Public record
Software health reportschema 0.27.0 · metrics 1.13.0 · 2026-07-25 12:24 UTC

johnmarktaylor91 / torchlens

Capture every activation and gradient of any PyTorch model — forward and backward — with automatic graph visualization, rich metadata, and live interventions. Works on any architecture, including dynamic and recurrent ones.

PythonApache-2.0★ 649 stars⑂ 29 forkssince Oct 2022View on GitHub ↗

johnmarktaylor91/torchlens holds a health index of 66 out of 100, placing it in the Moderate band. It scores highest on Engineering Quality (85/100) and lowest on Security (44/100). It was last updated today. A single contributor accounts for most of its recent work.

66
overall / 100
Moderate

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

66
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

JohnMark TaylorPersonal account
28 followers12 public repossince Jan 2016Columbia University

This repository is owned by a personal account. A single-owner project carries more continuity risk than an organization-backed one.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publishTags
PyPItorchlens2.32.12,6891480 days agotorchtorchlensactivationsfeaturesio

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

83Good · 22% of overall
How it's scored
36/36Push recency — last push 0 days ago
13.8/36Commit cadence — 20/52 weeks with commits
18/18Commit volume — 2,476 commits in the last year
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year2,476
human_commit_share0.99
days_since_last_push0
active_weeks_last_year20
How it's scored
27/27Ships releases — 100 releases published
36/36Release recency — latest release 0 days ago
27/27Release cadence — a release every ~4.2 days
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Inputs used
releases_count100
latest_release_tagv2.32.1
releases_from_tagsno
days_since_latest_release0
mean_days_between_releases4.2

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

56Moderate · 18% of overall
How it's scored
45.6/60Stars — 649 stars
12.1/25Forks — 29 forks
3.3/15Watchers — 5 watchers
Inputs used
forks29
stars649
watchers5
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (Apache-2.0)
0/18CONTRIBUTING guide
0/13.5Code of conduct
0/7.2Issue template
0/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingno
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno
How it's scored
45.7/80Monthly downloads — 2,689 downloads/month across pypi
0/20Registry dependents — not reported by this ecosystem
Inputs used
packagestorchlens
dependents
ecosystemspypi
total_downloads
monthly_downloads2,689
Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

56Moderate · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
0/22.5Commit distribution — top contributor authored 100% of commits
2.7/13.5Contributor breadth — 2 contributors
3/10OpenSSF Scorecard: Contributors — project has 1 contributing companies or organizations -- score normalized to 3
Inputs used
bus_factor1
contributors_sampled2
top_contributor_share0.999
How it's scored
42.1/46.8Issue resolution — 90% of issues closed
34.5/38.3PR acceptance — 121/134 decided PRs merged
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Inputs used
merged_prs121
open_issues4
closed_issues36
issue_closed_ratio0.9
closed_unmerged_prs13
How it's scored
10/30Ownership backing — personal (user) account
0/20Verified domain — not applicable to user accounts
10.5/25Owner reach — 28 followers of johnmarktaylor91
20.1/25Track record — 12 public repos, account ~10 yr old
Inputs used
followers28
owner_typeUser
is_verified
owner_loginjohnmarktaylor91
public_repos12
account_age_days3,853
Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.
How it's scored
25/25Published & resolvable — 1 package(s) on pypi
35/35Publish recency — latest publish 0 days ago
20/20Version history — 148 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packagestorchlens
ecosystemspypi
any_deprecatedno
min_days_since_publish0

Engineering Quality

Are baseline engineering and documentation practices in place?

85Excellent · 20% of overall
How it's scored
24/24CI workflows — 6 workflow(s)
24/24Tests present
16/16Linter config
9.6/9.6Pre-commit hooks
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — no data
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configyes
has_precommit_configyes
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.
How it's scored
30/30README
25/25Documentation directory
0/15Documentation / homepage site
10/10Repository description
0/10Topics
10/10Wiki
Inputs used
topics
has_wikiyes
homepage
has_readmeyes
has_docs_diryes
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

44At risk · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
3.8/7.5Branch-Protection — branch protection is not maximal on development and all release branches
0/2.5CI-Tests — no data
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0.8/2.5Contributors — project has 1 contributing companies or organizations -- score normalized to 3
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — no SAST tool detected
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate4.3
Excluded from scoring (no data or not applicable): ci_tests. Remaining weights renormalized.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

53Moderate · 0% of overall
How it's scored
45/45Agent instructions — .github/AGENTS.md, AGENTS.md, CLAUDE.md, notebooks/audit/CLAUDE.md, notebooks/audit/visual/CLAUDE.md, scripts/AGENTS.md, tests/AGENTS.md, torchlens/AGENTS.md, torchlens/CLAUDE.md, torchlens/backends/AGENTS.md, torchlens/backends/torch/AGENTS.md, torchlens/capture/AGENTS.md, torchlens/capture/CLAUDE.md, torchlens/data_classes/AGENTS.md, torchlens/data_classes/CLAUDE.md, torchlens/fastlog/CLAUDE.md, torchlens/intervention/CLAUDE.md, torchlens/postprocess/AGENTS.md, torchlens/postprocess/CLAUDE.md, torchlens/utils/AGENTS.md, torchlens/validation/AGENTS.md, torchlens/validation/CLAUDE.md, torchlens/visualization/AGENTS.md, torchlens/visualization/CLAUDE.md
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 85 of 99 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share0.859
agent_instruction_files.github/AGENTS.md, AGENTS.md, CLAUDE.md, notebooks/audit/CLAUDE.md, notebooks/audit/visual/CLAUDE.md, scripts/AGENTS.md, tests/AGENTS.md, torchlens/AGENTS.md, torchlens/CLAUDE.md, torchlens/backends/AGENTS.md, torchlens/backends/torch/AGENTS.md, torchlens/capture/AGENTS.md, torchlens/capture/CLAUDE.md, torchlens/data_classes/AGENTS.md, torchlens/data_classes/CLAUDE.md, torchlens/fastlog/CLAUDE.md, torchlens/intervention/CLAUDE.md, torchlens/postprocess/AGENTS.md, torchlens/postprocess/CLAUDE.md, torchlens/utils/AGENTS.md, torchlens/validation/AGENTS.md, torchlens/validation/CLAUDE.md, torchlens/visualization/AGENTS.md, torchlens/visualization/CLAUDE.md
agent_instruction_max_bytes26,150
How it's scored
0/18One-command bootstrap
22/22Automated tests
11/11Lint / format config
0/11Static type checking
0/10Reproducible environment
0/10Demonstrated agent practice — no agent-authored commits among the last 100
0/8Automated maintenance — no automated dependency updates observed
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Inputs used
has_nixno
has_testsyes
lockfiles
has_dockerfileno
typed_languageno
bootstrap_files
has_devcontainerno
has_linter_configyes
typecheck_configs
agent_commit_share0
toolchain_manifests
dependency_bot_commit_share0
How it's scored
0/45Type-checkable code — Python without a type-check config
53.5/55Manageable file sizes — 104/3,710 source files over 60KB
Inputs used
primary_languagePython
largest_source_bytes291,802
source_files_sampled3,710
oversized_source_files104
How it's scored
0/40API schema (OpenAPI/GraphQL/proto)
0/20MCP server
40/40Runnable examples — demos, examples, notebooks, recipes
Inputs used
example_dirsdemos, examples, notebooks, recipes
has_mcp_signalno
api_schema_files

Key facts

649GitHub stars
2contributors
2,476commits, last 12 months
0days since last push
100releases
1bus factor
4open issues
PyPIpackage ecosystems

Data collection warnings

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • deps.dev does not index pypi:torchlens@2.32.1; advisories assessed against the repository dependency graph instead
  • No resolved dependencies carried a version and a supported ecosystem

More detail

Star and fork history 0 ★ / 29 ⇿
0Stars
29Forks
99Releases

When each star and fork was added, collected from GitHub and bucketed by day. Cumulative growth sits directly above the daily additions it is made of, so the two read against each other: steady organic accretion looks nothing like an abrupt, short-lived burst. Where that difference is measurable, it is reported as growth authenticity.

0510152025302922022-122024-092026-07
Major 2Minor 52Patch 45

Each point covers 4 days.

OpenSSF Scorecard 4.3 / 10
4.3aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-25 12:24 UTC

10Binary-Artifactsno binaries found in the repo
5Branch-Protectionbranch protection is not maximal on development and all release branches
n/aCI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
3Contributorsproject has 1 contributing companies or organizations -- score normalized to 3
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTno SAST tool detected
0Security-Policysecurity policy file not detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
10Vulnerabilities0 existing vulnerabilities detected
Direct dependencies 8
RegistryPackageVersion constraintManifest
PyPInumpypyproject.toml
PyPIpackagingpyproject.toml
PyPItorch>=2.1pyproject.toml
PyPIsafetensors>=0.4pyproject.toml
PyPItqdmpyproject.toml
PyPIgraphvizpyproject.toml
PyPItyping_extensions>=4.0pyproject.toml
PyPIpillow>=9pyproject.toml
All dependencies 35

Full resolved dependency set from the GitHub dependency graph: 4 direct and 31 indirect (transitive) packages. The transitive closure is complete when the repository commits a lockfile.

RegistryPackageVersionRelation
PyPIpillowdirect
PyPIsafetensorsdirect
PyPItorchdirect
PyPItyping-extensionsdirect
PyPIbrain-scoreindirect
PyPIcaptumindirect
PyPIdepyfindirect
PyPIdialzindirect
PyPIinseqindirect
PyPIipythonindirect
PyPIjupyter-clientindirect
PyPIlightningindirect
PyPIlit-nlpindirect
PyPIlovely-tensorsindirect
PyPImlxindirect
PyPInnsightindirect
PyPIpaddlepaddleindirect
PyPIpandasindirect
PyPIpyarrowindirect
PyPIpytorch-grad-camindirect
PyPIrepengindirect
PyPIrsatoolboxindirect
PyPIsae-lensindirect
PyPIsentence-transformersindirect
PyPIsetuptoolsindirect
PyPIshapindirect
PyPIsteering-vectorsindirect
PyPItensorflowindirect
PyPItimmindirect
PyPItinygradindirect
PyPItorchextractorindirect
PyPItorchshowindirect
PyPItorchvisionindirect
PyPItransformersindirect
PyPIwandbindirect
Dependency advisories not assessed

Advisory matching could not run for this report: No resolved dependencies carried a version and a supported ecosystem

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 58658,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "Python": 52151754,
        "Jupyter Notebook": 588904
      },
      "pushed_at": "2026-07-25T12:22:48Z",
      "created_at": "2022-10-14T01:24:55Z",
      "owner_type": "User",
      "updated_at": "2026-07-25T12:23:10Z",
      "description": "Capture every activation and gradient of any PyTorch model — forward and backward — with automatic graph visualization, rich metadata, and live interventions. Works on any architecture,  including dynamic and recurrent ones.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Python",
      "significant_languages": [
        "Python"
      ]
    },
    "owner": {
      "blog": "johnmarktaylor.com",
      "name": "JohnMark Taylor",
      "type": "User",
      "login": "johnmarktaylor91",
      "company": "Columbia University",
      "location": "New York, NY",
      "followers": 28,
      "avatar_url": "https://avatars.githubusercontent.com/u/16569815?v=4",
      "created_at": "2016-01-06T03:49:14Z",
      "is_verified": null,
      "public_repos": 12,
      "account_age_days": 3853
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v2.32.1",
          "kind": "patch",
          "published_at": "2026-07-25T12:22:49Z"
        },
        {
          "tag": "v2.31.0",
          "kind": "minor",
          "published_at": "2026-07-10T17:17:52Z"
        },
        {
          "tag": "v2.30.1",
          "kind": "patch",
          "published_at": "2026-07-09T14:51:20Z"
        },
        {
          "tag": "v2.30.0",
          "kind": "minor",
          "published_at": "2026-07-09T13:47:40Z"
        },
        {
          "tag": "v2.29.1",
          "kind": "patch",
          "published_at": "2026-07-09T01:57:43Z"
        },
        {
          "tag": "v2.28.0",
          "kind": "minor",
          "published_at": "2026-06-24T18:22:18Z"
        },
        {
          "tag": "v2.27.0",
          "kind": "minor",
          "published_at": "2026-06-22T14:15:51Z"
        },
        {
          "tag": "v2.26.0",
          "kind": "minor",
          "published_at": "2026-06-17T21:26:20Z"
        },
        {
          "tag": "v2.25.0",
          "kind": "minor",
          "published_at": "2026-06-17T18:56:22Z"
        },
        {
          "tag": "v2.24.1",
          "kind": "patch",
          "published_at": "2026-06-17T16:44:25Z"
        },
        {
          "tag": "v2.24.0",
          "kind": "minor",
          "published_at": "2026-06-17T15:12:01Z"
        },
        {
          "tag": "v2.23.0",
          "kind": "minor",
          "published_at": "2026-06-17T00:37:32Z"
        },
        {
          "tag": "v2.22.0",
          "kind": "minor",
          "published_at": "2026-06-16T20:53:24Z"
        },
        {
          "tag": "v2.21.2",
          "kind": "patch",
          "published_at": "2026-06-16T17:14:12Z"
        },
        {
          "tag": "v2.21.1",
          "kind": "patch",
          "published_at": "2026-06-16T16:50:14Z"
        },
        {
          "tag": "v2.21.0",
          "kind": "minor",
          "published_at": "2026-06-16T15:13:59Z"
        },
        {
          "tag": "v2.20.3",
          "kind": "patch",
          "published_at": "2026-06-16T02:28:25Z"
        },
        {
          "tag": "v2.20.2",
          "kind": "patch",
          "published_at": "2026-06-16T02:16:48Z"
        },
        {
          "tag": "v2.20.1",
          "kind": "patch",
          "published_at": "2026-06-16T02:11:34Z"
        },
        {
          "tag": "v2.20.0",
          "kind": "minor",
          "published_at": "2026-06-16T02:05:33Z"
        },
        {
          "tag": "v2.19.0",
          "kind": "minor",
          "published_at": "2026-06-13T06:33:53Z"
        },
        {
          "tag": "v2.18.0",
          "kind": "minor",
          "published_at": "2026-05-29T18:10:04Z"
        },
        {
          "tag": "v2.17.0",
          "kind": "minor",
          "published_at": "2026-05-01T17:38:06Z"
        },
        {
          "tag": "v2.16.0",
          "kind": "minor",
          "published_at": "2026-04-30T11:56:31Z"
        },
        {
          "tag": "v2.15.0",
          "kind": "minor",
          "published_at": "2026-04-27T22:58:59Z"
        },
        {
          "tag": "v2.14.0",
          "kind": "minor",
          "published_at": "2026-04-27T21:32:53Z"
        },
        {
          "tag": "v2.13.0",
          "kind": "minor",
          "published_at": "2026-04-27T20:30:56Z"
        },
        {
          "tag": "v2.12.2",
          "kind": "patch",
          "published_at": "2026-04-27T20:05:33Z"
        },
        {
          "tag": "v2.12.1",
          "kind": "patch",
          "published_at": "2026-04-27T19:44:10Z"
        },
        {
          "tag": "v2.12.0",
          "kind": "minor",
          "published_at": "2026-04-27T19:10:03Z"
        },
        {
          "tag": "v2.11.0",
          "kind": "minor",
          "published_at": "2026-04-27T18:14:57Z"
        },
        {
          "tag": "v2.10.0",
          "kind": "minor",
          "published_at": "2026-04-27T17:49:10Z"
        },
        {
          "tag": "v2.9.0",
          "kind": "minor",
          "published_at": "2026-04-27T17:15:51Z"
        },
        {
          "tag": "v2.8.0",
          "kind": "minor",
          "published_at": "2026-04-27T16:59:43Z"
        },
        {
          "tag": "v2.7.0",
          "kind": "minor",
          "published_at": "2026-04-27T16:45:19Z"
        },
        {
          "tag": "v2.6.0",
          "kind": "minor",
          "published_at": "2026-04-27T14:41:10Z"
        },
        {
          "tag": "v2.5.0",
          "kind": "minor",
          "published_at": "2026-04-27T14:37:41Z"
        },
        {
          "tag": "v2.4.0",
          "kind": "minor",
          "published_at": "2026-04-27T07:45:51Z"
        },
        {
          "tag": "v2.3.1",
          "kind": "patch",
          "published_at": "2026-04-27T05:30:13Z"
        },
        {
          "tag": "v2.3.0",
          "kind": "minor",
          "published_at": "2026-04-27T05:20:40Z"
        },
        {
          "tag": "v2.2.1",
          "kind": "patch",
          "published_at": "2026-04-25T17:04:38Z"
        },
        {
          "tag": "v2.2.0",
          "kind": "minor",
          "published_at": "2026-04-25T15:41:18Z"
        },
        {
          "tag": "v2.1.0",
          "kind": "minor",
          "published_at": "2026-04-25T15:40:36Z"
        },
        {
          "tag": "v2.0.0",
          "kind": "major",
          "published_at": "2026-04-25T15:30:02Z"
        },
        {
          "tag": "v1.7.0",
          "kind": "minor",
          "published_at": "2026-04-24T22:20:26Z"
        },
        {
          "tag": "v1.6.0",
          "kind": "minor",
          "published_at": "2026-04-24T22:10:53Z"
        },
        {
          "tag": "v1.5.0",
          "kind": "minor",
          "published_at": "2026-04-24T22:02:02Z"
        },
        {
          "tag": "v1.4.0",
          "kind": "minor",
          "published_at": "2026-04-24T21:52:00Z"
        },
        {
          "tag": "v1.3.0",
          "kind": "minor",
          "published_at": "2026-04-24T03:15:44Z"
        },
        {
          "tag": "v1.2.0",
          "kind": "minor",
          "published_at": "2026-04-23T20:41:33Z"
        },
        {
          "tag": "v1.1.0",
          "kind": "minor",
          "published_at": "2026-04-22T23:28:14Z"
        },
        {
          "tag": "v1.0.2",
          "kind": "patch",
          "published_at": "2026-04-05T16:15:34Z"
        },
        {
          "tag": "v1.0.1",
          "kind": "patch",
          "published_at": "2026-03-23T01:31:38Z"
        },
        {
          "tag": "v1.0.0",
          "kind": "major",
          "published_at": "2026-03-13T22:06:26Z"
        },
        {
          "tag": "v0.22.0",
          "kind": "minor",
          "published_at": "2026-03-13T20:13:26Z"
        },
        {
          "tag": "v0.21.3",
          "kind": "patch",
          "published_at": "2026-03-11T23:34:20Z"
        },
        {
          "tag": "v0.21.2",
          "kind": "patch",
          "published_at": "2026-03-09T17:53:27Z"
        },
        {
          "tag": "v0.21.1",
          "kind": "patch",
          "published_at": "2026-03-09T15:04:08Z"
        },
        {
          "tag": "v0.21.0",
          "kind": "minor",
          "published_at": "2026-03-09T12:04:33Z"
        },
        {
          "tag": "v0.20.5",
          "kind": "patch",
          "published_at": "2026-03-09T02:49:14Z"
        },
        {
          "tag": "v0.20.4",
          "kind": "patch",
          "published_at": "2026-03-09T01:03:14Z"
        },
        {
          "tag": "v0.20.3",
          "kind": "patch",
          "published_at": "2026-03-08T23:49:07Z"
        },
        {
          "tag": "v0.20.2",
          "kind": "patch",
          "published_at": "2026-03-08T20:26:07Z"
        },
        {
          "tag": "v0.20.1",
          "kind": "patch",
          "published_at": "2026-03-08T19:42:57Z"
        },
        {
          "tag": "v0.20.0",
          "kind": "minor",
          "published_at": "2026-03-08T19:01:49Z"
        },
        {
          "tag": "v0.19.0",
          "kind": "minor",
          "published_at": "2026-03-08T18:41:14Z"
        },
        {
          "tag": "v0.18.0",
          "kind": "minor",
          "published_at": "2026-03-08T15:00:34Z"
        },
        {
          "tag": "v0.17.0",
          "kind": "minor",
          "published_at": "2026-03-08T13:55:50Z"
        },
        {
          "tag": "v0.16.4",
          "kind": "patch",
          "published_at": "2026-03-08T01:55:56Z"
        },
        {
          "tag": "v0.16.3",
          "kind": "patch",
          "published_at": "2026-03-08T00:29:34Z"
        },
        {
          "tag": "v0.16.2",
          "kind": "patch",
          "published_at": "2026-03-08T00:02:51Z"
        },
        {
          "tag": "v0.16.1",
          "kind": "patch",
          "published_at": "2026-03-07T22:00:23Z"
        },
        {
          "tag": "v0.16.0",
          "kind": "minor",
          "published_at": "2026-03-07T19:59:15Z"
        },
        {
          "tag": "v0.15.15",
          "kind": "patch",
          "published_at": "2026-03-07T04:55:23Z"
        },
        {
          "tag": "v0.15.14",
          "kind": "patch",
          "published_at": "2026-03-07T02:02:45Z"
        },
        {
          "tag": "v0.15.13",
          "kind": "patch",
          "published_at": "2026-03-07T01:28:15Z"
        },
        {
          "tag": "v0.15.12",
          "kind": "patch",
          "published_at": "2026-03-06T23:49:54Z"
        },
        {
          "tag": "v0.15.11",
          "kind": "patch",
          "published_at": "2026-03-06T05:48:57Z"
        },
        {
          "tag": "v0.15.10",
          "kind": "patch",
          "published_at": "2026-03-05T20:40:13Z"
        },
        {
          "tag": "v0.15.9",
          "kind": "patch",
          "published_at": "2026-03-05T14:03:24Z"
        },
        {
          "tag": "v0.15.8",
          "kind": "patch",
          "published_at": "2026-03-05T01:12:09Z"
        },
        {
          "tag": "v0.15.7",
          "kind": "patch",
          "published_at": "2026-03-04T23:59:40Z"
        },
        {
          "tag": "v0.15.6",
          "kind": "patch",
          "published_at": "2026-03-04T22:32:02Z"
        },
        {
          "tag": "v0.15.5",
          "kind": "patch",
          "published_at": "2026-03-04T20:45:36Z"
        },
        {
          "tag": "v0.15.4",
          "kind": "patch",
          "published_at": "2026-03-04T17:18:50Z"
        },
        {
          "tag": "v0.15.3",
          "kind": "patch",
          "published_at": "2026-03-04T15:33:08Z"
        },
        {
          "tag": "v0.15.2",
          "kind": "patch",
          "published_at": "2026-03-04T15:18:04Z"
        },
        {
          "tag": "v0.15.1",
          "kind": "patch",
          "published_at": "2026-03-04T14:43:03Z"
        },
        {
          "tag": "v0.15.0",
          "kind": "minor",
          "published_at": "2026-03-04T09:59:23Z"
        },
        {
          "tag": "v0.14.0",
          "kind": "minor",
          "published_at": "2026-03-04T01:59:10Z"
        },
        {
          "tag": "v0.13.1",
          "kind": "patch",
          "published_at": "2026-03-03T23:02:27Z"
        },
        {
          "tag": "v0.13.0",
          "kind": "minor",
          "published_at": "2026-03-03T16:44:38Z"
        },
        {
          "tag": "v0.12.0",
          "kind": "minor",
          "published_at": "2026-03-02T19:00:13Z"
        },
        {
          "tag": "v0.11.2",
          "kind": "patch",
          "published_at": "2026-03-02T18:22:14Z"
        },
        {
          "tag": "v0.11.1",
          "kind": "patch",
          "published_at": "2026-03-02T17:40:00Z"
        },
        {
          "tag": "v0.11.0",
          "kind": "minor",
          "published_at": "2026-03-02T15:54:24Z"
        },
        {
          "tag": "v0.10.1",
          "kind": "patch",
          "published_at": "2026-03-02T12:58:48Z"
        },
        {
          "tag": "v0.10.0",
          "kind": "minor",
          "published_at": "2026-03-02T01:04:25Z"
        },
        {
          "tag": "v0.9.0",
          "kind": "minor",
          "published_at": "2026-03-01T22:00:01Z"
        },
        {
          "tag": "v0.8.0",
          "kind": "minor",
          "published_at": "2026-03-01T20:32:12Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "3675dc20af58c6c1015f9640040adf968deba4b5",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): 2.32.1 [skip ci]",
          "author_name": "semantic-release",
          "author_login": null,
          "committed_at": "2026-07-25T12:22:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3193cf88d2b24b2a6a5d4d883810d1832c36a0c5",
          "body": null,
          "is_bot": true,
          "headline": "style: auto-format with ruff",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-25T12:20:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3aa8e9281aad1144e00290a76c7007ee3b896ab4",
          "body": "… pin ruff, CVE ignore)\n\nThe 2.32.0 push went green locally but red across CI's version matrix + whole-repo\nlint (my pre-push gate was single-env torch2.8/py3.11 + `ruff check torchlens/`).\nFixes:\n- capture/session.py: CaptureSession used @dataclass(slots=True, weakref_slot=True);\n  weakref_slot is \n[…]\nisting CVE-2026-3219 ignore).\n\nLocal verify (torch2.8/py3.11): mypy 366 files, ruff whole-repo clean, tlspec immunizers\nr83/r85/r87 66/0, pydot test passes. semantic-release will re-release as 2.32.1.",
          "is_bot": false,
          "headline": "fix: unblock 2.32.0 release CI (py3.10/torch-2.1 compat, pydot guard,…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-25T12:19:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bf16212f33629cf128e2f011950013a4ed81b7d4",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): 2.32.0 [skip ci]",
          "author_name": "semantic-release",
          "author_login": null,
          "committed_at": "2026-07-25T11:48:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7ea2b66e8e9275f34cb6149a9af8c9c09e8d658d",
          "body": "…/projective-field caches (assembled-main lockstep)\n\nThe rf/receptive-field merge added two DROP-policy cache fields\n(_receptive_field_cache, _projective_field_cache) to the Trace field surface,\nwhich the field-order/dataframe projection enumerates -> test_field_order_and_\ndataframe_golden went stal\n[…]\nioned TORCHLENS_UPDATE_BACKEND_\nPARITY flag. Caught by the capture-tripwire (this golden is not-slow-tier; added\nto the tripwire in r85 precisely so merge-time field-catalog drift can't slip through).",
          "is_bot": false,
          "headline": "test(runnable): regen field-order/dataframe golden for rf's receptive…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-25T05:55:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3f658c90567c887037b11ae2a97df33715d87c42",
          "body": "…for .tlspec (secA S1 privacy)\n\nsecA's r82 finding: a shipped .tlspec embedded the model's verbatim source, plus\nabsolute $HOME/username/site-packages paths and the capturing script filename, at\nevery save level with no opt-out -- a producer-side privacy exposure for the\nshareable format.\n\nFix (Opti\n[…]\npec immunizers r71..r87 195/0, smoke 1954/0. New\ntests in test_code_panel.py (opt-out has no source/$HOME/username bytes; default\nround-trips + renders; stripped artifact visualizes without crashing).",
          "is_bot": false,
          "headline": "Merge S1: include_source opt-out + unconditional path relativization …",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-25T04:31:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a5975fe2cba63255817e8dabcb90f00dc0495750",
          "body": "…lways relativize source paths\n\nA shipped .tlspec (the portable, shareable format) embedded the model's\nverbatim source code (whole class body, docstrings, class constants,\nper-call code_context source lines) plus absolute host paths ($HOME,\nsite-packages, capturing-script filename) and the OS usern\n[…]\nTest: opt-out artifact bytes carry no source text / $HOME / username;\n  default save relativizes paths yet round-trips + renders a source panel;\n  source-stripped artifact visualizes without crashing.",
          "is_bot": false,
          "headline": "feat(io): add include_source opt-out for .tlspec source embedding + a…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-25T04:15:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "acb39b96ba453b1b631a8493b42fb011ff7d8cf6",
          "body": "…OP field (field-order-contract lockstep)\n\ntest_field_order_drop_policy_fields_are_documented flags any FIELD_ORDER field\nmarked DROP/WEAKREF_STRIP that isn't in the case's documented set. The hardening\nsprint added _runnable_capture_state (FieldPolicy.DROP -- runnable capture-scratch,\ncorrectly non-portable) without registering it here. Exactly one field was\nundocumented (verified programmatically: 1 to add, 0 to remove); the ~52-field\ndrift the r81 note feared was already reconciled.",
          "is_bot": false,
          "headline": "test(runnable): document _runnable_capture_state as an intentional DR…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-25T03:51:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2440bc09a0414826fd426e21c31d3ba32ff59eda",
          "body": "…r renderer\n\nThe viz-refactor branch changed the renderer (_render_dot.py/render_ir.py @941cd395\nJul 11) AFTER last regenerating the S5 manifest (12797edc Jul 7), so\ntest_s5_render_dot_and_plan_hashes_match_manifest was stale + red on the branch\nitself (pre-merge) -- not a merge regression. Regenera\n[…]\nrally valid graphs dot_len>100; renderer independently\nverified by the 148 other viz tests incl. the render-identity oracle). Updated\n.secrets.baseline for the new (false-positive) hex content-hashes.",
          "is_bot": false,
          "headline": "test(viz): regen S5 render-identity golden for the merged viz-refacto…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-25T03:47:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "68f0e6cb1077349df96cd7a3e2a1c2e9f5e3fd13",
          "body": "… (tl.receptive_field, op.receptive_field, N-D, viz)",
          "is_bot": false,
          "headline": "Merge rf/receptive-field: receptive-field / projective-field analysis…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-25T03:26:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0b9c61a2181117be599e793cada64784c3946e6f",
          "body": "…equest / renderers split)",
          "is_bot": false,
          "headline": "Merge viz-refactor: visualization renderer refactor (source_graph / r…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-25T02:58:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6990b6114619f7172ac2fbe236ea23b05df31634",
          "body": "…s -- close the last verdict-neutral MED (r86 free FINDING-1 residual)\n\nr86's convergence wave found the runnable-.tlspec faithfulness contract at\nstrict-zero from both labs (zero false-VERIFIED/ATTESTED, zero honest\nover-trigger, the state-provenance matrix closed with no fifth cell). The one\nremai\n[…]\n golden+option-honesty), smoke 1946/0. C2 + r85\nimmunizers green; verdicts + replay fingerprints byte-unchanged. This reaches\nLITERAL strict-zero from both labs on the sparse runnable-.tlspec surface.",
          "is_bot": false,
          "headline": "Merge r87: registered-buffer write-side node keeps its backend_addres…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-25T02:56:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b22041b2be94aad4d655ec05fd2e637976bcd6e3",
          "body": "…dress (r87, closes free FINDING-1 residual)",
          "is_bot": false,
          "headline": "fix(runnable): registered-buffer write-side node keeps its backend_ad…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-25T01:56:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c72282fd8873f689918d5fbc7978a1189d3eb4ac",
          "body": "…ovenance storage column (r84 SOL-1)\n\nr84's confirming wave found the fourth and final cell of the state-provenance\nmatrix {buffer, activation/label} x {identity, storage}: a state-derived\nactivation (self.b * 1.0) whose storage is .data-rebound to input-derived data\nmid-forward replayed as VERIFIED\n[…]\ne contention (r35 lesson) -- its one\nunique signal, the field-order golden, is now in the tripwire and green. SOL-1\nconfirmed refusing at save. Zero-collateral: honest storage mutation stays VERIFIED.",
          "is_bot": false,
          "headline": "Merge r85: unified storage-integrity belt -- close the whole state-pr…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-25T01:05:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8fc7a3b2a4de193fc834cee6af3e155b4615dfee",
          "body": "…cords (r85 lockstep)\n\nr83's C3 (ef0c5b58) registered _pending_live_fire_records in PORTABLE_STATE_SPEC\n(the cache=True re-capture save fix) but did not regenerate the field-order\ngolden, leaving test_field_order_and_dataframe_golden red on main -- missed by\nr83's smoke+tripwire gate because this golden is in the not-slow tier only. The\nsole content delta is the one legitimate new portable field; zero backend_address\nor storage-belt contribution. Sanctioned update-flag regeneration.",
          "is_bot": false,
          "headline": "fix(runnable): regen field-order golden for r83 _pending_live_fire_re…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-24T23:31:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "37d42c3a79ee3bc0ddc31b27a742d44245fc836c",
          "body": "…grity belt\n\nRecord the r85 closure in the frozen contract, alongside the r81 buffer-storage\nbelt it mirrors:\n- Section 4 (witness state-attribution rungs): the label_raw / buffer_source\n  components now carry the storage-integrity belt as well as the r83 identity\n  belt -- the same set_tensor_label\n[…]\nhicle from a zero-copy byte write; the label-rung belt\n  witnesses it. The sharp line (in-place own-storage write stays verified; only a\n  pointer-swapping rebind ceils) is stated in all three places.",
          "is_bot": false,
          "headline": "docs(runnable): contract lockstep for the r85 label-rung storage-inte…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-24T23:27:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3812d0fbae396deea9e0f67898875b041862f5c3",
          "body": "…dress, only buffers decouple (r85)\n\nfree FINDING-1 (MED): r83's dee9d679 set the registered-only backend_address\noverride UNCONDITIONALLY in _fields_from_event, forcing EVERY op/activation node\nto None -- contradicting its own commit message (\"an op/input ... is unaffected\")\n-- and left the model-o\n[…]\nC2 buffer-authority immunizer is intact.\n\nCorrects the false 'popped for EVERY record' claim in the materialize comment.\nKeeps the C2 address-authority fix and immunizer intact (refines, not reverts).",
          "is_bot": false,
          "headline": "fix(runnable): backend_address decoupling -- op nodes keep coupled ad…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-24T23:24:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0562971c1768398b6f8b87628d185adeb7504ab8",
          "body": "…ery storage-rebind sibling (r85)\n\nThe r85 storage belt is a single mechanism at the shared label choke points, so\nno per-vehicle code is needed to close the rest of the storage column. Pins,\nproving the belt subsumes every sibling free/Sol flagged:\n\n- param-derived activation .data= rebind -> save \n[…]\norrectly passes it) and is caught instead by the r73/r75 layout net\n(PathDivergenceError on a channels_last twin, same-layout control VERIFIED),\nconfirming the belt and layout net compose with no gap.",
          "is_bot": false,
          "headline": "fix(runnable): column-completeness immunizers -- one belt subsumes ev…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-24T23:14:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9ab8c3a46433c54926209e47715697a91313fb73",
          "body": "…bound storage (r85)\n\nClose SOL-1 (r84 HIGH): a state-derived activation (self.b * 1.0) whose storage\nis .data=-rebound to input-derived data mid-forward kept its current-session\nlabel, re-bound as its same-named graph parent, and replayed the PRE-rebind\nvalue as a false VERIFIED on the SAME capture\n[…]\nstorage (tracked copy_, EMA mul_().add_(),\nbuf[:] = ...) keeps the pointer and stays VERIFIED. free's honest battery\n(ConvBN train/eval, num_batches_tracked, EMA, copy_-into-buffer) verdict-identical.",
          "is_bot": false,
          "headline": "fix(runnable): storage-integrity belt -- state receivers require unre…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-24T23:12:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "00987798c030b3815a4a7b50e1a6522aeb78a145",
          "body": "…collision class) + buffer-address authority + artifact-coherence closures\n\nr82's convergence wave found ONE root class broken independently by THREE labs\n(Sol, hon1, free): label provenance was validated by TEXT membership in the live\nevent index with no per-event object anchoring, so a tensor carr\n[…]\n's 59-case honest battery verdict-identical to main bar the one intended C2\nnested-mix refusal. secA S1 (source-embedding privacy) escalated to JMT, not\nincluded. All three r82 REDs confirmed ceiling.",
          "is_bot": false,
          "headline": "Merge r83: label-rung object anchoring (close the r82 cross-lab TEXT-…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-24T22:02:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2d3c66982ed1d4cae88ccb97669c68dc12f62a8c",
          "body": "…ver (r83)\n\nRegression: r83's C3 reconciled callable_registry vs the recorded op name at\nreadiness attach, BEFORE the resolver ran. For an UNRESOLVABLE tampered key\n(torch.definitely_absent) this fired first with context_field_invalid, so run()\nraised the coarse analysis-only RunCapabilityUnavailabl\n[…]\n (78 tests), the reg-2 test, and the S3 immunizer -- updated in lockstep to\nSEMANTIC_DRIFT plus a new pin that an unresolvable key keeps the ReattachError\npath -- are green. Contract updated to match.",
          "is_bot": false,
          "headline": "fix(runnable): relocate the S3 registry reconciliation into the resol…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-24T21:37:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dee9d6798cfd08db576d61a5fbff313e3a5c0283",
          "body": "…2 buffer fix (r83)\n\nRegression: r83's C2 (recorded buffer address is authoritative) leaked the\nrecorded address into the SEPARATE backend_address field for a plain-attribute\n(non-registered) buffer, where a current-format manifest previously left it None\n(test_current_bundle_preserves_none_backend_\n[…]\nEDs (matrix cases A/F, realistic normalizer, nested mix) all still refuse; the\n59-case honest battery is unchanged except the intended nested-mix refusal;\n467 immunizer+validation+unified tests green.",
          "is_bot": false,
          "headline": "fix(runnable): decouple display address from backend_address in the C…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-24T21:37:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c5e0db2981423b5956dca65c69029d2457264ab1",
          "body": "…ssion-inventory membership during capture (r83)",
          "is_bot": false,
          "headline": "test(runnable): strengthen root-A leak-vehicle immunizer -- assert se…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-24T20:42:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "705228e9ce02e50804d9d7430c0ff7f4e92fc6bb",
          "body": "… retention note (r83)\n\nCorrects a FALSE sentence r81 shipped. The contract claimed the ModuleType\ncleanup blind spot was closed by a shallow module-namespace sweep and that\n\"deeper stashes are harmless because the belt never trusts an unregistered\nstamp\". The parenthetical was false as written: the\n[…]\nng a FALSE identity match and re-opening the r80 F2\nlaunder. The note names the only safe reduction direction and requires\nre-deriving the F2 red first. Retention behaviour is unchanged in this round.",
          "is_bot": false,
          "headline": "docs(runnable): contract lockstep for the r83 closures + load-bearing…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-24T20:35:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ef0c5b581683acba35fd5c4a331f0ac0e07326ee",
          "body": "…egister the pending-live-fire field (r83)\n\nS3: the callable a loaded artifact EXECUTES comes from\nmanifest.json -> run.callable_registry[].key, while the SAME call is named\nindependently by manifest.json -> sites[].function_path and by\nmetadata.pkl -> layer_list[].func_name / .func_id.qualname. Not\n[…]\ndeferred.\n\nThe anchor runs on every runnable load: the 129 prior immunizers, the full\nvalidation tripwire suite and the r83 suites stay green (417 passed), and the\n59-case honest battery is unchanged.",
          "is_bot": false,
          "headline": "fix(runnable): artifact coherence -- registry/name reconciliation + r…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-24T20:34:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7cbc2be107b29bf69a405f0132e4960c737bc289",
          "body": "…e over the shape heuristic (r83)\n\nA shape heuristic in postprocess overrode the address the capture had correctly\nrecorded. _buffer_addresses_by_label discarded the recorded address whenever it\ndid not name an unassigned REGISTERED buffer, then re-derived one from\ntrace._buffer_initial_values (regi\n[…]\n their own dotted addresses in both train\nand eval, the BatchNorm running-stat and num_batches_tracked pre-assignments are\nuntouched, and the remaining 58 battery cases stay verdict-identical to main.",
          "is_bot": false,
          "headline": "fix(runnable): buffer address -- the recorded address is authoritativ…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-24T20:23:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "758d877fd2aceafb7157297b702fa10af154b005",
          "body": "…label stamps (r83)\n\nStale label stamps were cleared by REACHABILITY only, and the cleanup walk has\nstructural blind spots: it returns immediately for any nn.Module value outside\nthe traced tree (a helper module or nn.Sequential used as an activation cache)\nand for any object with no __dict__ (__slo\n[…]\nivation graph and defeat sparse save=. It names exactly\nthe stamped objects something outside TorchLens still holds -- the leak vehicles.\nVerdicts on the 59-case honest battery stay identical to main.",
          "is_bot": false,
          "headline": "fix(runnable): label-rung root A -- inventory-driven sweep of leaked …",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-24T20:03:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1e38bec6953e47dcb4c41035d54b1438d41f0316",
          "body": "…r raw labels (r83)\n\nLabel provenance was validated by TEXT membership in the active capture's live\nevent index, with no per-object anchoring. Label text is deterministic per\nop-kind + ordinal, so an ordinary op in a later, unrelated capture regenerates\nthe same string and a tensor still carrying a \n[…]\n train/eval, 3x repeat captures, three instances sharing one\nbuffer object, and the include_activations ATTESTED case), and the 129 prior\nimmunizers plus the full validation tripwire suite stay green.",
          "is_bot": false,
          "headline": "fix(runnable): label-rung belt -- current-session object anchoring fo…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-24T19:49:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b5db3f9541baf6f6e0720d43ae3b3ef63e1a7cde",
          "body": "…a static buffer stamp counts as provenance ONLY when the exact object was stamped in the ACTIVE session AND its live storage is still the storage pinned at stamp time (closes the r80 cross-capture ModuleType-stash stale-stamp leak and the single-capture plain-attr .data= input-layout launder, both false-VERIFIED at max-diff 20.0) + sprint field-catalog lockstep",
          "is_bot": false,
          "headline": "Merge r81: buffer-rung FULL PARITY with the param provenance rung -- …",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-24T18:43:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "619b907ac854f261399a000783e70e48d549125e",
          "body": "…er golden (r81 lockstep)\n\nThe r65-r81 hardening sprint added capture-scratch fields to Trace (host-RNG\nmonitor state, session param/buffer inventories, storage-address maps used by\nthe buffer-rung witness machinery) without registering them in the field\ncatalog. Register the 13 sprint fields in the\n[…]\nr_persistence into MODEL_LOG_FIELD_ORDER, and regenerate the\nfield-order/dataframe golden through its sanctioned update mechanism.\n\nCross-effort field-catalog drift outside this sprint stays deferred.",
          "is_bot": false,
          "headline": "fix(runnable): register r65-r81 sprint Trace fields + regen field-ord…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-24T18:43:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b36e60f56b15a5e429a6227b87b0773691fbdfec",
          "body": "… stamps in the witness state-attribution rungs close the plain-attr .data= input-layout launder into residual (3) (r81)",
          "is_bot": false,
          "headline": "fix(runnable): buffer-rung parity F2/belt -- session-validated buffer…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-23T04:08:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4a9cf4c8cf06d71d74598f865ac225606a37a0f7",
          "body": "…entry points + session identity registry with storage-pinned belt at the rung and all buffer-source logging gates + ModuleType cleanup sweep (r81)",
          "is_bot": false,
          "headline": "fix(runnable): buffer-rung parity F1 -- inventory both _record_write …",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-23T04:07:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "10975d98e8990f2abf85dadc8b7dff2f3daef20e",
          "body": "…tory-driven cleanup catches objects popped mid-forward + current-session object-identity gate in _build_param_fields, closing the layout-twin false-VERIFIED and the same-input wrong-bind) + seed-door bool/out-of-range rejection at all manual_seed sites + empty-name-param save-side canonical-label preflight",
          "is_bot": false,
          "headline": "Merge r79: close the r78 session-provenance-stamp leak (HIGH -- inven…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-23T02:54:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3eeaaa0b3bb003c55f8a0e8ed412c9372f74907d",
          "body": "…(r79)\n\nThe r79 session-leak fix threaded trace through _tag_untagged_buffers\n(model_prep.py); the production call site was updated but one existing unit\ntest still called the old single-arg signature:\ntests/test_tl_lifecycle.py::test_tag_untagged_buffers_promotes_prior_label_mid_session\n(TypeError \n[…]\ne_labels) across torchlens/\nand tests/ found NO other stale caller (remaining hits are production call\nsites already updated, or docstring mentions). Full smoke tier: 1884\npassed, 8 skipped, 0 failed.",
          "is_bot": false,
          "headline": "fix(runnable): update stale callers of r79 trace-threaded signatures …",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-23T02:42:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0e3bb8accc3b76a37722cd0c1db981b1d119f256",
          "body": "…ors the load door (r79)\n\nself._parameters[''] = nn.Parameter(...) bypasses register_parameter's\nempty-name validation, captured, and SAVED a runnable artifact whose weight\ntensor entry carried label '' -- which tl.load categorically refuses\n(TorchLensIOError: 'Runnable weight tensor entry 0 require\n[…]\ns round-trip VERIFIED; the weightless\nempty-name lane (no weight entries in the manifest; load accepts it today)\nis deliberately unchanged; both empty-name buffer pokes keep refusing at\nsave (pinned).",
          "is_bot": false,
          "headline": "fix(runnable): empty-name -- save-side canonical-label preflight mirr…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-23T02:17:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c290268aff4bf978f36d3822a731d1820901e4e1",
          "body": "…path manual_seed site (r79)\n\nThe r77 seed door checked only 'not isinstance(seed, int)', so two values\nstill escaped to raw torch RuntimeError (r78, hon1 + Sol): bool (an int\nsubclass that Generator.manual_seed rejects: 'manual_seed expected a long,\nbut got bool') and an int outside torch's accepte\n[…]\n-range boundaries, keeps 0/None/17 and BOTH exact range\nboundaries verifying, and unit-pins the shared guard against torch's own\nacceptance so the mirrors cannot drift. r77 seed suite unchanged (6/6).",
          "is_bot": false,
          "headline": "fix(runnable): seed -- reject bool and out-of-range int at every run-…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-23T02:10:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bf4881d1f897941ce7853a24f9756a444a2071d7",
          "body": "…nt-session identity resolution (r79)\n\nSession cleanup removed provenance stamps by re-traversing the live model\ntree, so a param/buffer popped from _parameters/_buffers mid-forward escaped\ncleanup and its prep stamp survived the session. A later capture accepted\nthe stale stamp (_tensor_has_known_p\n[…]\nizers 83/83; registered-param layout\nreads, honest conv+BN, hon1's non-popped cross-session case, and sequential\ndouble-capture cleanup all pinned green in the new immunizer (11 tests,\n7 RED pre-fix).",
          "is_bot": false,
          "headline": "fix(runnable): session-leak -- inventory-driven stamp cleanup + curre…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-23T02:04:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "288e06490606da8eccbafa45f645fffeec5dff56",
          "body": "…er provenance root -- require prep-stamped param_address, not bare isinstance) + L1 component-deep typed context_field_invalid + F2 non-tensor-state persistent-buffer universe (capture-time signatures) + seed-typing nit",
          "is_bot": false,
          "headline": "Merge r77: close the last layout vehicle (F1 fresh/foreign nn.Paramet…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-23T01:17:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5e64fb8532400e6cf417f67716a0a482c16d4db8",
          "body": "…t>) at the run door (r77)\n\nseed was typed int | None but unchecked: junk reached torch.manual_seed raw\nand escaped as RuntimeError 'manual_seed expected a long' instead of the typed\nprecondition lane. The run door now refuses non-int, non-None seeds with\nRunPreconditionError (context_field_invalid) before any provider work;\ntransactional (global torch RNG bit-identical after the refused call, pinned),\nand seed=0 / seed=None runs keep verifying.",
          "is_bot": false,
          "headline": "fix(runnable): nit -- typed RunPreconditionError for run(seed=<non-in…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-23T00:58:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "729c56ad5144c8f41863ee30ca1bb7034cb3addc",
          "body": "…on-tensor state (r77)\n\nsnapshot_capture_state returns None by design when any state_dict() value is\nnon-tensor (get_extra_state, packed/quantized entries), and the dead-model leg\nof _add_persistent_buffer_slot_drafts keyed its whole rebuild on that value\nsnapshot with a silent early return: an extr\n[…]\nhe dead save refuses loudly and typed (TorchLensIOError,\nmirroring the include_weights=True lane) -- never silent under-declaration,\nnever a wrong bind. r75 param-identity + weights suites stay green.",
          "is_bot": false,
          "headline": "fix(runnable): F2 -- dead-model persistent-buffer universe survives n…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-23T00:55:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d88a1dd9f0a893a13bba3fa8d517db25e76f85a4",
          "body": "…path/position components (r77)\n\nThe r75 L1 validator checked only the CONTAINER type: a well-formed sequence\npath/position carrying a nested list/mapping/slice COMPONENT (all unhashable\ndecoded literals) passed tuple(raw) and crashed the first downstream set/dict\nconsumer with a TypeError into the \n[…]\nis-only, typed .run() refusal, no verdict risk)\n-- lane hygiene only. Immunizer RED pre-fix on all six cross-lab-confirmed\ntamper spellings; well-formed artifacts unchanged (r75 envelope suite green).",
          "is_bot": false,
          "headline": "fix(runnable): L1 -- typed context_field_invalid for unhashable fact …",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-23T00:44:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "feed34232635ac5f4d6fc5ffa7df29f60961b2f6",
          "body": "…r rung of the unattributed-arg check (r77)\n\nA fresh/foreign nn.Parameter satisfied _tensor_has_known_provenance by bare\nisinstance, suppressing the unattributed_tensor_args break marker the r75\nlayout ancestry-integrity rung keys on: a Parameter-wrapped laundering chain\njudged CLEAN, empty input_an\n[…]\n\nr71+r73+r75 suites 59/59; state-rooted reads stay residual (3)). The\n'no graph/source provenance' warning now fires for on-path fresh-Parameter\nconsumption (same marker); save-door refusal unchanged.",
          "is_bot": false,
          "headline": "fix(runnable): F1 -- require prep-stamped provenance for the Paramete…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-23T00:38:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "15b4bd4aabd32e031b86ba97984c323b52ca2ade",
          "body": "…osed + storage-identity rung + transitive, whole class), F2 (capture-time param/buffer identity -- gc-independent honest runnable save), L1 (typed context_field_invalid for malformed envelope path)",
          "is_bot": false,
          "headline": "Merge r75: close F1 (unlabeled-receiver layout attribution -- fail-cl…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-22T23:51:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "75731f6ea0038962d5812c3390352a2de5743430",
          "body": "…d envelope fact paths (r75)\n\nA foreign artifact with a metadata-envelope path literal-encoded as an int\ncrashed tuple(fact.get('path', ()) or ()) with a TypeError into the generic\nparse catch-all (run_capability_unavailable, stringified traceback) instead\nof the closed-vocabulary context_field_inva\n[…]\niteral-fact path, and an int-encoded structure-fact position all load\nanalysis-only with context_field_invalid and refuse .run() typed;\nuntampered artifacts still verify. Contract updated in lockstep.",
          "is_bot": false,
          "headline": "fix(runnable): L1 -- typed context_field_invalid refusal for malforme…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-22T22:02:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f436bf8d7bbeecf83529b7f74b321cb797f6bb06",
          "body": "…dent honest saves (r75)\n\nThe producer resolved parameter-argument identity at SAVE time through live\nreferences (Param._param_ref, released by postprocess -> _source_model_ref ->\nnamed_parameters()); a caller that never held the model plus one gc.collect()\nbetween trace and save killed the chain, l\n[…]\nhe first\ncapture's deferred save; a genuinely-unmatched foreign tensor constant still\nrefuses typed. The r71+r73 two-file combo (the deterministic red gate) is\ngreen 3/3. Contract updated in lockstep.",
          "is_bot": false,
          "headline": "fix(runnable): F2 -- capture-time param/state identity for gc-indepen…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-22T21:56:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1766f7cb39f3c85f62ec4b52fa8a274f2dd9bcfb",
          "body": "…n with ledger/storage precision rungs (r75)\n\nThe r73 intermediate-layout net fail-OPENED on unlabeled receivers: .data\ndestroys both the capture label and _base, so (x*2).data.is_contiguous(...)\nrecorded nothing (false VERIFIED on a layout twin), and the alias LAUNDERS\nancestry transitively -- (x*2\n[…]\nout-oblivious zero-collateral, non-module hidden-tensor fail-closed\nfloor, save-door refusal pin for direct alias consumption, and a white-box\nstorage-rung precision pin. Contract updated in lockstep.",
          "is_bot": false,
          "headline": "fix(runnable): F1 -- fail-closed unlabeled-receiver layout attributio…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-22T21:38:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c75a835983acaa26fd31a14bca840116570cb474",
          "body": "…pe to UNVERIFIABLE (ancestry-precise, zero-collateral); residual (3) is now STATE-side only, input-side CLOSED",
          "is_bot": false,
          "headline": "Merge r73: close F1 -- ceiling input-derived intermediate-layout esca…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-22T20:26:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "03c5df1e184386803ed52835c417f5c86abb05e7",
          "body": "A model branching on an INTERMEDIATE tensor's layout\n((x * 2).is_contiguous(memory_format=channels_last)) reported a false\nVERIFIED when replayed on a runtime input with different strides\n(channels_last twin: same shape+dtype+values): the input contract pins\nshape+dtype+device+strided only, and the \n[…]\nth a NAMED synthetic-fact subset\n(_INPUT_METADATA_SYNTHETIC_FACT_NAMES): accessor parity stays exact,\nand a future synthetic fact still REDs the test until its state-side\ndisposition is made explicit.",
          "is_bot": false,
          "headline": "fix(runnable): ceiling input-derived intermediate-layout escape (r73 F1)",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-22T18:39:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dc15bbd4dfa7b4583a227443a22fdb4771c51d5c",
          "body": "…v2 per-family obligation/anchor model + parser-derived completeness floor + all-family strip-matrix immunizer (A); uninspectable-__dict__ fail-close (C); slice/composite-literal classifier-first (B); reserved-marker key-codec belt (D); coherent-reauthoring documented as a threat-model scope statement",
          "is_bot": false,
          "headline": "Merge r71: close the witness-strip class comprehensively -- registry-…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-22T17:41:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "07a94f84139faa786714714a1b4e517b00d31536",
          "body": "… no-read pin (r71 A)\n\ntest_r65_unread_bit_records_no_fact is buffer-carrying, so a preceding foreign\nmulti-positional-arg runnable save can corrupt buffer-address resolution (the\ndocumented pre-existing multi-arg bug, base-repro'd on 35ddfca3, out of r71\nscope) and surface as UNSUPPORTED_TENSOR_CON\n[…]\nhe r67\nsuite uses via _heal_capture_state), making the test order-independent -- natural\nalphabetical collection already runs r65 before r71, but this removes the latent\ncross-file fragility entirely.",
          "is_bot": false,
          "headline": "test(runnable): heal pre-existing buffer-address contamination in r65…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-22T15:55:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "25dbfa7641cc75b4bcc5bc7ab884c44faaedfd08",
          "body": "…t-model scope\n\n- Rewrite the r69 A 'Required-witness inventory' section as the r71\n  obligation/discharge model (all families incl. the four direct control kinds +\n  claim families, per-family anchor table + domain totality, WitnessCoverageGap\n  ledger + parser-derived completeness floor, inventory\n[…]\niteralSlice + composite-component policy. Cluster D:\n  reserved-namespace r: escaping.\n- AGENTS.md + CLAUDE.md runnable paragraphs updated to stop describing the old\n  self-indexed presence guarantee.",
          "is_bot": false,
          "headline": "docs(runnable): r71 A/B/C/D contract + AGENTS/CLAUDE lockstep + threa…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-22T15:43:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7eb913fae02cea664b53ff71a3d2d437295389b1",
          "body": "free-F1-secondary: encode_mapping_key escaped only its own \\x00tlk: prefix, so a\nreal dict key equal to a reserved input-path sentinel (EMPTY_CONTAINER_PATH_MARKER\n/ BOOL_KEY_PATH_TAG) -- \\x00-prefixed but not \\x00tlk: -- passed through raw and\n_value_at_path interpreted it positionally before mappi\n[…]\nEEN + kind changes still diverge; meta-test that every\n  positionally-interpreted sentinel is in the registry and never round-trips raw;\n  injectivity/round-trip tests extended with the reserved keys.",
          "is_bot": false,
          "headline": "fix(runnable): reserved-marker key-collision belt (r71 D)",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-22T15:37:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "20f7f17da6e17e560259944f0c4d0b293eba9da1",
          "body": "…t policy (r71 B)\n\nsecA-F1: _encode_slice_component gated only isinstance(int) then int(), so an\nIntEnum / int-subclass slice component laundered into a plain LiteralAtom(INT);\nthe snapshot treated the slice as one opaque leaf and _literal_leaf_equal fell\nthrough to value-only slice.__eq__, so a TYP\n[…]\n semantic-int specimen RED across slice start/stop/step + nested\n  edges; secA Mode.FAST E2E pin diverges; ordinary slices GREEN; composite-policy\n  coverage + classifier-before-coercion source scans.",
          "is_bot": false,
          "headline": "fix(runnable): classifier-first slice components + composite-componen…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-22T15:32:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d4a2d0ea03b2c8f7c1e350707b09648281f6e55c",
          "body": "…state (r71 C)\n\nhon1-F1: instance_state_names trusted a live __dict__ getattr, which executes a\nproperty/descriptor shadow -> attacker-chosen {} -> the declared-schema gate was\nblinded at save AND the symmetric runtime snapshot.\n\n- inspect_instance_state: ONE inert result type (names/complete/reason\n[…]\nripwire forbids live __dict__ getattr in the\n  normative module. Immunizer covers every hostile variant RED (hook counters\n  zero) + ordinary schemas GREEN + runtime uninspectable twin never verifies.",
          "is_bot": false,
          "headline": "fix(runnable): fail-closed on uninspectable declared-schema instance …",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-22T15:24:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6cb67155fa87d176cc26ca7da8a6d9f1e3625db2",
          "body": "…or; full r71 mutation matrix (r71 A phase 4)\n\n- The VERIFIED gate (_path_faithfulness) and readiness republish consult ONLY\n  the parser-derived completeness floor (derived_witness_completeness over the\n  typed gap ledger); run preparation re-asserts summary==floor as an A4 belt;\n  a summary-only f\n[…]\naim-family\n  matrix), named r70 E2E pins, completeness forgery, verdict monotonicity,\n  no-over-trigger GREENs, the floor source-scan tripwire, and the\n  coherent-reauthoring threat-model machine pin.",
          "is_bot": false,
          "headline": "fix(runnable): executor/state consume owner obligations + derived flo…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-22T15:15:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0f7c6919b74c55ef5b459714c9314e25a8dc4d96",
          "body": "…parser floor/totality (r71 A phases 1-3)\n\nClose the r70 witness-strip class at the contract/producer/parser layers:\n- WITNESS_FAMILY_REGISTRY v2: typed FamilySpec rows for EVERY verdict-steering\n  family (4 direct control kinds + 7 shape families) plus the two explicit\n  claim-only families (inert_\n[…]\nefuse at save instead of shipping\n  UNVERIFIABLE.\n- r70 named repros closed: corr2recover-H1 A/B single+pair+3-way strips,\n  free-F1 metadata matched-pair strip -> context_field_invalid analysis-only.",
          "is_bot": false,
          "headline": "fix(runnable): registry v2 + owner-record obligations + gap ledger + …",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-22T14:57:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a49738b895df3bca644201ba5eb7e98d65347152",
          "body": "…ence proof + descriptor inventory (A), enum/subclass semantic-scalar refuse + canonical mapping-key codec (B+D), all-MRO instance-state enumerator (C), scrub DROP-order fix (E), no-untyped-save-error belt; 2 documented residuals (custom-Mapping hidden-state, plain-vs-numpy-wrapper type-steering)",
          "is_bot": false,
          "headline": "Merge r69: close r68 input-contract completeness tail -- witness-pres…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-22T12:41:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bc54b622b3ced1466484f2a20cd473955d02d481",
          "body": "…riteback descriptor over-refusal\n\nGate item 1 (test lockstep): the authoritative SparseRunDescriptor field\ntuple in test_runnable_contract_scaffolding gains required_witness_inventory\n(the intended r69 A schema addition, contract section 4) -- sweep confirmed\nevery other descriptor-field enumeratio\n[…]\nded run\n(_heal_capture_state), the established workaround for the PRE-EXISTING\nmain-branch next-capture buffer-address bug (r68 ledger, reproduced\nbyte-identically on base 35ddfca3; out of r69 scope).",
          "is_bot": false,
          "headline": "fix(runnable): r69 gate -- authoritative-field lockstep + r15 numpy-w…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-22T12:23:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4979b07f79da8e7226e3c16b2d1f58e965b6b78e",
          "body": "…/glossary lockstep + the two documented residuals (r69)\n\nBelt: one parametrized input-boundary runnable-save sweep ({str, bytes, str\nsubclass, complex, Decimal, enum, stock NumPy scalar, object} x {top-level,\nnested mapping value, nested dataclass field, nested tuple element}) -- every\ncell either \n[…]\nalar, semantic-typed scalar,\n  canonical mapping-key token, required-witness inventory.\nAGENTS.md/CLAUDE.md frozen runnable summaries required no correction (no\nstatement contradicts the r69 posture).",
          "is_bot": false,
          "headline": "fix(runnable): cross-cutting -- no-untyped-save-error belt + contract…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-22T10:18:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1cc7461bc18b3ea53aa180d72c769295f76b2e76",
          "body": "…rializer (r69 E)\n\nhon1-F5 root cause: _scrub_field ran the Trace raw_input/raw_output special\ncase BEFORE the effective-policy DROP check, so the sparse-runnable effective\npolicy's DROP of both raw fields was bypassed and the generic small-value\npolicy retained a nested tensor inside the value-free\n[…]\nspecial case still runs);\nthe sparse-core payload assertion stays the untouched final tripwire (the\ngenuine-stray tensor/BlobRef negatives in test_tlspec_runnable_param_\nconditional.py still fire it).",
          "is_bot": false,
          "headline": "fix(runnable): E -- effective DROP wins before the Trace raw-value se…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-22T10:09:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3c1cd7d426d5e7a44337ba126367c2026fe019d2",
          "body": "…ce proof + bidirectional literal cross-anchor (r69 A)\n\nCloses the r68 witness-family stripping class (secA-F1/free-F1: validating\nonly SURVIVING facts let a stripped family restore weaker semantics and\nfalse-VERIFY a kind/class-swapped input).\n\nONE closed WITNESS_FAMILY_REGISTRY (torchlens/runnable\n[…]\n/inventory mutations + locked staging semantics, positive\nmatrix (tensor-only/scalar/empty-root/mixed-kwargs/no-reads/read-gated), and\nthe producer-emission meta-test (emitter count == registry size).",
          "is_bot": false,
          "headline": "fix(runnable): A -- RequiredWitnessInventory descriptor-native presen…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-22T10:06:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f0401893eb741a54b582a408d62296e8b47cc8a5",
          "body": "…pping-key authority (r69 B+D)\n\nONE closed classify_scalar lattice in _input_walk.py (enum FIRST, exact\nbuiltin atoms, programmatic stock-numpy transparent wrapper set with exact\n.item() admission, builtin/np-scalar subclasses semantic, else opaque),\nconsumed by every scalar choke point: snapshot le\n[…]\n>run structural law, NaN bit/injectivity property tests,\nduplicate-token refusal, and source meta-tests (classifier at every choke\npoint, no decoded-value binding lane, no broad np.generic admission).",
          "is_bot": false,
          "headline": "fix(runnable): B+D -- one scalar type-class classifier + canonical ma…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-22T09:45:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bd6ff991326bdf067e92f9d5fe485c6b4a911be1",
          "body": "… counts regardless of value (r69 C)\n\nOne instance_state_names() enumerator (every __dict__ key + every SET slot\nacross type(value).__mro__: string-__slots__ normalized, __dict__/__weakref__\nskipped, private names mangled against the declaring class, only genuine\nmember descriptors read directly -- \n[…]\nence subclass exemption (documented custom-Mapping residual)\nunchanged. Immunizer: MRO/storage matrix, falsey-presence matrix, E2E refusal\n+ bind-side divergence pins, clean-lane no-over-trigger pins.",
          "is_bot": false,
          "headline": "fix(runnable): C -- inert all-MRO instance-state enumerator, presence…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-22T09:31:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "35ddfca3676e028bc1129d484cb718863d2dcfea",
          "body": "…or table + return closure (C1), storage-accessor disposition + actual-read gating (C3+C6), _version always-refuse + oracle-1 parity (C4), neutral defensive materialization (C5), input-boundary snapshot spine + key codec + registered containers (C2), plus C2 over-trigger relaxations (numpy-scalar literal, custom-mapping input)",
          "is_bot": false,
          "headline": "Merge r67: close r66 completeness long-tail -- receiver-class generat…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-22T08:11:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cc9fae36fed2e76b8435269d465e4eab6b6dd9fb",
          "body": "…m-mapping input; conform opaque-key test (r67)\n\nHeavy-gate fixes on the combined r67 tree (3 C2 tests, all pass on base):\n\n- CODE: leaf/tensor snapshot nodes no longer carry the exact-type witness --\n  scalar value-literal semantics belong to the literal-witness VALUE contract\n  (numeric equality a\n[…]\nmapping_key), strictly\n  stronger than the superseded save-then-UNVERIFIABLE downgrade lane.\n- Forgery pins extended: type-on-leaf/tensor node facts and missing\n  container-type facts refuse at parse.",
          "is_bot": false,
          "headline": "fix(runnable): relax C2 over-triggers -- numpy-scalar literal + custo…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-22T07:53:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e2fcd3127766171076072c5d016a5ca587c01012",
          "body": "…for combined gate",
          "is_bot": false,
          "headline": "Merge r67 RNG/C1 (receiver-class generator table) into coupled C2-C6 …",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-22T06:04:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "51ee72412464c37a84e30753d7394eae3640ddcd",
          "body": "…ucture facts, one key codec, registered support (r67 C2)\n\nr66 C2 root: the structure witness recorded ROOT kind only and walkers disagreed\non vocabulary, so nested kinds, exact classes, empty-dataclass arity, grammar\nmapping keys, hidden instance state, and registered containers could be lost or\ntr\n[…]\ning a\n  multi-positional-arg runnable artifact breaks buffer-address resolution for\n  the NEXT capture until a loaded run heals it); documented in the r67 report\n  for the r68 ledger, out of C2 scope.",
          "is_bot": false,
          "headline": "fix(runnable): complete input-boundary snapshot spine -- per-node str…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-22T06:02:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "aa3ae6834db6614ae4544848004757ab5c98842f",
          "body": "… narrow helper for all defensive clone phases (r67 C5)\n\ncorr1-2: input/state clones, transfers, and fallback allocations inherited the\nCALLER's ambient inference/no-grad state (they run before recorded execution\ncontexts are entered), so .run() inside torch.inference_mode() minted\ninference-mode cl\n[…]\nity + input requires_grad mirror preservation pins.\n- Contract: neutral pre-forward defensive materialization defined separately\n  from recorded execution contexts, with the exact-restoration promise.",
          "is_bot": false,
          "headline": "fix(runnable): neutral pre-execution defensive materialization -- one…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-22T05:32:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "efecb342c3d00ac4a0f84a07ee88339757ee79fb",
          "body": "…gating + observed-value placement (r67 C3+C6)\n\ncorr1-4/free-F4/free-F5/r66b-R3: handle acquisition stamped storage_nbytes\nwithout an accessor call (false refusal on discarded larger-base handles),\nequivalent reads through UntypedStorage/TypedStorage handles were unwitnessed\n(false VERIFIED on stora\n[…]\nead\n  pairs, observed-read property, identity restoration, tied-alias pin,\n  non-leaf-grad matrix, hostile-subclass admission (state+input), r66b R3\n  named regression; contract rewritten in lockstep.",
          "is_bot": false,
          "headline": "fix(runnable): atomic storage-accessor dispositions with actual-read …",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-22T05:24:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e6768031da50078b85274ff303076dee0ae4e464",
          "body": null,
          "is_bot": false,
          "headline": "fix(rng): receiver-class generator table + return-value closure (r67 C1)",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-22T04:53:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a429993d6ef144e72d53c6ca4fc3aed6feadc134",
          "body": "…-policy table (r67 C4)\n\nhon1-F3: version_is_zero described a TorchLens-engineered staging clone, not\nOracle 1 -- default load_state_dict(strict=True, assign=False) copy increments\nconstructor-owned counters (0->1 plain slots, 1->2 initialized modules), so a\ncaptured _version==0 branch saved+VERIFIE\n[…]\ntion; no static scalar without a probe recipe; policy\n  table closed+total; both-histories _version refusal pins.\n- Contract: four dispositions defined; every version-zero staging guarantee\n  deleted.",
          "is_bot": false,
          "headline": "fix(runnable): _version is refuse-on-any-read under the closed oracle…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-22T04:42:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3891e77d3515e1f4285c5b00b9478794e54d2f9c",
          "body": "…t parity + walker unification + torch-RNG registry (r64 findings)\n\nIncludes the is_shared device-awareness regap fix (staged CUDA slots are is_shared=True).",
          "is_bot": false,
          "headline": "Merge r65: comprehensive witness/monitor completeness -- state<->inpu…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-22T03:15:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ab9e3e779bb300050a41858f504b973cf4ab9814",
          "body": "…ts are is_shared=True (r65 X regap)",
          "is_bot": false,
          "headline": "fix(runnable): device-aware is_shared canonicality -- staged CUDA slo…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-22T01:21:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e6031fbfd2c54df7de31ec2d4be0fd92fd86fb80",
          "body": "…ing version-0 guarantee",
          "is_bot": false,
          "headline": "Merge r65 lane X (state): state<->input metadata mirror parity + stag…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-21T23:32:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f921557273c833c03a08431646082fa0eb2399f6",
          "body": "…pleteness",
          "is_bot": false,
          "headline": "Merge r65 lane Z (rng): monitor torch global RNG APIs -- registry com…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-21T23:32:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cd19960e0c0fbfe931a49f5b87305dc676fe3074",
          "body": "…tch across three walkers",
          "is_bot": false,
          "headline": "Merge r65 lane Y (walk): single-source input-boundary container dispa…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-21T23:32:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ffd4e33504a027dd46151a809f889c93540560ef",
          "body": "…-0 guarantee for inference-source clones\n\nCompletes the r65 state-metadata mirror (mechanism at b55c1ff3):\n\n- tests/test_tlspec_runnable_r65_state_metadata_parity.py: T-X1 set identity\n  (mirror keys == input-constant union == 20-name io fact vocabulary), T-X2\n  chain completeness (every read kind \n[…]\nals (3-state-twin) and (4) identity-aliasing\n  documented; declared-fact witnesses supersede the r63 'no recorded metadata\n  fact' sentence as a v2 vocabulary extension (no schema bump, no new codes).",
          "is_bot": false,
          "headline": "fix(runnable): r65 cluster X parity tests + contract; staging version…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-21T20:06:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b55c1ff36d266c7c1db878a25f14d8b43e0dc848",
          "body": "… + CONTRACT PENDING\n\nMirror-table state-metadata witness net (INPUT_METADATA_ACCESSOR_SPECS driving the wrappers)\n+ storage_nbytes_is_tight and placement/autograd signature dims + internal_scalar_read()\nmarkers on TorchLens's own per-op requires_grad reads (so the new property observer never\nmistak\n[…]\n TESTS (T-X1/T-X2 + behavioral\npins) and the contract state-metadata section are NOT YET WRITTEN -- agent stalled before them.\nWIP so the mechanism is recoverable; resume adds tests + contract on top.",
          "is_bot": false,
          "headline": "wip(runnable): r65 cluster X state-metadata mirror mechanism -- TESTS…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-21T19:49:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "acbfd85deda93fdab5c343d0db666537e3e39af3",
          "body": "… cluster Z)\n\nAdd a frozen TORCH_RNG_SURFACE disposition table + enumeration meta-test to the host-\nnondeterminism registry: torch.seed/cuda.seed = entropy ceiling; manual_seed/set_rng_state/\nfork_rng = in-forward mutation ceiling; initial_seed = replayable_read (run seed==capture\nseed VERIFIED, off\n[…]\n39 escape belt; a row would over-ceiling torch.utils.checkpoint). Held-refs so\n'from torch import manual_seed' can't bypass; TL-internal seed/snapshot/restore suppressed.\nCloses r64 sol_correctness#2.",
          "is_bot": false,
          "headline": "fix(rng): monitor torch global RNG APIs -- registry completeness (r65…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-21T19:46:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "37b80ffcaa9e9cfc6e1ffac205610d59fb5dc786",
          "body": "… the three walkers (r65 cluster Y)\n\nClose the r64 Finding-1 false-VERIFIED: the capture metadata-site walker (W2)\ndid not descend dataclass input containers, so a metadata predicate read on a\ndataclass tensor field (box.x.is_contiguous()) recorded no model_input_metadata\nwitness and a same-value no\n[…]\nund-trip parity on a torture container; opaque-key subtrees stay\nfail-closed (consumed tensor refuses at save, non-tensor sibling ceilings\nUNVERIFIABLE). Contract input-site-exactness section updated.",
          "is_bot": false,
          "headline": "fix(runnable): single-source input-boundary container dispatch across…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-21T19:41:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fcafb88c748808687f893842a24d56c26d07c058",
          "body": "…ensor-construct deny (r62 findings)\n\nThree clusters from the r62 convergence check:\n- state-binder metadata/layout (2 HIGH, new class): witness registered-state metadata\n  reads (is_contiguous/stride/storage_offset/is_conj) as escapes + escape-gated producer\n  refusal of non-canonical captured phys\n[…]\nruct deny (1 MED + 1 LOW): extend the load-time constructor deny\n  from storage types to torch.Tensor / legacy tensortype / numpy.ndarray types.\n\nCapture tripwire intact; zero r63-surface regressions.",
          "is_bot": false,
          "headline": "Merge r63: state-metadata completeness + gc branch completion + r49 t…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-21T18:11:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "88c94fadb36be1abd0a2e7dde30b90a22d8d208f",
          "body": "…helper\n\nr63 C1 relocated the state-binding byte guard from the binder functions into the single\n_staged_state_clone helper (which still calls _byte_guarded_clone). The r61 corr_2\nguarantee -- every state-binding clone is byte-guarded, no raw clones -- is unchanged;\nassert the staging-helper routing instead of the pre-refactor call site.",
          "is_bot": false,
          "headline": "test(runnable): conform r61 clone-routing tripwire to r63 C1 staging …",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-21T16:34:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8d7876dc4e374c235540e591e44d29cd019fa633",
          "body": null,
          "is_bot": false,
          "headline": "Merge r63 C1: state-tensor metadata/layout completeness (escape-gated)",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-21T16:19:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b713f80db04a7c5cb0db8ae09c2e8bf486cae8c9",
          "body": null,
          "is_bot": false,
          "headline": "Merge r63 C2: gc numeric-payload branch completion (r61 regaps)",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-21T16:19:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bf40d6d5eb95c5f184b8d2e47d0260d8fba6d470",
          "body": null,
          "is_bot": false,
          "headline": "Merge r63 C3: r49 tensor/ndarray-construct deny (security regap)",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-21T16:19:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "723645dc3c841d427efc2d51bf4aac88fa3c10fb",
          "body": "…tate-metadata reads + escape-gated (r63 cluster 1)\n\nClose state-binder metadata/layout false-VERIFIED (r62 state-binder HIGHs + the\ncapture-transport lossiness found in reconcile). Part 1: extend the is_contiguous/\nstride/storage_offset/is_conj completeness wrappers to attribute reads on registered\n[…]\ning subset (class/layout/names/quantized/nested). One\n_state_metadata_signature helper stamped pre-clone; runtime tripwire in\n_state_contract_checks. One new STATE_METADATA_MISMATCH; no schema change.",
          "is_bot": false,
          "headline": "fix(runnable): state-tensor metadata/layout completeness -- witness s…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-21T16:15:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "53fc14e8af3746a50b9639ce2798946a916b6736",
          "body": "…er 2)\n\n_resolve_slot_member (r62 raw-shadow HIGH, sol_angle2#1): prefer the CPython-\nmangled private-slot key BEFORE any raw class-dict key and typecheck every\ncandidate -- only an inert types.MemberDescriptorType is ever returned (never\nan arbitrary raw __get__ attr that could invoke user code); N\n[…]\nass edge. Contract section 11 wording updated (mangled-first shadow-\nrobust slot resolution; payload instance AND user-defined class surfaces\nwalked, trusted torch/numpy/stdlib classes remain leaves).",
          "is_bot": false,
          "headline": "fix(rng): complete r61 numeric-payload branch structurally (r63 clust…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-21T15:18:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "94029675af3cf56525e17fc60c6d7a708c2f4a5d",
          "body": "The r49 alloc-DoS belt refused only torch STORAGE construction; a hostile\nmetadata.pkl could still REDUCE/NEWOBJ/NEWOBJ_EX-construct torch.Tensor(N) /\ntorch.FloatTensor(N) / numpy.ndarray((N,)) at plain tl.load() time (no trust,\nno .run()) -> attacker-sized uninitialized-heap alloc. Legacy torch.<dt\n[…]\nPTY over the torch weights_only baseline + TL\nallowlists. Zero-regression proven: a real embedded-weights .tlspec performs zero\ntensor/ndarray/storage constructions on load and still saves/loads/runs.",
          "is_bot": false,
          "headline": "fix(io): deny tensor/ndarray bare construction on unpickle belts (r63)",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-21T15:04:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c2668a1bd8652c4c39cd442a51ab6bf28d939c42",
          "body": "…reachability (r60 findings)\n\nClose the last heuristic in each recurring class per-edge:\n- allocation: remove the _has_numeric_literal projection short-circuit; project every\n  taken-path call carrying a size source (tensor operand OR numeric literal). Closes the\n  no-literal and zero-numel ([N,0]@[\n[…]\nload (tensor/ndarray/np.generic) instance __dict__/__slots__\n  walked; resolve CPython name-mangled slots (hon_1 + corr_1).\n\nNo new enum / error code / detection-stage string. Capture tripwire intact.",
          "is_bot": false,
          "headline": "Merge r61: structural completion of allocation-projection + gc inert-…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-21T14:06:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e69956eb7043779dac4739c5f903bfee2ac920e2",
          "body": "…-guard (free_1+corr_2)",
          "is_bot": false,
          "headline": "Merge r61 alloc lane: project any size-source call + whole-chain byte…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-21T12:24:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8745a811ce8754b92ae9946c29de47d7f8df6160",
          "body": null,
          "is_bot": false,
          "headline": "Merge r61 rng lane: per-edge gc inert-reachability (hon_1+corr_1)",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-21T12:24:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d096e48bf840f4124f37c20f9477162ff8196c41",
          "body": "…(r61 free_1+corr_2)\n\nRemove the _has_numeric_literal projection short-circuit: project every taken-path\ncall carrying a size source (tensor operand OR numeric literal), skip only when\nneither. Closes the no-literal and zero-numel ([N,0]@[0,N]) shape-amplifier families\nthat any numel/arity threshold\n[…]\nng, embedded-state + non-persistent\nbuffer binds) through one _byte_guarded_clone core at clone_allocation_preflight;\nbuild one RunResourceCeiling at run() top. No new enum/error-code/detection-stage.",
          "is_bot": false,
          "headline": "fix(runnable): project any size-source call + whole-chain byte-guard …",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-21T12:23:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a343f44759b09856f65a724387ae95bfd04f918c",
          "body": "…state walked, mangled slots resolved (r61 hon_1+corr_1)\n\nSplit _GC_EXPANSION_LEAF_TYPES by role: _AMBIENT_BRIDGE_LEAF_TYPES (modules,\ncode, frames, _abc_data) stay severed to []; _NUMERIC_PAYLOAD_LEAF_TYPES\n(ndarray, numpy scalar, tensor) are no longer hard leaves -- gc.get_referents\nis never calle\n[…]\nFIABLE/never-ATTESTED), the 6-case mangling ground-truth matrix,\nbenign/undrawn over-trigger pins, hostile-subclass zero-user-code counters,\nand source tripwires. Contract section 11 updated to match.",
          "is_bot": false,
          "headline": "fix(rng): per-edge gc inert-reachability -- numeric-payload instance …",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-21T12:13:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a0ed50ead48c5ee8114ba470a2874b490f66a62b",
          "body": "…s RNG (r58 findings)\n\nalloc-DoS class (free_1 output-count bomb + free_2 view bind-clone OOM, both HIGH) closed STRUCTURALLY via one aggregate RunResourceCeiling: (1) output-count cap (count-instrumented FakeTensorMode aborts during fanout -- no self-DoS), (2) guarded-clone bytes at every re-materi\n[…]\n false-VERIFIED without re-opening the ambient walls.\nGates: ruff/mypy 0, smoke 1585, oracle+golden 64 (tripwire intact), runnable/rng 1246, not-slow 0 alloc/rng/r47 failures (only pre-existing reds).",
          "is_bot": false,
          "headline": "Merge r59: aggregate replay resource ceiling + registered-module slot…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-21T10:40:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "447374fba17ee0a5921fa0720d0b90998d40778a",
          "body": null,
          "is_bot": false,
          "headline": "merge r59 B (registered-module __slots__ RNG inventory)",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-21T08:49:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "647dba473a3f887a7108824695339745f04184b4",
          "body": "… retention-floor)",
          "is_bot": false,
          "headline": "merge r59 A (aggregate replay resource ceiling: count + clone-bytes +…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-21T08:48:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "976823785b879a0a6697c48045c4342baf4ee34a",
          "body": "…ded-clone bytes + retention-floor) closes the allocation-DoS class structurally (r59)",
          "is_bot": false,
          "headline": "fix(runnable): aggregate replay resource ceiling (output-count + guar…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-21T08:46:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c7573902292b064fbc04f887a632deae51a05eae",
          "body": "…r (close the slots false-VERIFIED without re-opening the ambient walls) (r59 hon_1)",
          "is_bot": false,
          "headline": "fix(runnable): inventory a registered module's __slots__ RNG generato…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-21T08:28:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "32336d8775ac14174918cde49cbe048871a7a2d9",
          "body": "C3 (HIGH alloc DoS): FakeTensorMode projection runs for EVERY numeric-literal call (deleted the _SIZE_DRIVING_QUALNAME_TAILS allowlist); pure views excluded by _cdata storage-aliasing (no view-name list). Op-agnostic.\nC6 (HIGH honesty): gc inert sweep reaches a bound C method's non-module receiver +\n[…]\ndowngrade; C1 file-write refusal intact.\nGates: ruff/mypy 0, smoke 1566, oracle+golden 64 (tripwire intact), runnable/rng/codec 1400, not-slow 0 r47/rng failures (only pre-existing/other-sprint reds).",
          "is_bot": false,
          "headline": "Merge r57: delete the enumerations (r56 findings)",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-21T07:08:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1f3bd032ff6230fdb5cc12d5ea86418e48fce728",
          "body": "…bient edges)",
          "is_bot": false,
          "headline": "merge r57 C6 follow-up (drop FunctionType __globals__/__builtins__ am…",
          "author_name": "JohnMark Taylor",
          "author_login": "johnmarktaylor91",
          "committed_at": "2026-07-21T05:20:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 100,
      "commits_last_year": 2476,
      "latest_release_at": "2026-07-25T12:22:49Z",
      "latest_release_tag": "v2.32.1",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 20,
      "days_since_latest_release": 0,
      "mean_days_between_releases": 4.2
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 42,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "torchlens",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [
            "torch",
            "torchlens",
            "activations",
            "features",
            "io",
            "Development Status :: 4 - Beta",
            "Intended Audience :: Science/Research",
            "Natural Language :: English",
            "Programming Language :: Python :: 3.10",
            "Programming Language :: Python :: 3.11",
            "Programming Language :: Python :: 3.12",
            "Programming Language :: Python :: 3.13",
            "Programming Language :: Python :: 3.9"
          ],
          "ecosystem": "pypi",
          "matches_repo": true,
          "registry_url": "https://pypi.org/project/torchlens/",
          "is_deprecated": false,
          "latest_version": "2.32.1",
          "repository_url": "https://github.com/johnmarktaylor91/torchlens",
          "versions_count": 148,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 2689,
          "first_published_at": "2023-09-03T19:47:24.348665Z",
          "latest_published_at": "2026-07-25T12:23:00.518843Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 0
        }
      ]
    },
    "popularity": {
      "forks": 29,
      "stars": 649,
      "watchers": 5,
      "fork_history": {
        "days": [
          {
            "date": "2022-12-04",
            "count": 2
          },
          {
            "date": "2023-03-20",
            "count": 1
          },
          {
            "date": "2023-06-01",
            "count": 1
          },
          {
            "date": "2023-06-05",
            "count": 1
          },
          {
            "date": "2023-07-18",
            "count": 1
          },
          {
            "date": "2023-08-11",
            "count": 1
          },
          {
            "date": "2023-09-08",
            "count": 1
          },
          {
            "date": "2023-09-29",
            "count": 1
          },
          {
            "date": "2023-12-16",
            "count": 1
          },
          {
            "date": "2024-02-13",
            "count": 1
          },
          {
            "date": "2024-03-01",
            "count": 1
          },
          {
            "date": "2024-04-19",
            "count": 1
          },
          {
            "date": "2024-07-19",
            "count": 1
          },
          {
            "date": "2024-08-17",
            "count": 1
          },
          {
            "date": "2024-10-09",
            "count": 1
          },
          {
            "date": "2024-12-25",
            "count": 1
          },
          {
            "date": "2024-12-26",
            "count": 1
          },
          {
            "date": "2025-01-22",
            "count": 1
          },
          {
            "date": "2025-03-04",
            "count": 1
          },
          {
            "date": "2025-03-14",
            "count": 1
          },
          {
            "date": "2025-03-17",
            "count": 1
          },
          {
            "date": "2025-03-22",
            "count": 1
          },
          {
            "date": "2025-04-24",
            "count": 1
          },
          {
            "date": "2025-07-08",
            "count": 1
          },
          {
            "date": "2025-07-19",
            "count": 1
          },
          {
            "date": "2025-09-11",
            "count": 1
          },
          {
            "date": "2025-10-24",
            "count": 1
          },
          {
            "date": "2026-07-12",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 29,
        "total_forks": 29
      },
      "star_history": null,
      "open_issues_and_prs": 5
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "demos",
        "examples",
        "notebooks",
        "recipes"
      ],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [],
      "largest_source_bytes": 291802,
      "source_files_sampled": 3710,
      "oversized_source_files": 104,
      "agent_instruction_files": [
        ".github/AGENTS.md",
        "AGENTS.md",
        "CLAUDE.md",
        "notebooks/audit/CLAUDE.md",
        "notebooks/audit/visual/CLAUDE.md",
        "scripts/AGENTS.md",
        "tests/AGENTS.md",
        "torchlens/AGENTS.md",
        "torchlens/CLAUDE.md",
        "torchlens/backends/AGENTS.md",
        "torchlens/backends/torch/AGENTS.md",
        "torchlens/capture/AGENTS.md",
        "torchlens/capture/CLAUDE.md",
        "torchlens/data_classes/AGENTS.md",
        "torchlens/data_classes/CLAUDE.md",
        "torchlens/fastlog/CLAUDE.md",
        "torchlens/intervention/CLAUDE.md",
        "torchlens/postprocess/AGENTS.md",
        "torchlens/postprocess/CLAUDE.md",
        "torchlens/utils/AGENTS.md",
        "torchlens/validation/AGENTS.md",
        "torchlens/validation/CLAUDE.md",
        "torchlens/visualization/AGENTS.md",
        "torchlens/visualization/CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 26150
    },
    "dependencies": {
      "manifests": [
        "pyproject.toml"
      ],
      "advisories": {
        "error": "No resolved dependencies carried a version and a supported ecosystem",
        "scope": "repository_graph",
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 35,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "pypi"
      ],
      "dependencies": [
        {
          "name": "numpy",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": null
        },
        {
          "name": "packaging",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": null
        },
        {
          "name": "torch",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=2.1"
        },
        {
          "name": "safetensors",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.4"
        },
        {
          "name": "tqdm",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": null
        },
        {
          "name": "graphviz",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": null
        },
        {
          "name": "typing_extensions",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=4.0"
        },
        {
          "name": "pillow",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=9"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "pillow",
            "direct": true,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "safetensors",
            "direct": true,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "torch",
            "direct": true,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "typing-extensions",
            "direct": true,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "brain-score",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "captum",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "depyf",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "dialz",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "inseq",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "ipython",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "jupyter-client",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "lightning",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "lit-nlp",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "lovely-tensors",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "mlx",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "nnsight",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "paddlepaddle",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "pandas",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "pyarrow",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "pytorch-grad-cam",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "repeng",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "rsatoolbox",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "sae-lens",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "sentence-transformers",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "setuptools",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "shap",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "steering-vectors",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "tensorflow",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "timm",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "tinygrad",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "torchextractor",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "torchshow",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "torchvision",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "transformers",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "wandb",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 35,
        "direct_count": 4,
        "indirect_count": 31
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 1,
        "merged_prs": 121,
        "open_issues": 4,
        "closed_ratio": 0.9,
        "closed_issues": 36,
        "closed_unmerged_prs": 13
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "johnmarktaylor91",
          "commits": 1833,
          "avatar_url": "https://avatars.githubusercontent.com/u/16569815?v=4"
        },
        {
          "type": "User",
          "login": "kalekundert",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/298132?v=4"
        }
      ],
      "contributors_sampled": 2,
      "top_contributor_share": 0.999
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "lint.yml",
        "nightly.yml",
        "quality.yml",
        "release.yml",
        "tests.yml",
        "weekly.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": true
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 5,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 3,
            "reason": "project has 1 contributing companies or organizations -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "3675dc20af58c6c1015f9640040adf968deba4b5",
        "ran_at": "2026-07-25T12:24:03Z",
        "aggregate_score": 4.3,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-25T12:22:52Z",
      "oldest_open_prs": [
        {
          "number": 54,
          "created_at": "2025-07-19T11:33:04Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-10T17:17:13Z",
      "ci_last_conclusion": null,
      "oldest_open_issues": [
        {
          "number": 24,
          "created_at": "2024-08-20T23:17:11Z",
          "last_comment_at": "2024-08-21T04:24:18Z",
          "last_comment_author": "johnmarktaylor91"
        },
        {
          "number": 28,
          "created_at": "2024-08-30T20:45:09Z",
          "last_comment_at": "2024-08-30T21:59:45Z",
          "last_comment_author": "johnmarktaylor91"
        },
        {
          "number": 44,
          "created_at": "2025-03-29T09:05:04Z",
          "last_comment_at": "2025-10-14T17:34:49Z",
          "last_comment_author": "johnmarktaylor91"
        },
        {
          "number": 50,
          "created_at": "2025-05-02T00:05:56Z",
          "last_comment_at": "2025-05-07T01:31:11Z",
          "last_comment_author": "johnmarktaylor91"
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/johnmarktaylor91/torchlens",
    "host": "github.com",
    "name": "torchlens",
    "owner": "johnmarktaylor91"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 66,
      "inputs": {
        "security": 44,
        "vitality": 83,
        "community": 56,
        "governance": 56,
        "engineering": 85
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 83,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 78,
            "inputs": {
              "commits_last_year": 2476,
              "human_commit_share": 0.99,
              "days_since_last_push": 0,
              "active_weeks_last_year": 20
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "20/52 weeks with commits",
                "points": 13.8,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 20
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "2476 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 2476
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 100,
              "latest_release_tag": "v2.32.1",
              "releases_from_tags": false,
              "days_since_latest_release": 0,
              "mean_days_between_releases": 4.2
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "100 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 100
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~4.2 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 4.2
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 0,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 0 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 56,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "moderate",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 61,
            "inputs": {
              "forks": 29,
              "stars": 649,
              "watchers": 5,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "649 stars",
                "points": 45.6,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 649
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "29 forks",
                "points": 12.1,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 29
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "5 watchers",
                "points": 3.3,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 57,
            "inputs": {
              "packages": [
                "torchlens"
              ],
              "dependents": null,
              "ecosystems": "pypi",
              "total_downloads": null,
              "monthly_downloads": 2689
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "2,689 downloads/month across pypi",
                "points": 45.7,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 2689,
                      "ecosystems": "pypi"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 56,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 15,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 2,
              "top_contributor_share": 0.999
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "2 contributors",
                "points": 2.7,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 77,
            "inputs": {
              "merged_prs": 121,
              "open_issues": 4,
              "closed_issues": 36,
              "issue_closed_ratio": 0.9,
              "closed_unmerged_prs": 13
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "90% of issues closed",
                "points": 42.1,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 90
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "121/134 decided PRs merged",
                "points": 34.5,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 121,
                      "decided": 134
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 51,
            "inputs": {
              "followers": 28,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "johnmarktaylor91",
              "public_repos": 12,
              "account_age_days": 3853
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "28 followers of johnmarktaylor91",
                "points": 10.5,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 28,
                      "login": "johnmarktaylor91"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "12 public repos, account ~10 yr old",
                "points": 20.1,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 12
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 10
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "torchlens"
              ],
              "ecosystems": "pypi",
              "any_deprecated": false,
              "min_days_since_publish": 0
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on pypi",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "pypi"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 0 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "148 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 148
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "excellent",
        "name": "Engineering Quality",
        "value": 85,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "excellent",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 92,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": true
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "6 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 6
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 16,
                "status": "met",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 9.6,
                "status": "met",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 44,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 44,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 4.3
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 3.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 53,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.859,
              "agent_instruction_files": [
                ".github/AGENTS.md",
                "AGENTS.md",
                "CLAUDE.md",
                "notebooks/audit/CLAUDE.md",
                "notebooks/audit/visual/CLAUDE.md",
                "scripts/AGENTS.md",
                "tests/AGENTS.md",
                "torchlens/AGENTS.md",
                "torchlens/CLAUDE.md",
                "torchlens/backends/AGENTS.md",
                "torchlens/backends/torch/AGENTS.md",
                "torchlens/capture/AGENTS.md",
                "torchlens/capture/CLAUDE.md",
                "torchlens/data_classes/AGENTS.md",
                "torchlens/data_classes/CLAUDE.md",
                "torchlens/fastlog/CLAUDE.md",
                "torchlens/intervention/CLAUDE.md",
                "torchlens/postprocess/AGENTS.md",
                "torchlens/postprocess/CLAUDE.md",
                "torchlens/utils/AGENTS.md",
                "torchlens/validation/AGENTS.md",
                "torchlens/validation/CLAUDE.md",
                "torchlens/visualization/AGENTS.md",
                "torchlens/visualization/CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 26150
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": ".github/AGENTS.md, AGENTS.md, CLAUDE.md, notebooks/audit/CLAUDE.md, notebooks/audit/visual/CLAUDE.md, scripts/AGENTS.md, tests/AGENTS.md, torchlens/AGENTS.md, torchlens/CLAUDE.md, torchlens/backends/AGENTS.md, torchlens/backends/torch/AGENTS.md, torchlens/capture/AGENTS.md, torchlens/capture/CLAUDE.md, torchlens/data_classes/AGENTS.md, torchlens/data_classes/CLAUDE.md, torchlens/fastlog/CLAUDE.md, torchlens/intervention/CLAUDE.md, torchlens/postprocess/AGENTS.md, torchlens/postprocess/CLAUDE.md, torchlens/utils/AGENTS.md, torchlens/validation/AGENTS.md, torchlens/validation/CLAUDE.md, torchlens/visualization/AGENTS.md, torchlens/visualization/CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".github/AGENTS.md, AGENTS.md, CLAUDE.md, notebooks/audit/CLAUDE.md, notebooks/audit/visual/CLAUDE.md, scripts/AGENTS.md, tests/AGENTS.md, torchlens/AGENTS.md, torchlens/CLAUDE.md, torchlens/backends/AGENTS.md, torchlens/backends/torch/AGENTS.md, torchlens/capture/AGENTS.md, torchlens/capture/CLAUDE.md, torchlens/data_classes/AGENTS.md, torchlens/data_classes/CLAUDE.md, torchlens/fastlog/CLAUDE.md, torchlens/intervention/CLAUDE.md, torchlens/postprocess/AGENTS.md, torchlens/postprocess/CLAUDE.md, torchlens/utils/AGENTS.md, torchlens/validation/AGENTS.md, torchlens/validation/CLAUDE.md, torchlens/visualization/AGENTS.md, torchlens/visualization/CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "85 of 99 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 85,
                      "sampled": 99
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "at_risk",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 33,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [],
              "has_dockerfile": false,
              "typed_language": false,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [],
              "agent_commit_share": 0,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 11,
                "status": "met",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "moderate",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 54,
            "inputs": {
              "primary_language": "Python",
              "largest_source_bytes": 291802,
              "source_files_sampled": 3710,
              "oversized_source_files": 104
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Python without a type-check config",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_typecheck_config_language",
                    "params": {
                      "language": "Python"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "104/3710 source files over 60KB",
                "points": 53.5,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 3710,
                      "oversized": 104
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "demos",
                "examples",
                "notebooks",
                "recipes"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "demos, examples, notebooks, recipes",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "demos, examples, notebooks, recipes"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "deps.dev does not index pypi:torchlens@2.32.1; advisories assessed against the repository dependency graph instead",
    "No resolved dependencies carried a version and a supported ecosystem"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-25T12:24:15.240171Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/j/johnmarktaylor91/torchlens.svg",
  "full_name": "johnmarktaylor91/torchlens",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsPyPI.