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "804 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 804
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 2,
              "latest_release_tag": "v16.7.2",
              "releases_from_tags": false,
              "days_since_latest_release": 23,
              "mean_days_between_releases": 0.5
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "2 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 23 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 23
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~0.5 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 0.5
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 26,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "critical",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 25,
            "inputs": {
              "has_readme": true,
              "has_license": false,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "no license file detected",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "license_absent",
                    "params": {}
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 68,
            "inputs": {
              "packages": [
                "@godxjp/ui",
                "@godxjp/ui-mcp"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 12563
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "12,563 downloads/month across npm",
                "points": 54.7,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 12563,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 56,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 20,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 2,
              "top_contributor_share": 0.913
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 91% of commits",
                "points": 2,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 91
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "2 contributors",
                "points": 2.7,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 81,
            "inputs": {
              "merged_prs": 132,
              "open_issues": 3,
              "closed_issues": 68,
              "issue_closed_ratio": 0.958,
              "closed_unmerged_prs": 6
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "96% of issues closed",
                "points": 44.8,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 96
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "132/138 decided PRs merged",
                "points": 36.6,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 132,
                      "decided": 138
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/27 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "followers": 1,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "godx-jp",
              "public_repos": 10,
              "account_age_days": 107
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "1 followers of godx-jp",
                "points": 2.2,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 1,
                      "login": "godx-jp"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "10 public repos, account ~0 yr old",
                "points": 8.2,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 10
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "@godxjp/ui",
                "@godxjp/ui-mcp"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 5
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "2 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 2,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 5 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "114 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 114
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 76,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "5 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": "eslint.config.js",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.js"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "13 out of 13 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 65,
            "inputs": {
              "topics": [],
              "has_wiki": false,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 38,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "critical",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Packaging, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "packaging",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 23,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 2.3
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "13 out of 13 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/27 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "14 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:@godxjp/ui@18.4.0 runtime dependency closure — what installing the published package pulls in — 86 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:@godxjp/ui@18.4.0",
                  "assessed": 86
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 0,
              "affected_packages": 0,
              "assessed_packages": 86,
              "unassessed_packages": 0,
              "affected_by_severity": "none",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "no indirect dependency carries a known advisory",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "no_indirect_advisories",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 86,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 1
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 75,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.989,
              "agent_instruction_files": [
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 6321
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "94 of 95 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 94,
                      "sampled": 95
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 64,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "pnpm-lock.yaml"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "mcp/tsconfig.json",
                "tsconfig.json"
              ],
              "agent_commit_share": 0.28,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": "eslint.config.js",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.js"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "mcp/tsconfig.json, tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "mcp/tsconfig.json, tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "28 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 28,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 507078,
              "source_files_sampled": 860,
              "oversized_source_files": 3
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "3/860 source files over 60KB",
                "points": 54.8,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 860,
                      "oversized": 3
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "moderate",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": true,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-23T19:16:18.363635Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/g/godx-jp/godxjp-ui.svg",
  "full_name": "godx-jp/godxjp-ui",
  "license_state": "absent",
  "license_spdx": null
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsnpm.