Public record
Software health reportschema 0.27.0 · metrics 1.13.0 · 2026-07-26 23:59 UTC

ifx-run / ifx

Ifx is one reusable on-chain orchestration program for Solana.

TypeScript · Rust · GoApache-2.0★ 1 star⑂ 0 forkssince Jun 2026View on GitHub ↗

ifx-run/ifx holds a health index of 48 out of 100, placing it in the At risk band. It scores highest on AI Readiness (74/100) and lowest on Community & Adoption (28/100). It was last updated 8 days ago. A single contributor accounts for most of its recent work.

48
overall / 100
At risk

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

48
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

ifxOrganization
1 follower4 public repossince Jun 2026

This repository is backed by an organization — shared, accountable stewardship that can outlive any single maintainer.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publishTags
Gogithub.com/ifx-run/ifx/go-sdkv0.1.3-48 days ago
npm@ifx-run/sdk0.1.2282622 days agosolanaanchorifxssacpitransactionweb3
crates.ioifx-sdk0.1.221322 days ago

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

64Moderate · 22% of overall
How it's scored
28.8/36Push recency — last push 8 days ago
4.2/36Commit cadence — 6/52 weeks with commits
15.3/18Commit volume — 50 commits in the last year
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Inputs used
commits_last_year50
human_commit_share1
days_since_last_push8
active_weeks_last_year6
How it's scored
16.2/27Ships releases — 2 version tags (no GitHub releases)
36/36Release recency — latest release 8 days ago
27/27Release cadence — a release every ~14.2 days
0/10OpenSSF Scorecard: Signed-Releases — no data
Inputs used
releases_count2
latest_release_tagv0.1.3
releases_from_tagsyes
days_since_latest_release8
mean_days_between_releases14.2
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

28Critical · 18% of overall
How it's scored
0/60Stars — 1 stars
0/25Forks — 0 forks
0/15Watchers — 0 watchers
Inputs used
forks0
stars1
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (Apache-2.0)
0/18CONTRIBUTING guide
0/13.5Code of conduct
0/7.2Issue template
0/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingno
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno
How it's scored
33.1/80Monthly downloads — 303 downloads/month across crates, go, npm
0/20Registry dependents — not reported by this ecosystem
Inputs used
packagesgithub.com/ifx-run/ifx/go-sdk, @ifx-run/sdk, ifx-sdk
dependents
ecosystemscrates, go, npm
total_downloads64
monthly_downloads303
Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

34At risk · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
0/22.5Commit distribution — top contributor authored 100% of commits
1.4/13.5Contributor breadth — 1 contributors
3/10OpenSSF Scorecard: Contributors — project has 1 contributing companies or organizations -- score normalized to 3
Inputs used
bus_factor1
contributors_sampled1
top_contributor_share1
How it's scored
0/46.8Issue resolution — no issues or no data
0/38.3PR acceptance — no decided pull requests or no data
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Inputs used
merged_prs0
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs0
Excluded from scoring (no data or not applicable): Issue resolution, PR acceptance. Remaining weights renormalized.
How it's scored
30/30Ownership backing — organization-owned
0/20Verified domain
2.2/25Owner reach — 1 followers of ifx-run
5.4/25Track record — 4 public repos, account ~0 yr old
Inputs used
followers1
owner_typeOrganization
is_verified
owner_loginifx-run
public_repos4
account_age_days52
How it's scored
25/25Published & resolvable — 3 package(s) on crates, go, npm
35/35Publish recency — latest publish 8 days ago
20/20Version history — 6 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packagesgithub.com/ifx-run/ifx/go-sdk, @ifx-run/sdk, ifx-sdk
ecosystemscrates, go, npm
any_deprecatedno
min_days_since_publish8

Engineering Quality

Are baseline engineering and documentation practices in place?

66Moderate · 20% of overall
How it's scored
24/24CI workflows — 1 workflow(s)
24/24Tests present
0/16Linter config
0/9.6Pre-commit hooks
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — no data
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configno
has_precommit_configno
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.
How it's scored
30/30README
25/25Documentation directory
0/15Documentation / homepage site
10/10Repository description
0/10Topics
10/10Wiki
Inputs used
topics
has_wikiyes
homepage
has_readmeyes
has_docs_diryes
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

44At risk · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — no data
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0.8/2.5Contributors — project has 1 contributing companies or organizations -- score normalized to 3
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
0/5Packaging — no data
1.5/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 3
0/5SAST — no SAST tool detected
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — no data
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 42 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated15
scorecard_versionv5.5.0
checks_inconclusive3
scorecard_aggregate3
Excluded from scoring (no data or not applicable): ci_tests, packaging, signed_releases. Remaining weights renormalized.
How it's scored
35/35Direct dependencies free of known advisories — no direct dependency carries a known advisory
25/25Indirect dependencies free of known advisories — no indirect dependency carries a known advisory
0/40No advisories left outstanding — no advisory carries a publication date
Inputs used
sourceosv
advisories0
affected_packages0
assessed_packages1
unassessed_packages0
affected_by_severitynone
direct_affected_packages0
Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:@ifx-run/sdk@0.1.2 runtime dependency closure — what installing the published package pulls in — 1 packages. Reachability is not analyzed.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

74Good · 0% of overall
How it's scored
45/45Agent instructions — AGENTS.md
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 49 of 50 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share0.98
agent_instruction_filesAGENTS.md
agent_instruction_max_bytes985
How it's scored
12.6/18One-command bootstrap — Cargo.toml, crates/ifx-core/Cargo.toml, go-sdk/go.mod (toolchain convention, no task runner)
22/22Automated tests
0/11Lint / format config
11/11Static type checking — sdk/tsconfig.json, tsconfig.json
10/10Reproducible environment — lockfile
10/10Demonstrated agent practice — 49 of the last 50 commits agent-authored or agent-credited
0/8Automated maintenance — no automated dependency updates observed
3/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 3
Inputs used
has_nixno
has_testsyes
lockfilesCargo.lock, go.sum, package-lock.json
has_dockerfileno
typed_languageyes
bootstrap_files
has_devcontainerno
has_linter_configno
typecheck_configssdk/tsconfig.json, tsconfig.json
agent_commit_share0.98
toolchain_manifestsCargo.toml, crates/ifx-core/Cargo.toml, go-sdk/go.mod, programs/ifx/Cargo.toml, rust-sdk/Cargo.toml
dependency_bot_commit_share0
How it's scored
45/45Type-checkable code — TypeScript (statically typed)
55/55Manageable file sizes — 0/275 source files over 60KB
Inputs used
primary_languageTypeScript
largest_source_bytes50,691
source_files_sampled275
oversized_source_files0
How it's scored
0/40API schema (OpenAPI/GraphQL/proto)
0/20MCP server
40/40Runnable examples — examples
Inputs used
example_dirsexamples
has_mcp_signalno
api_schema_files

Key facts

1GitHub stars
1contributors
50commits, last 12 months
8days since last push
2releases
1bus factor
0open issues
crates.io, Go, npmpackage ecosystems

Data collection warnings

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

More detail

OpenSSF Scorecard 3.0 / 10
3.0aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-26 23:59 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
n/aCI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
3Contributorsproject has 1 contributing companies or organizations -- score normalized to 3
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
n/aPackagingpackaging workflow not detected
3Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 3
0SASTno SAST tool detected
10Security-Policysecurity policy file detected
n/aSigned-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities42 existing vulnerabilities detected
Direct dependencies 10
RegistryPackageVersion constraintManifest
Gogithub.com/gagliardetto/solana-gov1.12.0go-sdk/go.mod
npm@anchor-lang/core^1.0.2package.json
npm@ifx-run/sdkfile:./sdkpackage.json
npmbn.js^5.2.1package.json
crates.ioanchor-lang1.0.2rust-sdk/Cargo.toml
crates.ioifx-core0.1.2rust-sdk/Cargo.toml
crates.ioborsh1.5rust-sdk/Cargo.toml
crates.iosolana-sdkrust-sdk/Cargo.toml
crates.iosolana-system-interfacerust-sdk/Cargo.toml
npmbn.js^5.2.1sdk/package.json
All dependencies not collected

The resolved dependency set could not be collected for this report: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Dependency advisories 0

Installing npm:@ifx-run/sdk@0.1.2 pulls in 1 packages, direct and transitive: 0 carry known advisories, of which 0 are direct dependencies.

No known advisories affect the assessed dependencies.

An advisory means the version recorded in the dependency graph falls inside an advisory’s affected range. Reachability is not analysed, and the graph includes development and test pins — a finding may concern tooling rather than shipped software.

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 2906,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "Go": 239998,
        "Rust": 444510,
        "Shell": 32458,
        "JavaScript": 20939,
        "TypeScript": 512155
      },
      "pushed_at": "2026-07-18T06:22:43Z",
      "created_at": "2026-06-08T12:41:28Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-18T06:16:14Z",
      "description": "Ifx is one reusable on-chain orchestration program for Solana.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript",
        "Rust",
        "Go"
      ]
    },
    "owner": {
      "blog": null,
      "name": "ifx",
      "type": "Organization",
      "login": "ifx-run",
      "company": null,
      "location": null,
      "followers": 1,
      "avatar_url": "https://avatars.githubusercontent.com/u/290568763?v=4",
      "created_at": "2026-06-04T01:55:45Z",
      "is_verified": null,
      "public_repos": 4,
      "account_age_days": 52
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.1.3",
          "kind": "patch",
          "published_at": "2026-07-18T06:15:06Z"
        },
        {
          "tag": "v0.1.2",
          "kind": "patch",
          "published_at": "2026-07-04T01:38:58Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "522a2f9d8640c38d8f334207b6b3b509cd075a2c",
          "body": "bps may be u8–u64 and mulDiv divisor c may be narrower than a/b, with\non-chain promote; ship SDK 0.1.3 aligned to ifx/ifx-core 0.1.2 (redeploy).\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Allow narrow unsigned operands on bpsMul/mulDiv and bump 0.1.3.",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-07-18T06:15:06Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "28a600f4e0d4bf7a0fa33ce7d71a9c6434392525",
          "body": "Replace the legacy 512-byte test Frame with three copy-paste-ready production addresses and relegate 6RNv… to test-only in frame-authority §6.0.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "docs: document mainnet public Frame pool (Fr*, tapeLen 1024)",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-07-07T16:07:48Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "fe54f686ad18eb433ecbe8025b2077a19762337c",
          "body": "Link static Shields badge to verify.osec.io and note mainnet verified status in security table.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "docs: add mainnet verified badge to README",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-07-04T07:49:35Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "873fc418051e4ddf7529078194a8fb576333a097",
          "body": "Fix macOS mktemp in buffer hash verify, ProgramData extend on buffer-only\ndeploy, duplicate --url in verify-from-repo, and sync regenerated idl paths.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix: harden deploy/verify scripts; sync IDL to sdk",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-07-04T07:41:24Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "fdcbae25f9b742ae5e33c6c5a41f3b2f1147fe6b",
          "body": "Add cluster-specific verifiable build scripts, buffer ELF hash preflight,\nIFX_SKIP_BUILD without buffer, and cfg-gated declare_id support in keys:verify.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "docs: add deploy playbook; harden buffer deploy and keys:verify",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-07-04T06:31:24Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "ecef339502be158febdc6ca93c05c6b33473bfd0",
          "body": "Unquoted BUILD_ARGS split --cargo-build-sbf-args=--features devnet into two tokens, so the repo path was rejected as an unexpected argument.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix: quote solana-verify build args to preserve --features value",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-07-04T01:55:21Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "18208f7e16229f672628e877f3b3fc5b9726c1bf",
          "body": "Cargo.lock still resolves solana-program 3.0.0, so solana-verify picked the 3.0.0 image with Cargo 1.84 and failed on edition2024 deps. Align with Anchor.toml via workspace.metadata.cli.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix: pin solana-verify Docker image to 3.1.10 for verifiable builds",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-07-04T01:53:37Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "cc6ed60960adefdb36de371dfa7d590617b3068a",
          "body": "Default deploy uses solana-verify Docker builds, embeds source_release/revision in security_txt via build.rs, fixes program extend minimum (10240 bytes), and passes devnet/mainnet Cargo features so verify-from-repo matches on-chain program ids.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Add verifiable deploy pipeline with cluster declare_id features.",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-07-04T01:38:58Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3e8d0d2af133a2f390527fd6c74b71fa5afe5ff5",
          "body": "Align TS/Go/Rust changelogs, docs, and IDL metadata with wire tag 33.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Bump to 0.1.2 SDKs and 0.1.1 ifx-core for UnwrapLamports release.",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-07-03T12:48:14Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6a4a91034b1fa86ca3c4ebcde77682f9ef668c77",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'main' into feat/token-unwrap-lamports-structured-cpi",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-07-03T02:47:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6ab7609aa8c6adcbc3dce5b39e2e15f88f8e42b7",
          "body": "Sync IFX_PROGRAM_BUFFER resume flow to devnet, default write-buffer/deploy to --use-rpc for HTTP proxy environments, and fix macOS awk SOL formatting.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "deploy: add devnet buffer reuse and proxy-safe RPC uploads.",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-06-23T13:34:12Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3e47ed5685f552c2d23baacd2a588b4844cfea8e",
          "body": "mintTo uses web3 block-height confirm; use createMintToInstruction + sendAndConfirmSignersOnly for CI stability.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "test: replace spl-token mintTo in dust Token-2022 tests.",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-06-22T13:23:44Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "d4cd41bbfdda61d519a6cbb1c7502e8072d25a32",
          "body": "Poll signatures in confirmSignature and sendAndConfirmTransaction; use local mint helpers in personal AMM setup (spl-token mintTo uses block-height confirm).\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "test: avoid web3 block-height confirm in CI-heavy paths.",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-06-22T13:05:34Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "1dd9456b279b73a53b13d00379230ecbc4c3b873",
          "body": "Block-height confirm expires under slow Surfpool loads; waitForSignature avoids flaky personal AMM v0 test.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "test: use signature polling for v0/LUT confirms in CI.",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-06-21T15:31:52Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "70ce89401602be766e67452271dee0e4200ac79e",
          "body": "Fresh checkouts have no target/idl until anchor build; mkdir -p fixes pretest.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix: create target/idl before idl:sync on clean CI runners.",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-06-21T15:13:21Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4864e5ed29cc40c168293b9620d69d81304240ec",
          "body": "avm 1.0.2 no longer compiles on Rust 1.89; use 1.91 only for the install step.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "ci: install avm with Rust 1.91 and unset CARGO_TARGET_DIR.",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-06-21T15:07:05Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "dd97c791e12c3fd561b49fd448fdb355c58c2ab1",
          "body": "Run clippy, security:preflight, and npm run all:test on main; document status in README.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "ci: add GitHub Actions workflow and README CI badge.",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-06-21T14:36:09Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "ed39bff128bbf43a4ebe997169d3b4d999b05863",
          "body": "Document how Solana Explorer reads logo/name from on-chain security metadata separately from binary security_txt and Solscan.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "docs: add Explorer Program Metadata manifest and upload guide.",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-06-19T07:22:18Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "fe44e4f47206413afd2ff3f35173612b120f571a",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "assets: update Ifx icon f strokes and regenerate PNG.",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-06-18T01:50:21Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "1ac5630a6410f518df30bce77570478ad864f0ef",
          "body": "Support p-token optional-lamport unwrap via UnwrapLamportsPatch (all or frame-bound amount) across ifx-core, TS/Go/Rust SDKs, and codec tests; legacy SPL Token program id only.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Add Structured CPI for SPL Token UnwrapLamports (wire tag 33).",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-06-18T01:09:33Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4f53d9260d04be4d3553bd7fcd00d15cd466afdf",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "assets: add geometric Ifx brand icon (SVG and 512 PNG).",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-06-17T11:55:57Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "8aae0dade3c4848c24d7210826708a459130afb2",
          "body": "Expand the ifx-run org showcase section with the Rust ifx-sdk Raydium\nCPMM demo alongside ifx-pumpfun-ext.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "docs: add ifx-raydium-ext to mainnet reference integrations table.",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-06-15T13:55:23Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "329d7fd8b281939799125ebecfecc995a02144b4",
          "body": "Point readers to the ifx-run org showcase for Pump.fun v0 orchestration\nand clarify it is external demo software, not part of this repo.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "docs: link ifx-pumpfun-ext as mainnet reference integration.",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-06-14T13:44:55Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "09936b0f2823ae37d49008f69f46798bf2249b12",
          "body": "Fix LetAccountInput duck typing, add forPublicFrame, decode/logs helpers,\nand clearer planner errors across TS, Go, and Rust clients. Wire unchanged.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Release SDK v0.1.1 — integrator feedback (no program changes).",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-06-14T13:04:53Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "8a1decd06bbdea4ccce37beb9192dd25b9187715",
          "body": "Publish the public tapeLen=512 Frame for backend orchestration in README\nand add npm run create-public-frame (wallet/RPC via env only).\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "docs: document mainnet shared Frame and add create-public-frame script.",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-06-13T14:06:08Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a505494380a4121f976dc0bec0688530db0a2987",
          "body": "Frame tape vs Memory PDA as mid-tx scratch; drop misleading \"no Memory\" wording.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "docs: clarify Lighthouse vs Ifx comparison uses mechanisms not labels.",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-06-13T07:49:43Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a5cb6ae797a53be407989de0b773d4f19c9a8d1c",
          "body": "Put Networks & SDKs quick reference before What Ifx is; slim Deployment section to maintainer notes.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "docs: move cluster program IDs and SDK table to README top.",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-06-13T07:43:57Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f22955e7dde2b5077d3ba602af123b2f04a3cba0",
          "body": "Unify TypeScript, Go, and Rust registry install instructions across READMEs and client-sdks; drop devnet dist-tag guidance.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "docs: align SDK 0.1.0 install docs and add crates.io badges.",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-06-13T07:38:28Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "e8e14163c1d7cf6c920cb01a6454574b48f36396",
          "body": "Align with ifx-sdk and go-sdk 0.1.0; publish via latest tag and document deprecating legacy devnet previews.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "release: bump @ifx-run/sdk to 0.1.0 for npm publish.",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-06-13T07:32:58Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "bd6faa0e962991fa109340517011c026f11defe1",
          "body": "Reflect mainnet as the live default across READMEs and SDK docs while keeping no-third-party-audit warnings.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "docs: remove developer preview wording after mainnet deploy.",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-06-13T07:14:10Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2a3a92a97d342b5c73f59be153b0f7241d31a349",
          "body": "…eploy.\n\nMirror devnet deploy flow for mainnet (RPC/balance/proxy options, anchor --buffer resume), and mark ifxmwW… as deployed on mainnet in README.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat: add mainnet deploy script with buffer reuse and document live d…",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-06-13T07:11:24Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2a9f495179bcf7d9d1b8ac52ee4564392993cc9e",
          "body": "Add IFX_MAINNET_PROGRAM_ID across TS/Go/Rust, switch DEFAULT to ifxmwW…, extend keys verify and root README deployment guidance.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat: default SDK program id to mainnet and document cluster addresses.",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-06-13T06:24:53Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a89ca575dfaf8dfb8a9cfe056141aec9df938c5f",
          "body": "Record the 2026-06-13 maintainer-led review (63/11/0) with doc links, and commit mainnet pubkey layout with gitignored keypair path.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "docs: publish internal audit @ 8a42766 and add mainnet program id.",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-06-13T06:13:39Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "8a42766c00226a4197ce3e43376115bc21ac6056",
          "body": "Explain how Ifx closes same-tx check-use gaps; replace mempool/block/gas\nwording with slot and fee-payer terms while keeping smart contract as\nprogram-equivalent in personal-amm docs.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "docs: add TOCTOU framing to README and align Solana terminology.",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-06-13T05:52:17Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "8a71855bb952fce9a26419acaf6e8c8d3f8d963d",
          "body": "Resolve clippy lints across ifx-core, ifx-sdk, and programs/ifx, and add\nall:test to run TS, Go, and Rust test suites in one command.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix: satisfy cargo clippy -D warnings and add npm run all:test.",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-06-13T05:44:29Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "12f51a93cc662c7ebe54e6ea34ae2183e4eaed8a",
          "body": "Add L1–L3 planners with localnet integration on Go and Rust, fix Go\nstructured CPI encoding when wire tag is 0, and add 33-variant encode_cpi\ngolden tests so TS/Go/Rust stay aligned.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat: align Go/Rust SDK planners and lock structured CPI wire parity.",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-06-13T03:47:32Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "101515c5363120b1aa5c778687e583569eb7d00c",
          "body": "Unify Rust SDK with TS/Go in client docs; rewrite crate rustdoc; clarify top-level\nIfx integration (drop scratch PDA backlog). Add DEFAULT_TAPE_LEN (512),\nassert_multi/tape_len guidance, production Frame authority notes, fix ifx-core\ndoc-tests, and align integration tests across TS, Go, and Rust.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "docs: Rust SDK client index, integration defaults, and tape_len 512.",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-06-12T15:17:24Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a9c22bea99b47989cbb1d1c1480de43a76b30ef5",
          "body": "Squash branch work from main:\n\n- Milestone A: cast/stake/mint lets, guardrails, ifx_assert_multi\n- R5: Lighthouse LetBinding tags 45–67 and coverage docs\n- SP-5: stake structured CPI and example sweep\n- ifx-core: wire, layout, structured-cpi extraction (R1)\n- ifx-sdk: FrameScratch planner, ix_* / CPI / if_else (R2–R3), localnet e2e\n- go-sdk: align error codes with on-chain ErrorCode enum\n- Align Solana workspace deps with Anchor 1.0.2\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat: terminal A/B — ifx-core, ifx-sdk, Lighthouse R5, and stake CPI",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-06-11T16:21:47Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4896d22364c5d2a66f956d0d3a66912baca1fd84",
          "body": "…et.0.\n\nUpdate implementation guides, glossary, and READMEs for the new\n[2][accounts_start][accounts_len][StructuredCpiPatch…] layout.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "docs: align Structured CPI Borsh wire and bump SDK refs to 0.4.0-devn…",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-06-10T18:01:15Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "52efa475520815f8ae5653fd6caa91406344da05",
          "body": "Cpi::Structured now serializes as [2][accounts_start][accounts_len][patch…]\nwith single-byte Value slots; bump @ifx-run/sdk to 0.4.0-devnet.0 and deprecate\nencodeStructuredCpiPatchPayload in favor of encodeStructuredCpiPatch.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Migrate Structured CPI wire to Borsh and align TS/Go SDK encoders.",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-06-10T17:57:00Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "98c48abaa2807237b5a315013fe24d75cda11f89",
          "body": "…dmap.\n\nDocument grant-aligned domain benchmark, explicit As* cast plan (tags 19–28), stake survey, and mainnet terminal goals without program changes.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "docs: add Lighthouse coverage, IR completeness, and milestone A/B roa…",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-06-10T16:26:07Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "736fbcb6d68343d88e39e1e6f27290e347674d7d",
          "body": "…API cleanup.\n\nRewrite root README around mid-tx orchestration vs wrapper programs and client-only assembly; align L0–L3 docs and examples with structured CPI best practices, on-chain ATA rent, and planPublicFrame. Add examples:typecheck, fix SECURITY links, rename public Frame helpers to publicFrameAuthority, and remove legacy close_authority / InvalidCloseAuthority aliases.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Docs and SDK: README rewrite, structured CPI examples, and authority …",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-06-10T13:22:28Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "1acf91b43ec0e445a5bf84103cecf2b01fe691c2",
          "body": "Frame-bound slots appear as `patch amount <- $0` instead of only the ix label; wire literals are omitted. Updates debugging docs for RawPatched vs Structured formats.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Log structured CPI patches with named fields in pseudocode output.",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-06-09T15:58:05Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "12fc56772372c8430c274e950eb6fc0fd07e27bb",
          "body": "…sts.\n\nDocument public Frame as the zero-cost default, add private ifx_let UnauthorizedFrameWrite coverage, and add Go PlanPublicFrame/immortal tests.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Default docs and L0 examples to planPublicFrame; tighten authority te…",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-06-09T15:40:37Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6f675d51bf2c15ad44df99ffe94d416ec2fd56f0",
          "body": "Clarify Ifx vs per-flow wrapper programs, use 合约 in zh-CN prose, and link SDK READMEs back to the repo homepage.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Rewrite README intro to state the orchestration value prop plainly.",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-06-09T15:18:36Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a951474d3a7a08ea3b37733aaa9e54c9161cb595",
          "body": "Re-run Phase 0 (137 npm / 49 cargo tests) and refresh checklist after Structured CPI merge; update audit index and README links.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Publish internal security review for commit 11be96e.",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-06-09T14:46:31Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "11be96eed3724291bd514ac659b8e4eb1f3ad0dd",
          "body": "…t.0.\n\nReplace Typed mask+template CPI with flat StructuredCpiPatch (29 wire tags) and\nRawPatched escape hatch; add Frame authority write ACL, Frame.generation (+8 B\nlayout), Pubkey on tape, Go SDK parity, docs/skills sync, and structured CPI\nprogram-id guard tests. Breaking vs 0.2.0-devnet.0 — redeploy devnet and recreate\nFrame PDAs.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Ship Structured CPI, Frame authority, generation, and SDK 0.3.0-devne…",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-06-09T14:40:56Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "10f9c06160ec876364c6a7bc0a21e462abddd5dd",
          "body": "Update program-security docs to the 2026-06-08 review at 09a9114.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Point npm badge at @devnet tag and refresh audit links in README.",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-06-08T13:06:31Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "c48c320f6d4b35cf7c3f12907d6537999bfabcdc",
          "body": "Record reviewed program revision explicitly after the monolithic Initial commit.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Pin internal audit report to Initial commit 09a9114.",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-06-08T12:52:35Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "09a9114e167216da645f7da24e348fbe054fa2b0",
          "body": "Ifx: on-chain conditional CPI SDK (TypeScript + Go), unified Cpi/IfElseArm wire, devnet npm 0.2.0-devnet.0 prep.\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Initial commit.",
          "author_name": "Chopin65536",
          "author_login": "chopin65536",
          "committed_at": "2026-06-08T12:52:00Z",
          "body_truncated": false,
          "is_coding_agent": true
        }
      ],
      "releases_count": 2,
      "commits_last_year": 50,
      "latest_release_at": "2026-07-18T06:15:06Z",
      "latest_release_tag": "v0.1.3",
      "releases_from_tags": true,
      "days_since_last_push": 8,
      "active_weeks_last_year": 6,
      "days_since_latest_release": 8,
      "mean_days_between_releases": 14.2
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 62,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/ifx-run/ifx/go-sdk",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/ifx-run/ifx/go-sdk",
          "is_deprecated": false,
          "latest_version": "v0.1.3",
          "repository_url": "https://github.com/ifx-run/ifx",
          "versions_count": 4,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-18T06:15:06Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 8
        },
        {
          "name": "@ifx-run/sdk",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [
            "solana",
            "anchor",
            "ifx",
            "ssa",
            "cpi",
            "transaction",
            "web3"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@ifx-run/sdk",
          "is_deprecated": false,
          "latest_version": "0.1.2",
          "repository_url": "https://github.com/ifx-run/ifx",
          "versions_count": 6,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 282,
          "first_published_at": "2026-06-07T09:36:46.218000Z",
          "latest_published_at": "2026-07-04T07:47:24.171000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 22
        },
        {
          "name": "ifx-sdk",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [],
          "ecosystem": "crates",
          "matches_repo": true,
          "registry_url": "https://crates.io/crates/ifx-sdk",
          "is_deprecated": false,
          "latest_version": "0.1.2",
          "repository_url": "https://github.com/ifx-run/ifx",
          "versions_count": 3,
          "total_downloads": 64,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 21,
          "first_published_at": "2026-06-13T07:24:13.311751Z",
          "latest_published_at": "2026-07-04T07:45:51.747819Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 22
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 1,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": null,
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "sdk/tsconfig.json",
        "tsconfig.json"
      ],
      "toolchain_manifests": [
        "Cargo.toml",
        "crates/ifx-core/Cargo.toml",
        "go-sdk/go.mod",
        "programs/ifx/Cargo.toml",
        "rust-sdk/Cargo.toml"
      ],
      "largest_source_bytes": 50691,
      "source_files_sampled": 275,
      "oversized_source_files": 0,
      "agent_instruction_files": [
        "AGENTS.md"
      ],
      "agent_instruction_max_bytes": 985
    },
    "dependencies": {
      "manifests": [
        "Cargo.toml",
        "go-sdk/go.mod",
        "package.json",
        "rust-sdk/Cargo.toml",
        "sdk/package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 1,
        "malicious_count": 0,
        "assessed_package": "npm:@ifx-run/sdk@0.1.2",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "crates",
        "go",
        "npm"
      ],
      "dependencies": [
        {
          "name": "github.com/gagliardetto/solana-go",
          "manifest": "go-sdk/go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.12.0"
        },
        {
          "name": "@anchor-lang/core",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.0.2"
        },
        {
          "name": "@ifx-run/sdk",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "file:./sdk"
        },
        {
          "name": "bn.js",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.2.1"
        },
        {
          "name": "anchor-lang",
          "manifest": "rust-sdk/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.0.2"
        },
        {
          "name": "ifx-core",
          "manifest": "rust-sdk/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.1.2"
        },
        {
          "name": "borsh",
          "manifest": "rust-sdk/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.5"
        },
        {
          "name": "solana-sdk",
          "manifest": "rust-sdk/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "solana-system-interface",
          "manifest": "rust-sdk/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "bn.js",
          "manifest": "sdk/package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.2.1"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 0,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "chopin65536",
          "commits": 50,
          "avatar_url": "https://avatars.githubusercontent.com/u/291778881?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "Cargo.lock",
        "go.sum",
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 3,
            "reason": "project has 1 contributing companies or organizations -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 3,
            "reason": "dependency not pinned by hash detected -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "42 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "522a2f9d8640c38d8f334207b6b3b509cd075a2c",
        "ran_at": "2026-07-26T23:59:05Z",
        "aggregate_score": 3,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-18T06:27:46Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": null,
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/ifx-run/ifx",
    "host": "github.com",
    "name": "ifx",
    "owner": "ifx-run"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "at_risk",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 48,
      "inputs": {
        "security": 44,
        "vitality": 64,
        "community": 28,
        "governance": 34,
        "engineering": 66
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "moderate",
        "name": "Vitality",
        "value": 64,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "at_risk",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 48,
            "inputs": {
              "commits_last_year": 50,
              "human_commit_share": 1,
              "days_since_last_push": 8,
              "active_weeks_last_year": 6
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 8 days ago",
                "points": 28.8,
                "status": "partial",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 8
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "6/52 weeks with commits",
                "points": 4.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 6
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "50 commits in the last year",
                "points": 15.3,
                "status": "partial",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 50
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 88,
            "inputs": {
              "releases_count": 2,
              "latest_release_tag": "v0.1.3",
              "releases_from_tags": true,
              "days_since_latest_release": 8,
              "mean_days_between_releases": 14.2
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "2 version tags (no GitHub releases)",
                "points": 16.2,
                "status": "partial",
                "details": [
                  {
                    "code": "version_tags_no_releases",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 8 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 8
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~14.2 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 14.2
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 28,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 1,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "1 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "at_risk",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 41,
            "inputs": {
              "packages": [
                "github.com/ifx-run/ifx/go-sdk",
                "@ifx-run/sdk",
                "ifx-sdk"
              ],
              "dependents": null,
              "ecosystems": "crates, go, npm",
              "total_downloads": 64,
              "monthly_downloads": 303
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "303 downloads/month across crates, go, npm",
                "points": 33.1,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 303,
                      "ecosystems": "crates, go, npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 34,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 13,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "critical",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution, PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution",
                    "pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "merged_prs": 0,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "no decided pull requests or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_decided_prs_or_data",
                    "params": {}
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 38,
            "inputs": {
              "followers": 1,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "ifx-run",
              "public_repos": 4,
              "account_age_days": 52
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "1 followers of ifx-run",
                "points": 2.2,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 1,
                      "login": "ifx-run"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "4 public repos, account ~0 yr old",
                "points": 5.4,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 4
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/ifx-run/ifx/go-sdk",
                "@ifx-run/sdk",
                "ifx-sdk"
              ],
              "ecosystems": "crates, go, npm",
              "any_deprecated": false,
              "min_days_since_publish": 8
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "3 package(s) on crates, go, npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 3,
                      "ecosystems": "crates, go, npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 8 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 8
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "6 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 6
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 66,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 60,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "1 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 44,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests, Packaging, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests",
                    "packaging",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 30,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 15,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 3,
              "scorecard_aggregate": 3
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 3",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "42 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:@ifx-run/sdk@0.1.2 runtime dependency closure — what installing the published package pulls in — 1 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:@ifx-run/sdk@0.1.2",
                  "assessed": 1
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 0,
              "affected_packages": 0,
              "assessed_packages": 1,
              "unassessed_packages": 0,
              "affected_by_severity": "none",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "no indirect dependency carries a known advisory",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "no_indirect_advisories",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 1,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 74,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.98,
              "agent_instruction_files": [
                "AGENTS.md"
              ],
              "agent_instruction_max_bytes": 985
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "AGENTS.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "AGENTS.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "49 of 50 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 49,
                      "sampled": 50
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 69,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "Cargo.lock",
                "go.sum",
                "package-lock.json"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "sdk/tsconfig.json",
                "tsconfig.json"
              ],
              "agent_commit_share": 0.98,
              "toolchain_manifests": [
                "Cargo.toml",
                "crates/ifx-core/Cargo.toml",
                "go-sdk/go.mod",
                "programs/ifx/Cargo.toml",
                "rust-sdk/Cargo.toml"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Cargo.toml, crates/ifx-core/Cargo.toml, go-sdk/go.mod (toolchain convention, no task runner)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "toolchain_convention",
                    "params": {
                      "files": "Cargo.toml, crates/ifx-core/Cargo.toml, go-sdk/go.mod"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "sdk/tsconfig.json, tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "sdk/tsconfig.json, tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "49 of the last 50 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 49,
                      "sampled": 50
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 50691,
              "source_files_sampled": 275,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/275 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 275,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-26T23:59:09.486320Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/i/ifx-run/ifx.svg",
  "full_name": "ifx-run/ifx",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsGo, npm, crates.io.