Public record
Software health reportschema 0.27.0 · metrics 1.13.0 · 2026-07-27 16:54 UTC

joinmeow / amazon-cognito-passwordless-auth

Passwordless authentication with Amazon Cognito: FIDO2 (WebAuthn, support for Passkeys), Totp MFA, Totp and Passkey Step Up

TypeScriptApache-2.0★ 0 stars⑂ 0 forkssince Apr 2025forkView on GitHub ↗

joinmeow/amazon-cognito-passwordless-auth holds a health index of 59 out of 100, placing it in the Moderate band. It scores highest on Vitality (83/100) and lowest on Community & Adoption (26/100). It was last updated 4 days ago. 2 contributors account for most of its recent work.

59
overall / 100
Moderate

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

59
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

MeowOrganization
4 followers4 public repossince Feb 2021

This repository is backed by an organization — shared, accountable stewardship that can outlive any single maintainer.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publishTags
npm@joinmeow/cognito-passwordless-auth1.0.1048,7131006 days agoawscognitofido2passwordlesswebauthnpasskeys

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

83Good · 22% of overall
How it's scored
36/36Push recency — last push 4 days ago
7.6/36Commit cadence — 11/52 weeks with commits
17.9/18Commit volume — 97 commits in the last year
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year97
human_commit_share0.95
days_since_last_push4
active_weeks_last_year11

Release discipline

100Excellent
How it's scored
27/27Ships releases — 96 releases published
36/36Release recency — latest release 6 days ago
27/27Release cadence — a release every ~32 days
0/10OpenSSF Scorecard: Signed-Releases — no data
Inputs used
releases_count96
latest_release_tagv1.0.104
releases_from_tagsno
days_since_latest_release6
mean_days_between_releases32
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

26Critical · 18% of overall
How it's scored
0/60Stars — 0 stars
0/25Forks — 0 forks
0/15Watchers — 0 watchers
Inputs used
forks0
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
How it's scored
0/22.5README
22.5/22.5License — recognized license (Apache-2.0)
0/18CONTRIBUTING guide
0/13.5Code of conduct
0/7.2Issue template
0/6.3PR template
Inputs used
has_readmeno
has_licenseno
has_contributingno
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno
How it's scored
52.5/80Monthly downloads — 8,713 downloads/month across npm
0/20Registry dependents — not reported by this ecosystem
Inputs used
packages@joinmeow/cognito-passwordless-auth
dependents
ecosystemsnpm
total_downloads
monthly_downloads8,713
Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

68Moderate · 24% of overall
How it's scored
25.2/54Bus factor — 2 contributor(s) cover half of all commits
12.4/22.5Commit distribution — top contributor authored 45% of commits
13.5/13.5Contributor breadth — 20 contributors
10/10OpenSSF Scorecard: Contributors — project has 3 contributing companies or organizations -- score normalized to 10
Inputs used
bus_factor2
contributors_sampled20
top_contributor_share0.448
How it's scored
0/46.8Issue resolution — no issues or no data
36.5/38.3PR acceptance — 105/110 decided PRs merged
0/15OpenSSF Scorecard: Code-Review — Found 0/29 approved changesets -- score normalized to 0
Inputs used
merged_prs105
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs5
Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.
How it's scored
30/30Ownership backing — organization-owned
0/20Verified domain
5/25Owner reach — 4 followers of joinmeow
16/25Track record — 4 public repos, account ~5 yr old
Inputs used
followers4
owner_typeOrganization
is_verified
owner_loginjoinmeow
public_repos4
account_age_days2,000
How it's scored
25/25Published & resolvable — 1 package(s) on npm
35/35Publish recency — latest publish 6 days ago
20/20Version history — 100 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packages@joinmeow/cognito-passwordless-auth
ecosystemsnpm
any_deprecatedno
min_days_since_publish6

Engineering Quality

Are baseline engineering and documentation practices in place?

53Moderate · 20% of overall
How it's scored
24/24CI workflows — 2 workflow(s)
24/24Tests present
16/16Linter config — .eslintrc.cjs
0/9.6Pre-commit hooks
0/6.4.editorconfig
18/20OpenSSF Scorecard: CI-Tests — 24 out of 25 merged PRs checked by a CI test -- score normalized to 9
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configyes
has_precommit_configno

Documentation

10Critical
How it's scored
0/30README
0/25Documentation directory
0/15Documentation / homepage site
0/10Repository description
0/10Topics
10/10Wiki
Inputs used
topics
has_wikiyes
homepage
has_readmeno
has_docs_dirno
has_descriptionno

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

55Moderate · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
2.2/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.2/2.5CI-Tests — 24 out of 25 merged PRs checked by a CI test -- score normalized to 9
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/29 approved changesets -- score normalized to 0
2.5/2.5Contributors — project has 3 contributing companies or organizations -- score normalized to 10
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — no data
1.5/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 3
5/5SAST — SAST tool is run on all commits
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — no data
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 12 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate4.4
Excluded from scoring (no data or not applicable): packaging, signed_releases. Remaining weights renormalized.
How it's scored
35/35Direct dependencies free of known advisories — no direct dependency carries a known advisory
25/25Indirect dependencies free of known advisories — no indirect dependency carries a known advisory
0/40No advisories left outstanding — no advisory carries a publication date
Inputs used
sourceosv
advisories0
affected_packages0
assessed_packages3
unassessed_packages0
affected_by_severitynone
direct_affected_packages0
Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:@joinmeow/cognito-passwordless-auth@1.0.104 runtime dependency closure — what installing the published package pulls in — 3 packages. Reachability is not analyzed.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

64Moderate · 0% of overall
How it's scored
0/45Agent instructions — no CLAUDE.md / AGENTS.md / editor rules
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 76 of 95 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share0.8
agent_instruction_files
agent_instruction_max_bytes
How it's scored
0/18One-command bootstrap
22/22Automated tests
11/11Lint / format config — .eslintrc.cjs
11/11Static type checking — client/tsconfig.json
10/10Reproducible environment — lockfile
4/10Demonstrated agent practice — 2 of the last 100 commits agent-authored or agent-credited
8/8Automated maintenance — 5 of the last 100 commits are automated dependency updates
3/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 3
Inputs used
has_nixno
has_testsyes
lockfilespackage-lock.json
has_dockerfileno
typed_languageyes
bootstrap_files
has_devcontainerno
has_linter_configyes
typecheck_configsclient/tsconfig.json
agent_commit_share0.02
toolchain_manifests
dependency_bot_commit_share0.05
How it's scored
45/45Type-checkable code — TypeScript (statically typed)
53.2/55Manageable file sizes — 3/92 source files over 60KB
Inputs used
primary_languageTypeScript
largest_source_bytes96,149
source_files_sampled92
oversized_source_files3

Key facts

0GitHub stars
20contributors
97commits, last 12 months
4days since last push
96releases
2bus factor
0open issues
npmpackage ecosystems

Data collection warnings

  • Community profile unavailable

More detail

OpenSSF Scorecard 4.4 / 10
4.4aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-27 16:53 UTC

10Binary-Artifactsno binaries found in the repo
3Branch-Protectionbranch protection is not maximal on development and all release branches
9CI-Tests24 out of 25 merged PRs checked by a CI test -- score normalized to 9
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/29 approved changesets -- score normalized to 0
10Contributorsproject has 3 contributing companies or organizations -- score normalized to 10
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
n/aPackagingpackaging workflow not detected
3Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 3
10SASTSAST tool is run on all commits
0Security-Policysecurity policy file not detected
n/aSigned-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities12 existing vulnerabilities detected
Direct dependencies 2
RegistryPackageVersion constraintManifest
npmaws-jwt-verify^4.0.1package.json
npmcbor^9.0.2package.json
All dependencies 619

Full resolved dependency set from the GitHub dependency graph: 2 direct and 617 indirect (transitive) packages. The transitive closure is complete when the repository commits a lockfile.

RegistryPackageVersionRelation
npmaws-jwt-verify4.0.1direct
npmcbor9.0.2direct
npm@ampproject/remapping2.3.0indirect
npm@asamuzakjp/css-color3.2.0indirect
npm@babel/code-frame7.27.1indirect
npm@babel/compat-data7.27.3indirect
npm@babel/core7.27.3indirect
npm@babel/generator7.27.3indirect
npm@babel/helper-compilation-targets7.27.2indirect
npm@babel/helper-module-imports7.27.1indirect
npm@babel/helper-module-transforms7.27.3indirect
npm@babel/helper-plugin-utils7.27.1indirect
npm@babel/helper-string-parser7.27.1indirect
npm@babel/helper-validator-identifier7.27.1indirect
npm@babel/helper-validator-option7.27.1indirect
npm@babel/helpers7.27.3indirect
npm@babel/parser7.27.3indirect
npm@babel/plugin-syntax-async-generators7.8.4indirect
npm@babel/plugin-syntax-bigint7.8.3indirect
npm@babel/plugin-syntax-class-properties7.12.13indirect
npm@babel/plugin-syntax-class-static-block7.14.5indirect
npm@babel/plugin-syntax-import-attributes7.27.1indirect
npm@babel/plugin-syntax-import-meta7.10.4indirect
npm@babel/plugin-syntax-json-strings7.8.3indirect
npm@babel/plugin-syntax-jsx7.27.1indirect
npm@babel/plugin-syntax-logical-assignment-operators7.10.4indirect
npm@babel/plugin-syntax-nullish-coalescing-operator7.8.3indirect
npm@babel/plugin-syntax-numeric-separator7.10.4indirect
npm@babel/plugin-syntax-object-rest-spread7.8.3indirect
npm@babel/plugin-syntax-optional-catch-binding7.8.3indirect
npm@babel/plugin-syntax-optional-chaining7.8.3indirect
npm@babel/plugin-syntax-private-property-in-object7.14.5indirect
npm@babel/plugin-syntax-top-level-await7.14.5indirect
npm@babel/plugin-syntax-typescript7.27.1indirect
npm@babel/runtime7.27.6indirect
npm@babel/template7.27.2indirect
npm@babel/traverse7.27.3indirect
npm@babel/types7.27.3indirect
npm@bcoe/v8-coverage0.2.3indirect
npm@cspotcode/source-map-support0.8.1indirect
npm@csstools/color-helpers5.0.2indirect
npm@csstools/css-calc2.1.4indirect
npm@csstools/css-color-parser3.0.10indirect
npm@csstools/css-parser-algorithms3.0.5indirect
npm@csstools/css-tokenizer3.0.4indirect
npm@esbuild/aix-ppc640.28.1indirect
npm@esbuild/android-arm0.28.1indirect
npm@esbuild/android-arm640.28.1indirect
npm@esbuild/android-x640.28.1indirect
npm@esbuild/darwin-arm640.28.1indirect
npm@esbuild/darwin-x640.28.1indirect
npm@esbuild/freebsd-arm640.28.1indirect
npm@esbuild/freebsd-x640.28.1indirect
npm@esbuild/linux-arm0.28.1indirect
npm@esbuild/linux-arm640.28.1indirect
npm@esbuild/linux-ia320.28.1indirect
npm@esbuild/linux-loong640.28.1indirect
npm@esbuild/linux-mips64el0.28.1indirect
npm@esbuild/linux-ppc640.28.1indirect
npm@esbuild/linux-riscv640.28.1indirect
npm@esbuild/linux-s390x0.28.1indirect
npm@esbuild/linux-x640.28.1indirect
npm@esbuild/netbsd-arm640.28.1indirect
npm@esbuild/netbsd-x640.28.1indirect
npm@esbuild/openbsd-arm640.28.1indirect
npm@esbuild/openbsd-x640.28.1indirect
npm@esbuild/openharmony-arm640.28.1indirect
npm@esbuild/sunos-x640.28.1indirect
npm@esbuild/win32-arm640.28.1indirect
npm@esbuild/win32-ia320.28.1indirect
npm@esbuild/win32-x640.28.1indirect
npm@eslint-community/eslint-utils4.4.0indirect
npm@eslint-community/regexpp4.10.1indirect
npm@eslint/eslintrc2.1.4indirect
npm@eslint/js8.57.0indirect
npm@humanwhocodes/config-array0.11.14indirect
npm@humanwhocodes/module-importer1.0.1indirect
npm@humanwhocodes/object-schema2.0.3indirect
npm@istanbuljs/load-nyc-config1.1.0indirect
npm@istanbuljs/schema0.1.3indirect
npm@jest/console29.7.0indirect
npm@jest/core29.7.0indirect
npm@jest/environment29.7.0indirect
npm@jest/environment30.0.0-beta.3indirect
npm@jest/environment-jsdom-abstract30.0.0-beta.3indirect
npm@jest/expect29.7.0indirect
npm@jest/expect-utils29.7.0indirect
npm@jest/fake-timers29.7.0indirect
npm@jest/fake-timers30.0.0-beta.3indirect
npm@jest/globals29.7.0indirect
npm@jest/pattern30.0.0-beta.3indirect
npm@jest/reporters29.7.0indirect
npm@jest/schemas29.6.3indirect
npm@jest/schemas30.0.0-beta.3indirect
npm@jest/source-map29.6.3indirect
npm@jest/test-result29.7.0indirect
npm@jest/test-sequencer29.7.0indirect
npm@jest/transform29.7.0indirect
npm@jest/types29.6.3indirect
npm@jest/types30.0.0-beta.3indirect
npm@jridgewell/gen-mapping0.3.8indirect
npm@jridgewell/resolve-uri3.1.2indirect
npm@jridgewell/set-array1.2.1indirect
npm@jridgewell/sourcemap-codec1.4.15indirect
npm@jridgewell/trace-mapping0.3.25indirect
npm@jridgewell/trace-mapping0.3.9indirect
npm@nodelib/fs.scandir2.1.5indirect
npm@nodelib/fs.stat2.0.5indirect
npm@nodelib/fs.walk1.2.8indirect
npm@sinclair/typebox0.27.8indirect
npm@sinclair/typebox0.34.33indirect
npm@sinonjs/commons3.0.1indirect
npm@sinonjs/fake-timers10.3.0indirect
npm@sinonjs/fake-timers13.0.5indirect
npm@testing-library/dom10.4.0indirect
npm@testing-library/react16.3.0indirect
npm@tsconfig/node101.0.11indirect
npm@tsconfig/node121.0.11indirect
npm@tsconfig/node141.0.3indirect
npm@tsconfig/node161.0.4indirect
npm@types/aria-query5.0.4indirect
npm@types/babel__core7.20.5indirect
npm@types/babel__generator7.27.0indirect
npm@types/babel__template7.4.4indirect
npm@types/babel__traverse7.20.7indirect
npm@types/graceful-fs4.1.9indirect
npm@types/istanbul-lib-coverage2.0.6indirect
npm@types/istanbul-lib-report3.0.3indirect
npm@types/istanbul-reports3.0.4indirect
npm@types/jest29.5.14indirect
npm@types/jsdom21.1.7indirect
npm@types/json50.0.29indirect
npm@types/node20.14.5indirect
npm@types/prop-types15.7.12indirect
npm@types/react18.3.3indirect
npm@types/stack-utils2.0.3indirect
npm@types/tough-cookie4.0.5indirect
npm@types/yargs17.0.33indirect
npm@types/yargs-parser21.0.3indirect
npm@typescript-eslint/eslint-plugin7.13.1indirect
npm@typescript-eslint/parser7.13.1indirect
npm@typescript-eslint/scope-manager7.13.1indirect
npm@typescript-eslint/type-utils7.13.1indirect
npm@typescript-eslint/types7.13.1indirect
npm@typescript-eslint/typescript-estree7.13.1indirect
npm@typescript-eslint/utils7.13.1indirect
npm@typescript-eslint/visitor-keys7.13.1indirect
npm@ungap/structured-clone1.2.0indirect
npmacorn8.12.0indirect
npmacorn-jsx5.3.2indirect
npmacorn-walk8.3.3indirect
npmagent-base7.1.3indirect
npmajv6.12.6indirect
npmansi-escapes4.3.2indirect
npmansi-escapes7.0.0indirect
npmansi-regex5.0.1indirect
npmansi-regex6.1.0indirect
npmansi-styles4.3.0indirect
npmansi-styles5.2.0indirect
npmansi-styles6.2.1indirect
npmanymatch3.1.3indirect
npmarg4.1.3indirect
npmargparse1.0.10indirect
npmargparse2.0.1indirect
npmaria-query5.3.0indirect
npmarray-buffer-byte-length1.0.1indirect
npmarray-includes3.1.8indirect
npmarray-union2.1.0indirect
npmarray.prototype.findlast1.2.5indirect
npmarray.prototype.findlastindex1.2.5indirect
npmarray.prototype.flat1.3.2indirect
npmarray.prototype.flatmap1.3.2indirect
npmarray.prototype.toreversed1.1.2indirect
npmarray.prototype.tosorted1.1.4indirect
npmarraybuffer.prototype.slice1.0.3indirect
npmasync3.2.6indirect
npmavailable-typed-arrays1.0.7indirect
npmbabel-jest29.7.0indirect
npmbabel-plugin-istanbul6.1.1indirect
npmbabel-plugin-jest-hoist29.6.3indirect
npmbabel-preset-current-node-syntax1.1.0indirect
npmbabel-preset-jest29.6.3indirect
npmbalanced-match1.0.2indirect
npmbrace-expansion1.1.11indirect
npmbrace-expansion2.1.1indirect
npmbraces3.0.3indirect
npmbrowserslist4.25.0indirect
npmbs-logger0.2.6indirect
npmbser2.1.1indirect
npmbuffer-from1.1.2indirect
npmcall-bind1.0.7indirect
npmcallsites3.1.0indirect
npmcamelcase5.3.1indirect
npmcamelcase6.3.0indirect
npmcaniuse-lite1.0.30001720indirect
npmchalk4.1.2indirect
npmchalk5.4.1indirect
npmchar-regex1.0.2indirect
npmci-info3.9.0indirect
npmci-info4.2.0indirect
npmcjs-module-lexer1.4.3indirect
npmcli-cursor5.0.0indirect
npmcli-truncate4.0.0indirect
npmcliui8.0.1indirect
npmco4.6.0indirect
npmcollect-v8-coverage1.0.2indirect
npmcolor-convert2.0.1indirect
npmcolor-name1.1.4indirect
npmcolorette2.0.20indirect
npmcommander14.0.0indirect
npmconcat-map0.0.1indirect
npmconvert-source-map2.0.0indirect
npmcreate-jest29.7.0indirect
npmcreate-require1.1.1indirect
npmcross-spawn7.0.6indirect
npmcssstyle4.3.1indirect
npmcsstype3.1.3indirect
npmdata-urls5.0.0indirect
npmdata-view-buffer1.0.1indirect
npmdata-view-byte-length1.0.1indirect
npmdata-view-byte-offset1.0.0indirect
npmdebug3.2.7indirect
npmdebug4.4.1indirect
npmdecimal.js10.5.0indirect
npmdedent1.6.0indirect
npmdeep-is0.1.4indirect
npmdeepmerge4.3.1indirect
npmdefine-data-property1.1.4indirect
npmdefine-properties1.2.1indirect
npmdequal2.0.3indirect
npmdetect-newline3.1.0indirect
npmdiff4.0.2indirect
npmdiff-sequences29.6.3indirect
npmdir-glob3.0.1indirect
npmdoctrine2.1.0indirect
npmdoctrine3.0.0indirect
npmdom-accessibility-api0.5.16indirect
npmejs3.1.10indirect
npmelectron-to-chromium1.5.161indirect
npmemittery0.13.1indirect
npmemoji-regex10.4.0indirect
npmemoji-regex8.0.0indirect
npmentities6.0.0indirect
npmenvironment1.1.0indirect
npmerror-ex1.3.2indirect
npmes-abstract1.23.3indirect
npmes-define-property1.0.0indirect
npmes-errors1.3.0indirect
npmes-iterator-helpers1.0.19indirect
npmes-object-atoms1.0.0indirect
npmes-set-tostringtag2.0.3indirect
npmes-shim-unscopables1.0.2indirect
npmes-to-primitive1.2.1indirect
npmesbuild0.28.1indirect
npmescalade3.2.0indirect
npmescape-string-regexp2.0.0indirect
npmescape-string-regexp4.0.0indirect
npmeslint8.57.0indirect
npmeslint-import-resolver-node0.3.9indirect
npmeslint-module-utils2.8.1indirect
npmeslint-plugin-header3.1.1indirect
npmeslint-plugin-import2.29.1indirect
npmeslint-plugin-react7.34.2indirect
npmeslint-plugin-react-hooks4.6.2indirect
npmeslint-plugin-security3.0.1indirect
npmeslint-scope7.2.2indirect
npmeslint-visitor-keys3.4.3indirect
npmespree9.6.1indirect
npmesprima4.0.1indirect
npmesquery1.5.0indirect
npmesrecurse4.3.0indirect
npmestraverse5.3.0indirect
npmesutils2.0.3indirect
npmeventemitter35.0.1indirect
npmexeca5.1.1indirect
npmexit0.1.2indirect
npmexpect29.7.0indirect
npmfast-deep-equal3.1.3indirect
npmfast-glob3.3.2indirect
npmfast-json-stable-stringify2.1.0indirect
npmfast-levenshtein2.0.6indirect
npmfastq1.17.1indirect
npmfb-watchman2.0.2indirect
npmfile-entry-cache6.0.1indirect
npmfilelist1.0.4indirect
npmfill-range7.1.1indirect
npmfind-up4.1.0indirect
npmfind-up5.0.0indirect
npmflat-cache3.2.0indirect
npmflatted3.4.2indirect
npmfor-each0.3.3indirect
npmfs.realpath1.0.0indirect
npmfsevents2.3.3indirect
npmfunction-bind1.1.2indirect
npmfunction.prototype.name1.1.6indirect
npmfunctions-have-names1.2.3indirect
npmgensync1.0.0-beta.2indirect
npmget-caller-file2.0.5indirect
npmget-east-asian-width1.3.0indirect
npmget-intrinsic1.2.4indirect
npmget-package-type0.1.0indirect
npmget-stream6.0.1indirect
npmget-symbol-description1.0.2indirect
npmglob7.2.3indirect
npmglob-parent5.1.2indirect
npmglob-parent6.0.2indirect
npmglobals11.12.0indirect
npmglobals13.24.0indirect
npmglobalthis1.0.4indirect
npmglobby11.1.0indirect
npmgopd1.0.1indirect
npmgraceful-fs4.2.11indirect
npmgraphemer1.4.0indirect
npmhas-bigints1.0.2indirect
npmhas-flag4.0.0indirect
npmhas-property-descriptors1.0.2indirect
npmhas-proto1.0.3indirect
npmhas-symbols1.0.3indirect
npmhas-tostringtag1.0.2indirect
npmhasown2.0.2indirect
npmhtml-encoding-sniffer4.0.0indirect
npmhtml-escaper2.0.2indirect
npmhttp-proxy-agent7.0.2indirect
npmhttps-proxy-agent7.0.6indirect
npmhuman-signals2.1.0indirect
npmhusky9.1.7indirect
npmiconv-lite0.6.3indirect
npmignore5.3.1indirect
npmimport-fresh3.3.0indirect
npmimport-local3.2.0indirect
npmimurmurhash0.1.4indirect
npminflight1.0.6indirect
npminherits2.0.4indirect
npminternal-slot1.0.7indirect
npmis-array-buffer3.0.4indirect
npmis-arrayish0.2.1indirect
npmis-async-function2.0.0indirect
npmis-bigint1.0.4indirect
npmis-boolean-object1.1.2indirect
npmis-callable1.2.7indirect
npmis-core-module2.13.1indirect
npmis-data-view1.0.1indirect
npmis-date-object1.0.5indirect
npmis-extglob2.1.1indirect
npmis-finalizationregistry1.0.2indirect
npmis-fullwidth-code-point3.0.0indirect
npmis-fullwidth-code-point4.0.0indirect
npmis-fullwidth-code-point5.0.0indirect
npmis-generator-fn2.1.0indirect
npmis-generator-function1.0.10indirect
npmis-glob4.0.3indirect
npmis-map2.0.3indirect
npmis-negative-zero2.0.3indirect
npmis-number7.0.0indirect
npmis-number-object1.0.7indirect
npmis-path-inside3.0.3indirect
npmis-potential-custom-element-name1.0.1indirect
npmis-regex1.1.4indirect
npmis-set2.0.3indirect
npmis-shared-array-buffer1.0.3indirect
npmis-stream2.0.1indirect
npmis-string1.0.7indirect
npmis-symbol1.0.4indirect
npmis-typed-array1.1.13indirect
npmis-weakmap2.0.2indirect
npmis-weakref1.0.2indirect
npmis-weakset2.0.3indirect
npmisarray2.0.5indirect
npmisexe2.0.0indirect
npmistanbul-lib-coverage3.2.2indirect
npmistanbul-lib-instrument5.2.1indirect
npmistanbul-lib-instrument6.0.3indirect
npmistanbul-lib-report3.0.1indirect
npmistanbul-lib-source-maps4.0.1indirect
npmistanbul-reports3.1.7indirect
npmiterator.prototype1.1.2indirect
npmjake10.9.2indirect
npmjest29.7.0indirect
npmjest-changed-files29.7.0indirect
npmjest-circus29.7.0indirect
npmjest-cli29.7.0indirect
npmjest-config29.7.0indirect
npmjest-diff29.7.0indirect
npmjest-docblock29.7.0indirect
npmjest-each29.7.0indirect
npmjest-environment-jsdom30.0.0-beta.3indirect
npmjest-environment-node29.7.0indirect
npmjest-get-type29.6.3indirect
npmjest-haste-map29.7.0indirect
npmjest-leak-detector29.7.0indirect
npmjest-localstorage-mock2.4.26indirect
npmjest-matcher-utils29.7.0indirect
npmjest-message-util29.7.0indirect
npmjest-message-util30.0.0-beta.3indirect
npmjest-mock29.7.0indirect
npmjest-mock30.0.0-beta.3indirect
npmjest-pnp-resolver1.2.3indirect
npmjest-regex-util29.6.3indirect
npmjest-regex-util30.0.0-beta.3indirect
npmjest-resolve29.7.0indirect
npmjest-resolve-dependencies29.7.0indirect
npmjest-runner29.7.0indirect
npmjest-runtime29.7.0indirect
npmjest-snapshot29.7.0indirect
npmjest-util29.7.0indirect
npmjest-util30.0.0-beta.3indirect
npmjest-validate29.7.0indirect
npmjest-watcher29.7.0indirect
npmjest-worker29.7.0indirect
npmjs-tokens4.0.0indirect
npmjs-yaml3.14.2indirect
npmjs-yaml4.1.1indirect
npmjsdom26.1.0indirect
npmjsesc3.1.0indirect
npmjson-buffer3.0.1indirect
npmjson-parse-even-better-errors2.3.1indirect
npmjson-schema-traverse0.4.1indirect
npmjson-stable-stringify-without-jsonify1.0.1indirect
npmjson51.0.2indirect
npmjson52.2.3indirect
npmjsx-ast-utils3.3.5indirect
npmkeyv4.5.4indirect
npmkleur3.0.3indirect
npmleven3.1.0indirect
npmlevn0.4.1indirect
npmlilconfig3.1.3indirect
npmlines-and-columns1.2.4indirect
npmlint-staged16.1.2indirect
npmlistr28.3.3indirect
npmlocate-path5.0.0indirect
npmlocate-path6.0.0indirect
npmlodash.memoize4.1.2indirect
npmlodash.merge4.6.2indirect
npmlog-update6.1.0indirect
npmloose-envify1.4.0indirect
npmlru-cache10.4.3indirect
npmlru-cache5.1.1indirect
npmlz-string1.5.0indirect
npmmake-dir4.0.0indirect
npmmake-error1.3.6indirect
npmmakeerror1.0.12indirect
npmmerge-stream2.0.0indirect
npmmerge21.4.1indirect
npmmicromatch4.0.8indirect
npmmimic-fn2.1.0indirect
npmmimic-function5.0.1indirect
npmminimatch3.1.5indirect
npmminimatch5.1.9indirect
npmminimatch9.0.9indirect
npmminimist1.2.8indirect
npmms2.1.3indirect
npmnano-spawn1.0.2indirect
npmnatural-compare1.4.0indirect
npmnode-int640.4.0indirect
npmnode-releases2.0.19indirect
npmnofilter3.1.0indirect
npmnormalize-path3.0.0indirect
npmnpm-run-path4.0.1indirect
npmnwsapi2.2.20indirect
npmobject-assign4.1.1indirect
npmobject-inspect1.13.1indirect
npmobject-keys1.1.1indirect
npmobject.assign4.1.5indirect
npmobject.entries1.1.8indirect
npmobject.fromentries2.0.8indirect
npmobject.groupby1.0.3indirect
npmobject.hasown1.1.4indirect
npmobject.values1.2.0indirect
npmonce1.4.0indirect
npmonetime5.1.2indirect
npmonetime7.0.0indirect
npmoptionator0.9.4indirect
npmp-limit2.3.0indirect
npmp-limit3.1.0indirect
npmp-locate4.1.0indirect
npmp-locate5.0.0indirect
npmp-try2.2.0indirect
npmparent-module1.0.1indirect
npmparse-json5.2.0indirect
npmparse57.3.0indirect
npmpath-exists4.0.0indirect
npmpath-is-absolute1.0.1indirect
npmpath-key3.1.1indirect
npmpath-parse1.0.7indirect
npmpath-type4.0.0indirect
npmpicocolors1.1.1indirect
npmpicomatch2.3.2indirect
npmpicomatch4.0.4indirect
npmpidtree0.6.0indirect
npmpirates4.0.7indirect
npmpkg-dir4.2.0indirect
npmpossible-typed-array-names1.0.0indirect
npmprelude-ls1.2.1indirect
npmprettier3.3.2indirect
npmpretty-format27.5.1indirect
npmpretty-format29.7.0indirect
npmpretty-format30.0.0-beta.3indirect
npmprompts2.4.2indirect
npmprop-types15.8.1indirect
npmpunycode2.3.1indirect
npmpure-rand6.1.0indirect
npmqueue-microtask1.2.3indirect
npmreact18.3.1indirect
npmreact-dom18.3.1indirect
npmreact-is16.13.1indirect
npmreact-is17.0.2indirect
npmreact-is18.3.1indirect
npmreflect.getprototypeof1.0.6indirect
npmregexp-tree0.1.27indirect
npmregexp.prototype.flags1.5.2indirect
npmrequire-directory2.1.1indirect
npmresolve1.22.8indirect
npmresolve2.0.0-next.5indirect
npmresolve-cwd3.0.0indirect
npmresolve-from4.0.0indirect
npmresolve-from5.0.0indirect
npmresolve.exports2.0.3indirect
npmrestore-cursor5.1.0indirect
npmreusify1.0.4indirect
npmrfdc1.4.1indirect
npmrimraf3.0.2indirect
npmrrweb-cssom0.8.0indirect
npmrun-parallel1.2.0indirect
npmsafe-array-concat1.1.2indirect
npmsafe-regex2.1.1indirect
npmsafe-regex-test1.0.3indirect
npmsafer-buffer2.1.2indirect
npmsaxes6.0.0indirect
npmscheduler0.23.2indirect
npmsemver6.3.1indirect
npmsemver7.6.2indirect
npmsemver7.7.2indirect
npmset-function-length1.2.2indirect
npmset-function-name2.0.2indirect
npmshebang-command2.0.0indirect
npmshebang-regex3.0.0indirect
npmside-channel1.0.6indirect
npmsignal-exit3.0.7indirect
npmsignal-exit4.1.0indirect
npmsisteransi1.0.5indirect
npmslash3.0.0indirect
npmslice-ansi5.0.0indirect
npmslice-ansi7.1.0indirect
npmsource-map0.6.1indirect
npmsource-map-support0.5.13indirect
npmsprintf-js1.0.3indirect
npmstack-utils2.0.6indirect
npmstring-argv0.3.2indirect
npmstring-length4.0.2indirect
npmstring-width4.2.3indirect
npmstring-width7.2.0indirect
npmstring.prototype.matchall4.0.11indirect
npmstring.prototype.trim1.2.9indirect
npmstring.prototype.trimend1.0.8indirect
npmstring.prototype.trimstart1.0.8indirect
npmstrip-ansi6.0.1indirect
npmstrip-ansi7.1.0indirect
npmstrip-bom3.0.0indirect
npmstrip-bom4.0.0indirect
npmstrip-final-newline2.0.0indirect
npmstrip-json-comments3.1.1indirect
npmsupports-color7.2.0indirect
npmsupports-color8.1.1indirect
npmsupports-preserve-symlinks-flag1.0.0indirect
npmsymbol-tree3.2.4indirect
npmtest-exclude6.0.0indirect
npmtext-table0.2.0indirect
npmtldts6.1.86indirect
npmtldts-core6.1.86indirect
npmtmpl1.0.5indirect
npmto-regex-range5.0.1indirect
npmtough-cookie5.1.2indirect
npmtr465.1.1indirect
npmts-api-utils1.3.0indirect
npmts-jest29.3.4indirect
npmts-node10.9.2indirect
npmtsconfig-paths3.15.0indirect
npmtype-check0.4.0indirect
npmtype-detect4.0.8indirect
npmtype-fest0.20.2indirect
npmtype-fest0.21.3indirect
npmtype-fest4.41.0indirect
npmtyped-array-buffer1.0.2indirect
npmtyped-array-byte-length1.0.1indirect
npmtyped-array-byte-offset1.0.2indirect
npmtyped-array-length1.0.6indirect
npmtypescript5.4.5indirect
npmunbox-primitive1.0.2indirect
npmundici-types5.26.5indirect
npmupdate-browserslist-db1.1.3indirect
npmuri-js4.4.1indirect
npmv8-compile-cache-lib3.0.1indirect
npmv8-to-istanbul9.3.0indirect
npmw3c-xmlserializer5.0.0indirect
npmwalker1.0.8indirect
npmwebidl-conversions7.0.0indirect
npmwhatwg-encoding3.1.1indirect
npmwhatwg-mimetype4.0.0indirect
npmwhatwg-url14.2.0indirect
npmwhich2.0.2indirect
npmwhich-boxed-primitive1.0.2indirect
npmwhich-builtin-type1.1.3indirect
npmwhich-collection1.0.2indirect
npmwhich-typed-array1.1.15indirect
npmword-wrap1.2.5indirect
npmwrap-ansi7.0.0indirect
npmwrap-ansi9.0.0indirect
npmwrappy1.0.2indirect
npmwrite-file-atomic4.0.2indirect
npmws8.18.2indirect
npmxml-name-validator5.0.0indirect
npmxmlchars2.2.0indirect
npmy18n5.0.8indirect
npmyallist3.1.1indirect
npmyaml2.8.0indirect
npmyargs17.7.2indirect
npmyargs-parser21.1.1indirect
npmyn3.1.1indirect
npmyocto-queue0.1.0indirect
Dependency advisories 0

Installing npm:@joinmeow/cognito-passwordless-auth@1.0.104 pulls in 3 packages, direct and transitive: 0 carry known advisories, of which 0 are direct dependencies.

No known advisories affect the assessed dependencies.

An advisory means the version recorded in the dependency graph falls inside an advisory’s affected range. Reachability is not analysed, and the graph includes development and test pins — a finding may concern tooling rather than shipped software.

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": true,
      "size_kb": 23630,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "JavaScript": 4487,
        "TypeScript": 1136056
      },
      "pushed_at": "2026-07-23T16:22:55Z",
      "created_at": "2025-04-22T14:39:53Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-23T16:24:17Z",
      "description": "Passwordless authentication with Amazon Cognito: FIDO2 (WebAuthn, support for Passkeys), Totp MFA,  Totp and Passkey Step Up",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": "www.meow.com",
      "name": "Meow",
      "type": "Organization",
      "login": "joinmeow",
      "company": null,
      "location": "United States of America",
      "followers": 4,
      "avatar_url": "https://avatars.githubusercontent.com/u/78460202?v=4",
      "created_at": "2021-02-03T03:32:11Z",
      "is_verified": null,
      "public_repos": 4,
      "account_age_days": 2000
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": false
    },
    "activity": {
      "releases": [
        {
          "tag": "v1.0.104",
          "kind": "patch",
          "published_at": "2026-07-20T22:36:18Z"
        },
        {
          "tag": "v1.0.103",
          "kind": "patch",
          "published_at": "2026-07-17T18:24:38Z"
        },
        {
          "tag": "v1.0.102",
          "kind": "patch",
          "published_at": "2026-06-24T02:04:29Z"
        },
        {
          "tag": "v1.0.101",
          "kind": "patch",
          "published_at": "2026-06-23T20:34:07Z"
        },
        {
          "tag": "v1.0.100",
          "kind": "patch",
          "published_at": "2026-06-17T17:26:46Z"
        },
        {
          "tag": "v1.0.99",
          "kind": "patch",
          "published_at": "2026-05-31T15:49:03Z"
        },
        {
          "tag": "v1.0.98",
          "kind": "patch",
          "published_at": "2025-11-04T18:22:08Z"
        },
        {
          "tag": "v1.0.97",
          "kind": "patch",
          "published_at": "2025-10-06T20:02:32Z"
        },
        {
          "tag": "v1.0.96",
          "kind": "patch",
          "published_at": "2025-10-06T15:42:06Z"
        },
        {
          "tag": "v1.0.95",
          "kind": "patch",
          "published_at": "2025-10-05T19:50:05Z"
        },
        {
          "tag": "v1.0.94",
          "kind": "patch",
          "published_at": "2025-10-03T00:04:41Z"
        },
        {
          "tag": "v1.0.92",
          "kind": "patch",
          "published_at": "2025-10-02T22:13:38Z"
        },
        {
          "tag": "v1.0.91",
          "kind": "patch",
          "published_at": "2025-10-02T21:53:37Z"
        },
        {
          "tag": "v1.0.90",
          "kind": "patch",
          "published_at": "2025-09-09T20:17:24Z"
        },
        {
          "tag": "v1.0.88",
          "kind": "patch",
          "published_at": "2025-07-28T15:12:46Z"
        },
        {
          "tag": "v1.0.87",
          "kind": "patch",
          "published_at": "2025-07-23T13:32:39Z"
        },
        {
          "tag": "v1.0.86",
          "kind": "patch",
          "published_at": "2025-07-23T12:02:57Z"
        },
        {
          "tag": "v1.0.85",
          "kind": "patch",
          "published_at": "2025-07-22T19:16:58Z"
        },
        {
          "tag": "v1.0.84",
          "kind": "patch",
          "published_at": "2025-07-22T18:32:27Z"
        },
        {
          "tag": "v1.0.83",
          "kind": "patch",
          "published_at": "2025-07-20T22:05:13Z"
        },
        {
          "tag": "v1.0.82",
          "kind": "patch",
          "published_at": "2025-07-20T16:09:18Z"
        },
        {
          "tag": "v1.0.81",
          "kind": "patch",
          "published_at": "2025-07-08T18:20:39Z"
        },
        {
          "tag": "v1.0.80",
          "kind": "patch",
          "published_at": "2025-06-09T21:00:10Z"
        },
        {
          "tag": "v1.0.79",
          "kind": "patch",
          "published_at": "2025-06-09T01:33:45Z"
        },
        {
          "tag": "v1.0.78",
          "kind": "patch",
          "published_at": "2025-06-09T01:25:02Z"
        },
        {
          "tag": "v1.0.77",
          "kind": "patch",
          "published_at": "2025-06-09T00:28:16Z"
        },
        {
          "tag": "v1.0.76",
          "kind": "patch",
          "published_at": "2025-06-08T23:25:12Z"
        },
        {
          "tag": "v1.0.75",
          "kind": "patch",
          "published_at": "2025-06-08T22:49:40Z"
        },
        {
          "tag": "v1.0.74",
          "kind": "patch",
          "published_at": "2025-06-08T22:39:31Z"
        },
        {
          "tag": "v1.0.73",
          "kind": "patch",
          "published_at": "2025-06-08T22:32:48Z"
        },
        {
          "tag": "v1.0.72",
          "kind": "patch",
          "published_at": "2025-06-08T22:03:35Z"
        },
        {
          "tag": "v1.0.71",
          "kind": "patch",
          "published_at": "2025-05-30T02:03:25Z"
        },
        {
          "tag": "v1.0.70",
          "kind": "patch",
          "published_at": "2025-05-28T22:24:59Z"
        },
        {
          "tag": "v1.0.69",
          "kind": "patch",
          "published_at": "2025-05-18T17:25:59Z"
        },
        {
          "tag": "v1.0.68",
          "kind": "patch",
          "published_at": "2025-05-18T13:13:07Z"
        },
        {
          "tag": "v1.0.67",
          "kind": "patch",
          "published_at": "2025-05-17T20:31:59Z"
        },
        {
          "tag": "v1.0.66",
          "kind": "patch",
          "published_at": "2025-05-17T18:54:51Z"
        },
        {
          "tag": "v1.0.65",
          "kind": "patch",
          "published_at": "2025-05-17T15:08:16Z"
        },
        {
          "tag": "v1.0.64",
          "kind": "patch",
          "published_at": "2025-05-17T14:41:50Z"
        },
        {
          "tag": "v1.0.63",
          "kind": "patch",
          "published_at": "2025-05-16T21:54:47Z"
        },
        {
          "tag": "v1.0.62",
          "kind": "patch",
          "published_at": "2025-05-16T19:58:44Z"
        },
        {
          "tag": "v1.0.61",
          "kind": "patch",
          "published_at": "2025-05-16T19:31:04Z"
        },
        {
          "tag": "v1.0.60",
          "kind": "patch",
          "published_at": "2025-05-16T18:31:56Z"
        },
        {
          "tag": "v1.0.59",
          "kind": "patch",
          "published_at": "2025-05-16T17:51:25Z"
        },
        {
          "tag": "v1.0.58",
          "kind": "patch",
          "published_at": "2025-05-16T17:19:30Z"
        },
        {
          "tag": "v1.0.57",
          "kind": "patch",
          "published_at": "2025-05-16T02:27:24Z"
        },
        {
          "tag": "v1.0.56",
          "kind": "patch",
          "published_at": "2025-05-16T01:10:06Z"
        },
        {
          "tag": "v1.0.55",
          "kind": "patch",
          "published_at": "2025-05-15T15:57:07Z"
        },
        {
          "tag": "v1.0.54",
          "kind": "patch",
          "published_at": "2025-05-15T15:43:32Z"
        },
        {
          "tag": "v1.0.53",
          "kind": "patch",
          "published_at": "2025-05-15T01:15:08Z"
        },
        {
          "tag": "v1.0.52",
          "kind": "patch",
          "published_at": "2025-05-13T20:43:51Z"
        },
        {
          "tag": "v1.0.51",
          "kind": "patch",
          "published_at": "2025-05-13T12:34:24Z"
        },
        {
          "tag": "v1.0.50",
          "kind": "patch",
          "published_at": "2025-05-12T22:17:31Z"
        },
        {
          "tag": "v1.0.49",
          "kind": "patch",
          "published_at": "2025-05-10T18:47:14Z"
        },
        {
          "tag": "v1.0.48",
          "kind": "patch",
          "published_at": "2025-05-10T17:32:48Z"
        },
        {
          "tag": "v1.0.47",
          "kind": "patch",
          "published_at": "2025-05-09T23:17:15Z"
        },
        {
          "tag": "v1.0.46",
          "kind": "patch",
          "published_at": "2025-05-09T18:00:53Z"
        },
        {
          "tag": "v1.0.45",
          "kind": "patch",
          "published_at": "2025-05-09T16:15:05Z"
        },
        {
          "tag": "v1.0.44",
          "kind": "patch",
          "published_at": "2025-05-09T15:27:02Z"
        },
        {
          "tag": "v1.0.43",
          "kind": "patch",
          "published_at": "2025-05-09T13:46:53Z"
        },
        {
          "tag": "v1.0.42",
          "kind": "patch",
          "published_at": "2025-05-09T13:36:04Z"
        },
        {
          "tag": "v1.0.41",
          "kind": "patch",
          "published_at": "2025-05-09T12:42:14Z"
        },
        {
          "tag": "v1.0.40",
          "kind": "patch",
          "published_at": "2025-05-09T12:28:33Z"
        },
        {
          "tag": "v1.0.39",
          "kind": "patch",
          "published_at": "2025-05-09T02:08:42Z"
        },
        {
          "tag": "v1.0.38",
          "kind": "patch",
          "published_at": "2025-05-09T01:50:24Z"
        },
        {
          "tag": "v1.0.37",
          "kind": "patch",
          "published_at": "2025-05-09T01:28:47Z"
        },
        {
          "tag": "v1.0.36",
          "kind": "patch",
          "published_at": "2025-05-09T01:14:20Z"
        },
        {
          "tag": "v1.0.35",
          "kind": "patch",
          "published_at": "2025-05-09T00:43:19Z"
        },
        {
          "tag": "v1.0.34",
          "kind": "patch",
          "published_at": "2025-05-09T00:00:09Z"
        },
        {
          "tag": "v1.0.33",
          "kind": "patch",
          "published_at": "2025-05-08T23:05:08Z"
        },
        {
          "tag": "v1.0.32",
          "kind": "patch",
          "published_at": "2025-05-08T19:10:49Z"
        },
        {
          "tag": "v1.0.31",
          "kind": "patch",
          "published_at": "2025-05-08T18:15:39Z"
        },
        {
          "tag": "v1.0.30",
          "kind": "patch",
          "published_at": "2025-05-07T01:33:16Z"
        },
        {
          "tag": "v1.0.29",
          "kind": "patch",
          "published_at": "2025-05-06T23:37:16Z"
        },
        {
          "tag": "v1.0.28",
          "kind": "patch",
          "published_at": "2025-05-06T22:15:53Z"
        },
        {
          "tag": "v1.0.27",
          "kind": "patch",
          "published_at": "2025-05-06T21:03:22Z"
        },
        {
          "tag": "v1.0.26",
          "kind": "patch",
          "published_at": "2025-05-06T19:23:16Z"
        },
        {
          "tag": "v1.0.25",
          "kind": "patch",
          "published_at": "2025-05-06T18:59:43Z"
        },
        {
          "tag": "v1.0.24",
          "kind": "patch",
          "published_at": "2025-05-06T18:24:46Z"
        },
        {
          "tag": "v1.0.23",
          "kind": "patch",
          "published_at": "2025-05-06T17:40:15Z"
        },
        {
          "tag": "v1.0.22",
          "kind": "patch",
          "published_at": "2025-05-06T16:23:22Z"
        },
        {
          "tag": "v1.0.21",
          "kind": "patch",
          "published_at": "2025-05-06T13:38:10Z"
        },
        {
          "tag": "v1.0.20",
          "kind": "patch",
          "published_at": "2025-05-05T19:22:29Z"
        },
        {
          "tag": "v1.0.19",
          "kind": "patch",
          "published_at": "2025-05-05T16:29:37Z"
        },
        {
          "tag": "v1.0.18",
          "kind": "patch",
          "published_at": "2025-05-05T12:35:20Z"
        },
        {
          "tag": "v1.0.17",
          "kind": "patch",
          "published_at": "2025-05-04T20:03:20Z"
        },
        {
          "tag": "v1.0.16",
          "kind": "patch",
          "published_at": "2025-05-02T20:52:39Z"
        },
        {
          "tag": "v1.0.15",
          "kind": "patch",
          "published_at": "2025-05-02T20:19:30Z"
        },
        {
          "tag": "v1.0.14",
          "kind": "patch",
          "published_at": "2025-05-02T19:59:33Z"
        },
        {
          "tag": "v1.0.13",
          "kind": "patch",
          "published_at": "2025-05-01T16:19:53Z"
        },
        {
          "tag": "v1.0.12",
          "kind": "patch",
          "published_at": "2025-05-01T12:34:20Z"
        },
        {
          "tag": "v1.0.11",
          "kind": "patch",
          "published_at": "2025-04-24T23:51:58Z"
        },
        {
          "tag": "v1.0.10",
          "kind": "patch",
          "published_at": "2025-04-24T18:32:54Z"
        },
        {
          "tag": "v1.0.9",
          "kind": "patch",
          "published_at": "2025-04-24T18:07:35Z"
        },
        {
          "tag": "v1.0.8",
          "kind": "patch",
          "published_at": "2025-04-24T17:30:56Z"
        },
        {
          "tag": "v1.0.7",
          "kind": "patch",
          "published_at": "2025-04-24T16:40:20Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "2ddce40e8a2b8cce16f32bf03fd4b5051de26594",
          "body": "cognitoIdpEndpoint is the target for every cognito-idp API call\n(InitiateAuth, RespondToAuthChallenge, GetTokensFromRefreshToken,\nRevokeToken, GetUser, SignUp, ChangePassword, ...). Passwords\n(USER_PASSWORD_AUTH), SRP parameters, refresh/access tokens and any\noptional clientSecret are POSTed to it, \n[…]\ning hostedUi.domain http:// rejection. Bare AWS region shorthand\n(e.g. eu-west-1) is unaffected — it is handled by the auto-prefix path.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)",
          "is_bot": false,
          "headline": "fix(security): require https for cognitoIdpEndpoint (#110)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-07-23T16:22:55Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "72e1fd04e0be2667d7c69e2b563d5017fb215ab9",
          "body": "fido2.baseUrl is the base URL for every FIDO2 backend API call\n(register passkey, list/delete credentials). The user's ID token is sent\nas an `Authorization: Bearer <idToken>` header to that URL, so a\nplaintext http:// base would expose the token in transit.\n\nconfigure() validated hostedUi.domain ag\n[…]\n plaintext http:// fido2.baseUrl at\nconfigure() time, mirroring the existing hostedUi.domain http:// check\nin placement and error style.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)",
          "is_bot": false,
          "headline": "fix(security): require https for fido2.baseUrl (#111)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-07-23T16:22:27Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ac145cc518b432d2b3d4b454baa2ae1ee6f9c64a",
          "body": null,
          "is_bot": false,
          "headline": "Bump version from 1.0.103 to 1.0.104",
          "author_name": "GitHub Action",
          "author_login": "actions-user",
          "committed_at": "2026-07-20T22:35:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e87dfdffd03ab314c231f3d9108af2a6a74e2374",
          "body": "… scope (#108)\n\nHosted-UI / OAuth access tokens only carry the OAuth scopes that were\nrequested at sign-in. Cognito GetUser requires\naws.cognito.signin.user.admin, so for redirect sessions the MFA-status\nfetch fails deterministically with NotAuthorizedException and the hook\nretries it per token (and\n[…]\nser; without\nthe scope, publish the default TOTP status (disabled) and mark\nmfaStatusReady immediately. Same guard in refreshTotpMfaStatus.\nUnparseable tokens fail open and keep the previous behavior.",
          "is_bot": false,
          "headline": "fix(react): skip GetUser MFA-status fetch when token lacks user.admin…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-07-20T22:34:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ab3efa53ec4aa9d9441702ccc580c6c8a111baba",
          "body": null,
          "is_bot": false,
          "headline": "Bump version from 1.0.102 to 1.0.103",
          "author_name": "GitHub Action",
          "author_login": "actions-user",
          "committed_at": "2026-07-17T18:24:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "25fd5254cb20d30ce8403f74515ce3bb0da7826b",
          "body": "…t can't wedge auth (#107)\n\ncreateFetchWithRetry awaited fetch with no per-attempt timeout, so a black-holed\nconnection (TLS up, no response, no error) hung forever. Because auth requests\nrun on the critical sign-in/refresh path, one hung call — e.g. ConfirmDevice\nduring device confirmation, which r\n[…]\nast attempt). Default 25s; configurable via a\nnew createFetchWithRetry parameter. Applies to every Cognito call, so ConfirmDevice,\nRespondToAuthChallenge, and refresh all fail fast instead of hanging.",
          "is_bot": false,
          "headline": "fix(client): bound each fetch attempt with a timeout so a hung reques…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-07-17T18:20:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ccf3af1fca4bd1562ff01cd5bcabf7f46efc1dbe",
          "body": null,
          "is_bot": false,
          "headline": "Bump version from 1.0.101 to 1.0.102",
          "author_name": "GitHub Action",
          "author_login": "actions-user",
          "committed_at": "2026-06-24T02:04:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ba5e93fe4e0d3e407d94f5a7c99954acfd9a3f64",
          "body": "…ignal API (#106)\n\nWhen the relying party rejects a sign-in because it does not recognize the\npresented credential (a discoverable passkey revoked server-side but still\noffered at the login screen), Cognito returns a UserLambdaValidationException\ncarrying {\"reason\":\"unknown_credential\"}. authenticat\n[…]\n plus a produced assertion: cancels,\naborts, network/throttle failures, wrong signature, and generic NotAuthorized\nall keep the existing failure path, so a valid passkey is never signalled as\nunknown.",
          "is_bot": false,
          "headline": "feat(client): surface unknown-credential sign-in rejections for the S…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-24T02:03:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "de9d7afdbac03a3a37aa37aca8549faf3fb8c6ab",
          "body": null,
          "is_bot": false,
          "headline": "Bump version from 1.0.100 to 1.0.101",
          "author_name": "GitHub Action",
          "author_login": "actions-user",
          "committed_at": "2026-06-23T20:33:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "64ea8e32b66b70f06ab6289a942d7ffbfbcccbc5",
          "body": "* feat(client): add WebAuthn Signal API wrappers\n\nAdd signalAllAcceptedCredentials, signalUnknownCredential and\nsignalCurrentUserDetails over the W3C PublicKeyCredential.signal* static\nmethods. Each is feature-gated via getClientCapabilities() and no-ops where the\nbrowser lacks support. The WebAuthn\n[…]\nix rather than the current hostname.\nResolve the rpId from an explicit argument or the configured fido2.rp.id only,\nand no-op when neither is available rather than signalling against a guessed\ndomain.",
          "is_bot": false,
          "headline": "feat(client): add WebAuthn Signal API wrappers (#105)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-23T19:41:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e624ca2be4ba7ddcf578c378565a7a1f5eb13131",
          "body": null,
          "is_bot": false,
          "headline": "Bump version from 1.0.99 to 1.0.100",
          "author_name": "GitHub Action",
          "author_login": "actions-user",
          "committed_at": "2026-06-17T17:26:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6ff0a56ccaafc689b2df73e068e2f4e65ba5ba58",
          "body": "When another tab signs out it removes the Cognito token keys from\nstorage, firing a storage event in this tab. The handler only called\nloadTokens (which nulls tokens) but never dispatched SIGN_OUT, so\nper-user React state (totpMfaStatus, mfaStatusReady, deviceKey,\nauthMethod, ...) survived until the\n[…]\n removal and a LastAuthUser removal each reset\ndeviceKey/totpMfaStatus/mfaStatusReady; a token change (refresh) keeps\nthe user signed in with state intact. The removal tests fail on the\nprevious code.",
          "is_bot": false,
          "headline": "Reset per-user state on a cross-tab sign-out (#103)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-17T17:09:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "77436c4968b14db832cebb897cbf0e1825a1bf2c",
          "body": "…in (#100)\n\nThree small hardening fixes from the re-review's core-cleanups bucket:\n\n- initiateAuth no longer mutates the caller's authParameters object\n  (it set authParameters.DEVICE_KEY = deviceKey, which stuck on an\n  object reused across retry attempts). The device key is merged into\n  the reque\n[…]\nh sends DEVICE_KEY without mutating the caller's\nobject (incl. reuse across two calls); http:// hostedUi.domain throws;\na bare domain is accepted. The behaviour-change tests fail on the\nprevious code.",
          "is_bot": false,
          "headline": "Misc safety: no authParameters mutation, reject http:// hostedUi.doma…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-17T17:08:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e17e4cf3b509a17eb9e0e1734a1aabecdb1b64dd",
          "body": "* Retry transient renewal initiate in conditional FIDO2 flow\n\nThe conditional-mediation renewal loop re-initiates a fresh Cognito\nCUSTOM_AUTH challenge at the top of each iteration. A transient network\nfailure of that initiateFido2Challenge() call threw and killed the whole\nconditional-autofill flow\n[…]\nker pointing at a dead, superseded flow rather\nthan returning to \"no live conditional flow\". Restore only a still-live\nprevious flow, else clear to undefined, so the invariant (non-null ⇒ live)\nholds.",
          "is_bot": false,
          "headline": "Retry transient renewal initiate in conditional FIDO2 flow (#102)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-17T17:08:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1162e23c608e6a6c6c1185c272e49f2094923d86",
          "body": "* Track refresh failures and backoff retry timer per user\n\nMove consecutiveRefreshFailures from a module global into per-user\nRefreshState, and track the failure-backoff retry timer so it can be\ncancelled on sign-out / abort / forced refresh instead of firing for a\ntorn-down session. One user's repe\n[…]\nMap) could arm a retry nothing could cancel.\n\nCancel retryTimer in clearExistingTimer too, and bail the failure catch when\nthere is no username. Regression test added for the re-schedule cancellation.",
          "is_bot": false,
          "headline": "Track refresh failures and backoff retry timer per user (#101)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-17T17:08:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "090cd82d89396c579600d07d6b2a45531982b0f3",
          "body": "…104)\n\n* Rehydrate deviceKey from storage in the SRP and plaintext tokensCb\n\nThe FIDO2 sign-in tokensCb rehydrates the device key from the\nremembered-device record when the tokens don't carry one (since #64),\nbut the SRP and plaintext tokensCb did not: SRP only set deviceKey when\npresent, and plaint\n[…]\ntical FIDO2/SRP/plaintext rehydrate blocks (which diverged once — the\nbug the previous commit fixed) collapse into one shared rehydrateDeviceKey()\nhelper. Add a regression test for the cross-tab case.",
          "is_bot": false,
          "headline": "Rehydrate deviceKey from storage in the SRP and plaintext tokensCb (#…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-17T17:07:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "32215579e7dc3a376d5ad9893a4051780c6995ec",
          "body": "processTokens is the only thing that arms the next refresh, and it runs\nonly on a fresh sign-in / refresh — never on a page reload, where the\ntokens are read back from storage. So after a reload nothing scheduled\nthe next refresh until the +5-minute watchdog tick. With short access\ntokens (Cognito a\n[…]\nt.\n\nTest: a session restored from storage schedules a refresh on mount; the\nsigned-out case still calls scheduleRefresh (which no-ops). Both fail on\nthe previous code, which never scheduled on reload.",
          "is_bot": false,
          "headline": "Schedule a token refresh on page reload (#99)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-15T17:20:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cda691f78d9ad1c0af387b5594d52b28e00d1ef0",
          "body": "…#97)\n\nThree related warts in the processTokens scheduling machinery:\n\n1. Identity-checked schedule deletion. A completed refresh runs its\n   nested processTokens (which registers the NEXT schedule for the new\n   tokens) BEFORE the old schedule's tokensCb fires. The tokensCb\n   deleted the user's ac\n[…]\n: newDeviceMetadata=undefined schedules immediately (no deferral);\na real new device key defers 2 minutes; sign-out cancels a pending\ndeferral. The two behavior-change tests fail on the previous code.",
          "is_bot": false,
          "headline": "Fix processTokens refresh-scheduling dedup and fresh-login deferral (…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-15T17:15:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "899d1d336df59fde027f19db7c507094f573a549",
          "body": "…sions (#98)\n\n* Resolve CodeQL alerts: two polynomial-ReDoS regexes and workflow permissions\n\nCodeQL code-scanning flagged three open alerts:\n\n- HIGH js/polynomial-redos in client/config.ts (trailing-slash trim\n  /\\/+$/): replace with a linear backward scan. Backtracking on a long\n  run of \"/\" was p\n[…]\nrightmost one\nwith a non-empty suffix (and non-empty prefix), which is what the regex\nresolves to — still O(n), no backtracking. Verified equivalent to the\nregex across single- and multi-marker cases.",
          "is_bot": false,
          "headline": "Resolve CodeQL alerts: two polynomial-ReDoS regexes + workflow permis…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-15T17:14:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "93c2e55fa9790379267c4b187e3b43df1fb5fe01",
          "body": "Bumps the npm_and_yarn group with 1 update in the / directory: [esbuild](https://github.com/evanw/esbuild).\n\n\nUpdates `esbuild` from 0.25.8 to 0.28.1\n- [Release notes](https://github.com/evanw/esbuild/releases)\n- [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG-2025.md)\n- [Commits](h\n[…]\n dependency-type: indirect\n  dependency-group: npm_and_yarn\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump esbuild in the npm_and_yarn group across 1 directory (#90)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-15T17:07:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b02822e635fb47a9792008d018264d4a286fc8d9",
          "body": "…r (#96)\n\nOn a getUser error the hook retained the last-known MFA status, marked\nmfaStatusReady true, and scheduled a silent retry every ~7s by clearing\nthe token guard and nudging a re-run. There was no cap: a persistent\nfailure (network outage, or a backend that keeps erroring) retried\nforever.\n\nC\n[…]\nhile retries\nstop.\n\nTest: getUser failing every time yields exactly 1 initial + 3 retries =\n4 fetches then stops (the previous code kept polling); a token rotation\nresets the budget and fetches again.",
          "is_bot": false,
          "headline": "Cap the MFA-status fetch retry so a failing getUser can't poll foreve…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-15T16:52:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cc1c76821192f55d05a7bc341fa0f66109c9135c",
          "body": "* Honor an explicit advancedSecurity.region as an allowlist override\n\n#70 added a hardcoded allowlist of regions known to host the Advanced\nSecurity script and stopped defaulting unknown regions to us-east-1.\nBut it also gated an EXPLICITLY configured advancedSecurity.region\nbehind that allowlist, s\n[…]\n the allowlist. A malformed value is rejected outright rather than\nfalling through to the endpoint-derived region. Regression test loads a\nhost-injection region string and asserts nothing is injected.",
          "is_bot": false,
          "headline": "Honor an explicit advancedSecurity.region as an allowlist override (#95)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-15T16:38:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1482b75a02f0d181e6f0d6f32b03c4184723eadd",
          "body": "#92 widened the React OAuth-callback gate to also fire on an `error`\nparam so denied sign-ins surface instead of hanging silently. It checks\n`error` in both the query and the URL fragment, unconditionally.\n\nPer RFC 6749, response errors come back in the query for the code flow\n(§4.1.2.1) and in the \n[…]\n first — this just stops the spurious entry\nat the gate.\n\nTests: a code-flow fragment error no longer invokes the handler; an\nimplicit-flow fragment error still does and surfaces the provider message.",
          "is_bot": false,
          "headline": "Gate implicit-flow OAuth fragment errors to responseType \"token\" (#94)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-15T16:10:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "58c417acec1cd6d44d0fe9e09083a01f26b12b69",
          "body": "…dow (#93)\n\n* Close FIDO2 conditional renewal/takeover seam during the initiate window\n\nThe conditional-autofill renewal loop tracked takeovers only via\npendingConditionalGet, which exists solely while a navigator.credentials\n.get() is pending. Between renewal iterations — after the previous get()\ni\n[…]\nin once it has\nsuperseded the conditional one.\n\nTest: a conditional getter that performs a modal takeover and then\nresolves with a credential ends the flow with superseded=true rather\nthan completing.",
          "is_bot": false,
          "headline": "Close FIDO2 conditional renewal/takeover seam during the initiate win…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-15T16:08:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d49f2bf27b9ffa4b4548f269f419ba1f106b3abe",
          "body": "Two bugs in the hook's OAuth-callback effect:\n\n1. The gate only fired for code/access_token, so an error-only redirect\n   (user denied consent: ?error=access_denied with no code/token, in the\n   query for the code flow or the fragment for implicit) never invoked\n   handleCognitoOAuthCallback. The ha\n[…]\nGNED_IN; null result resolves to NOT_SIGNED_IN (not stuck at\nSIGNING_IN); tokens reach SIGNED_IN; a non-callback URL never invokes\nthe handler. The two behavior-change tests fail on the previous hook.",
          "is_bot": false,
          "headline": "Fix React OAuth callback gate for errors and stuck busy status (#92)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-15T15:37:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e227267b66592b2c50b3a8ac5d2831295e223b01",
          "body": "* Route forceRefreshTokens through the per-user refresh lock\n\nforceRefreshTokens (exposed by the React hook, called on a 401) passed\nforce:true, which conflated two concerns: skip the cross-tab dedup\ncheck AND bypass the per-user refresh lock. Bypassing the lock let a\nforced refresh race a concurren\n[…]\nes to a private\nperformRefresh that carries skipLock. Only the in-lock immediate-\nrefresh path calls performRefresh with skipLock:true. Verified the\ngenerated refresh.d.ts no longer mentions skipLock.",
          "is_bot": false,
          "headline": "Route forceRefreshTokens through the per-user refresh lock (#91)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-15T15:25:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e9b3b4ff7b5529a75303ede5eecd6fb990d22389",
          "body": "…an takeover (#89)\n\n* Fix sign-out and lock liveness: timeout fallback, heartbeat cap, orphan takeover\n\nThree liveness gaps around the cross-tab storage lock:\n\n1. signOut now catches LockTimeoutError and proceeds without the lock.\n   Previously another tab's heartbeat-renewed refresh lock made signO\n[…]\ned-token write) is\ncompensated; fresh sign-in clears a stale tombstone; the E2E\nhung-refresh race still passes. The signOut leftover-keys test now\nasserts the tombstone is the one deliberate survivor.",
          "is_bot": false,
          "headline": "Fix sign-out and lock liveness: timeout fallback, heartbeat cap, orph…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-15T14:32:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "af5251cf768cd8ce16308e9d1ef104e51f0a5a51",
          "body": "…#88)\n\nThe stale-device hardening added to the plaintext flow (#67) never\nreached its SRP sibling, leaving the worst behavior in the most-used\nflow: srp.ts sent device keys from placeholder records (no device\npassword), and a device forgotten server-side PERMANENTLY bricked SRP\nsign-in - every attem\n[…]\n-api.ts and device.ts import each\nother, and a requireActual factory re-enters that cycle and splits the\nmodule identity (device.ts ends up calling a different confirmDevice\nthan the test configured).",
          "is_bot": false,
          "headline": "Bring SRP flow to device-key parity; never persist unconfirmed keys (…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-12T16:37:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3a8a950e464f487dafaaafb8487f8636ea645f25",
          "body": "* Make refresh-bugs suite deterministic under parallel load\n\nThe suite failed ~25% of runs on loaded machines. Root cause:\nprocessTokens launches fire-and-forget scheduleRefresh chains whose\nhops (storage-lock jitter sleeps, poll loops) outlive the test that\nstarted them; with static imports a strag\n[…]\nfor isolation (they belong to the\ndiscarded module graph) but the teardown comment claimed otherwise.\nCancel each suite username's timers via cleanupUserRefreshState\nbefore resetting the module graph.",
          "is_bot": false,
          "headline": "Make refresh-bugs suite deterministic under parallel load (#87)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-11T15:31:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fa16ca3af307056f882b6aa84e478745686de989",
          "body": "* Add opt-in Hosted UI sign-out via signOutWithRedirect\n\nLocal signOut only clears storage and revokes the refresh token; the\nCognito Hosted UI (managed login) session cookie survives, so on a\nshared device the next signInWithRedirect within the hour silently\nsigns in as the previous user. Add an op\n[…]\ndow\nshrinks from a network round-trip to microtasks. Regular signOut\nordering is unchanged (local-first, so a network failure can never\nkeep a user signed in). Ordering pinned by tests for both modes.",
          "is_bot": false,
          "headline": "Add opt-in Hosted UI sign-out via signOutWithRedirect (#68)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-11T13:42:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ea8744ee16be560e641efb4ef8f98aeb605fb3d6",
          "body": "* Send DEVICE_KEY in USER_PASSWORD_AUTH initiateAuth call\n\nThe plaintext password flow looked up the remembered device key only\nafter initiateAuth had already been sent, and never passed it along, so\nCognito could not recognize a remembered device: users were always\nprompted for MFA and the pre-buil\n[…]\ner browser\n   now fully self-heal in one sign-in).\n\n3. clearDeviceKey now awaits the storage removals before dispatching,\n   so a sign-in started right after it resolves cannot read the old\n   record.",
          "is_bot": false,
          "headline": "Send DEVICE_KEY in USER_PASSWORD_AUTH initiateAuth call (#67)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-11T13:06:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3163c2fe8041250aface58d2a7acac8a3d3d6905",
          "body": "…ow (#66)\n\n* Surface fragment-delivered OAuth errors and deprecate implicit flow\n\nPer RFC 6749 §4.2.2.1, implicit-flow error responses arrive in the URL\nfragment, but the callback handler only read url.searchParams, so real\nIdP errors were swallowed and surfaced as a misleading \"Access token\nmissing\n[…]\nattack stays blocked: the fallback never\nruns when the fragment holds valid tokens. Also rephrase the channel\ncomments to distinguish RFC-specified server behavior from this\nclient's hardening policy.",
          "is_bot": false,
          "headline": "Surface fragment-delivered OAuth errors and deprecate the implicit fl…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-11T13:05:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7b49703bcacfdf6e14cd3e292c46f2f37253d063",
          "body": "…O2 request (#76)\n\n* Abort pending conditional credentials.get() before starting a new request\n\nPer the Credential Management API, only one credentials.get() request may\nbe pending at a time. With the documented usage pattern - a conditional\n(autofill) request kicked off at page load, followed by th\n[…]\nso the autofill flow would restart behind the modal request's\nback and keep renewing indefinitely. Rethrow superseded aborts so the\nflow ends cleanly; regression test covers the renewal-boundary race.",
          "is_bot": false,
          "headline": "Abort pending conditional credentials.get() before starting a new FID…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-11T00:59:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "762177be4dbe88d0f41e9ed7d382846852c0a5e4",
          "body": "* Reset per-user state on sign-out in React hook\n\nThe SIGN_OUT reducer action was defined but never dispatched, so the\nReact signOut method left deviceKey, totpMfaStatus, mfaStatusReady and\nactivity timestamps from the previous user in place. A subsequent user\non the same provider instance could the\n[…]\nin a session, and\nsign-out is a session boundary: reset it so the next user's fetch\nruns immediately. Regression test signs user B in within the cooldown\nand asserts an immediate fetch with B's token.",
          "is_bot": false,
          "headline": "Reset per-user state on sign-out in React hook (#64)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-11T00:59:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ddf4a3d8b8b10ca059c1bcc59b97c86d20bcfac0",
          "body": "…its (#62)\n\nThe post-exchange URL cleanup used history.pushState, which adds a new\nhistory entry and leaves the callback URL carrying ?code=...&state=...\n(or #access_token=... in the implicit flow) one step back in session\nhistory. Worse, no error path cleaned the URL at all: on state mismatch,\nmiss\n[…]\nes in the implicit flow, which previously threw without scrubbing.\nFalls back to pushState for custom MinimalHistory implementations\nwithout replaceState (replaceState is added as an optional member).",
          "is_bot": false,
          "headline": "Scrub OAuth code/tokens from URL with replaceState on all callback ex…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-11T00:58:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a225f9d40becb55236a9efdfc33af481193342cf",
          "body": "…bility listener (#60)\n\n* Keep global refresh listeners alive across sign-out\n\nsignOut called cleanupRefreshSystem(username), which tore down the\nglobal visibilitychange listener, refresh watchdog, and page-unload\nhandlers for the rest of the page lifetime. Since these are only\nregistered once at mo\n[…]\nther lookup in this file since #55) so the\nlock is honored whenever a refresh token still exists. With the lock\nhonored, the handler serializes behind signOut and then no-ops once\nthe tokens are gone.",
          "is_bot": false,
          "headline": "Fix signOut permanently tearing down global refresh watchdog and visi…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T23:15:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0d5792f526b14c6c213b6b91a863b183cf3715cd",
          "body": "…h cooldown (#61)\n\nWhen the access token changed within 5s of the previous getUser call\n(e.g. OAuth code exchange completing after stored tokens loaded, or a\nforced refresh right after sign-in), updateTokens reset mfaStatusReady\nto false but the MFA status effect early-returned on the cooldown\nwitho\n[…]\nw the cooldown branch schedules a setTimeout for the remaining\ncooldown that nudges the effect to re-run (INCREMENT_RECHECK_STATUS),\nwith cleanup on dependency change/unmount so timers cannot pile up.",
          "is_bot": false,
          "headline": "Fix mfaStatusReady deadlock when access token rotates within MFA fetc…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T23:15:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e5b2dc57ef7e31902784970450d3ec45e7dd825d",
          "body": "The plaintext (USER_PASSWORD_AUTH) flow looked up and stored remembered-\ndevice records under the username as entered, which may be an alias\n(e-mail / phone), while the SRP flow keys them by USER_ID_FOR_SRP. A\ndevice confirmed via one flow was then invisible to the other, silently\nlosing device reme\n[…]\ness token's username claim) and use it\nfor device record lookups and for the rest of the auth flow, with a\nbackward-compat fallback lookup under the username as entered so legacy\nrecords keep working.",
          "is_bot": false,
          "headline": "Key plaintext-flow device records by canonical user id (#71)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T23:14:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "04f2aa9ffb0a7c3cc05b009070c70eb5d6aff17b",
          "body": "…n-ASCII usernames (#75)\n\nRegistration encoded the server-sent user.id with Latin-1 byte-stuffing\n(charCodeAt mod 256) while usernameless sign-in decodes the returned\nuserHandle with TextDecoder (UTF-8). For non-ASCII usernames the bytes\nwere corrupted at registration, so the derived USERNAME never \n[…]\n\nare symmetric, and throw a clear Fido2ValidationError if the encoded\nhandle exceeds the 64-byte WebAuthn limit instead of failing opaquely.\nASCII user handles are byte-identical under both encodings.",
          "is_bot": false,
          "headline": "Fix userHandle encoding to UTF-8 so usernameless sign-in works for no…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T23:14:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1b6f2e03fecc7f9296913fc4e5681fcbe7b7b24e",
          "body": "handleCognitoOAuthCallback() overwrote the shared in-progress flag with\n\"processing\" before verifying the current URL matched the configured\nredirect URL. The URL-mismatch branch then returned null without\nrestoring the flag, so any invocation on a non-callback URL (e.g. the\nReact hook firing on an \n[…]\nthe redirect-URL comparison ahead of the flag transition so\nnon-callback invocations leave the flag untouched. All paths after the\n\"processing\" write either complete the flow or clear state and throw.",
          "is_bot": false,
          "headline": "Check redirect URL before marking OAuth callback as processing (#65)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T23:13:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c0df6f6c281fcfcfee03c1a6626e172d9a6a73e2",
          "body": "…y (#57)\n\n* Make setTimeoutWallClock resilient to device sleep for the whole delay\n\nPreviously, delays >= 30s used a plain setTimeout for all but the final\n30 seconds, and browsers don't reliably credit setTimeout time spent in\nsystem sleep. If the device slept during that phase (almost the entire\nd\n[…]\nresh() deadlocks. Add an\nawaitPumpingTimers helper that advances mock time in 100ms steps (settling\nmicrotasks between steps via real-timer waits) and use it for all\nscheduleRefresh calls in the file.",
          "is_bot": false,
          "headline": "Make setTimeoutWallClock resilient to device sleep for the whole dela…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T21:13:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c8621e1468bcec5b6cc36f6c2e85ca922c561f40",
          "body": "The CognitoSecurityProvider previously awaited script injection with a\n5-second timeout on every auth API call whenever the Amazon Cognito\nAdvanced Security script could not load (ad blockers, CSP, unsupported\nregions), and re-appended a fresh script tag on each attempt. An SRP\nsign-in flow could ac\n[…]\nire-and-forget, attempted at most once per page\nload, and skipped for custom proxy endpoints and regions where AWS does\nnot host the script (previously such endpoints silently defaulted to\nus-east-1).",
          "is_bot": false,
          "headline": "Never block auth calls on threat-protection script loading (#70)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T21:07:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9033903f9e328c377b4733dd3583248a081dc4c0",
          "body": "…okens (#69)\n\nThe 5-minute deduplication window in processTokens compared only\nwall-clock age of the previous schedule entry. After a successful\nrefresh, processTokens runs for the new tokens while the previous\nentry is still tracked (refresh.ts clears it via tokensCb only after\nprocessTokens return\n[…]\nently disabling retry backoff and abort propagation\nfor the replacement schedule). Add a regression test asserting a\nrefresh-driven processTokens arms the next refresh timer without\naborting anything.",
          "is_bot": false,
          "headline": "Fix refresh-schedule dedup suppressing next refresh for short-lived t…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T21:06:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5f60ac1452eb2b9da33565a48dedfa1a92d9ecd2",
          "body": "The documented fallback pattern `error.name === 'NotAllowedError'` could\nnever match because fromDOMException wraps the DOMException in a\nFido2CredentialError whose name is \"Fido2CredentialError\", and both\nNotAllowedError and InvalidStateError mapped to the same CREDENTIAL_ERROR\ncode, leaving no pro\n[…]\nERROR fallback\n- Fix the JSDoc examples in fido2.ts and the docs in ERROR_HANDLING.md\n  and client/react/README.md to use the working pattern\n- Add regression tests for the new codes and the predicate",
          "is_bot": false,
          "headline": "Add discriminating error codes for WebAuthn credential failures (#63)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T21:05:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "af2490b368037b73c28dedc2b82006365989d0e3",
          "body": "The Fido2ConfigError thrown when isConditionalMediationAvailable()\nresolves false was inside the same try block whose catch only\ndebug-logged and continued, so the guard never fired and the code\nproceeded to call navigator.credentials.get with conditional mediation\non browsers that explicitly report\n[…]\nt false propagates as\nFido2ConfigError, keep the lenient fallthrough when the capability\ncheck itself throws, and make the debug message truthful about\nproceeding. Add regression tests for both cases.",
          "is_bot": false,
          "headline": "Fix unreachable conditional-mediation guard in fido2getCredential (#59)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T21:04:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "58174921e5c1d978a08fa4fb3a781c73707e08a9",
          "body": "fido2getCredential unconditionally overrode userVerification to\n\"preferred\" when mediation was \"conditional\", silently downgrading a\nserver-requested \"required\". The WebAuthn spec has no such requirement;\n\"preferred\" is only passkeys.dev UX guidance. With the downgrade, an\nauthenticator may skip use\n[…]\n).\n\nNow the requested value is passed through unchanged and \"preferred\" is\napplied only as a default when no userVerification was requested. The\ntimeout removal for conditional mediation is unchanged.",
          "is_bot": false,
          "headline": "Respect requested userVerification for conditional mediation (#58)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T21:03:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8388acd84cedfa0b45af2d02aabe4eba1a820c70",
          "body": "…oIdpEndpoint fallback (#56)\n\ngetAuthorizeEndpoint()/getTokenEndpoint() fell back to cognitoIdpEndpoint\nwhen hostedUi.domain was omitted. With the documented region-only\nconfiguration (e.g. cognitoIdpEndpoint: \"eu-west-1\") this produced\nhttps://eu-west-1/oauth2/authorize, sending signInWithRedirect(\n[…]\nis not a bare AWS region), so https://eu-west-1 or other dotless\nhosts cannot slip through; plaintext http:// origins are rejected,\nbecause OAuth2 authorization codes and tokens travel to that origin.",
          "is_bot": false,
          "headline": "Require hostedUi.domain for OAuth2 endpoints instead of broken cognit…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T21:02:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "068f9fba5c3ba456ecfe10dab874ad492da31afa",
          "body": "…#86)\n\nPR #52 added the onTokensStored(cb) subscriber API to client/storage.ts;\nthe React hook calls the returned unsubscribe function in its mount\neffect cleanup. PR #74 added react-context-stability.test.tsx, which\nmocks ../storage without making onTokensStored return a function, so\nthe cleanup ca\n[…]\nact suites already use\n(mockOnTokensStored.mockReturnValue(() => {})), and harden the hook\ncleanup with a typeof check so a future mock omission degrades\ngracefully instead of throwing during unmount.",
          "is_bot": false,
          "headline": "Fix react-context-stability test suite broken by parallel PR merges (…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T20:21:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c8b7664193b23d5b953cab54bce2fda0560628d8",
          "body": "Debug output previously included full refresh/access/ID tokens, SRP\nsecret blocks, device keys and the OAuth state/PKCE challenge whenever\nan application wired the debug callback to console.log or a remote\nlogger. Add redactSecret and redactTokensFromObject helpers to\nclient/util.ts and apply them a\n[…]\nall, which still logged SECRET_BLOCK and DEVICE_KEY verbatim during\nremembered-device authentication, and the ConfirmDevice response log.\nA regression test covers the device challenge flow end to end.",
          "is_bot": false,
          "headline": "Redact tokens and device keys from debug logging (#78)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T18:57:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e561cdb5e4cddcecb76707907e8ea92b94a25c96",
          "body": "signOut's storage cleanup missed the per-user keys the library actually\nwrites: Passwordless.<clientId>.<username>.authMethod,\n.lastRefreshAttempt and .lastRefreshCompleted. A leftover\nlastRefreshAttempt written shortly before sign-out makes\nshouldAttemptRefresh veto the first refresh after an immed\n[…]\nthe .expireAt and\n.refreshingTokens removals as legacy-key migration hygiene, and add a\nregression test asserting no per-user residue remains after sign-out\n(while the remembered-device key persists).",
          "is_bot": false,
          "headline": "Remove leftover per-user storage keys on sign-out (#81)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T18:56:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2a4526a12cf96d9d802033285da6e84b0dcbcae2",
          "body": "… refresh (#55)\n\nrefreshTokens()/forceRefreshTokens() without an explicit tokens argument\nresolved the user and refresh token via retrieveTokens(), which returns\nundefined once the stored access token's exp is in the past. That made\nrefresh fail with \"Cannot determine user identity for refresh lock\"\n[…]\nen load, reuse-exception\nrecovery, cross-tab coordination helpers, forceRefreshTokens timer\nlookup) to retrieveTokensForRefresh(), which does not gate on\naccess-token expiry, and add regression tests.",
          "is_bot": false,
          "headline": "Use retrieveTokensForRefresh in refresh paths so expired sessions can…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T18:56:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "26a244a7b52c02b1bf39d1a20c8be26be40a6359",
          "body": "The storage lock could be double-acquired across tabs, causing\nconcurrent token refreshes and (with refresh-token rotation)\nRefreshTokenReuseException / session loss:\n\n- The storage event listener treated ANY foreign write to the lock key\n  as a release, including another waiter's acquisition, so a \n[…]\nownership verify\nthat acquisition uses, standing down if a competing write landed after\nours. Release already only removes the key when it still holds our id,\nso a takeover survives release untouched.",
          "is_bot": false,
          "headline": "Fix cross-tab storage lock to enforce mutual exclusion (#54)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T18:55:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dbf43b14757a2a26a5feea20180cd94996e5ecb0",
          "body": "The conditional-mediation fast path in prepareFido2SignIn called\ninitiateAuth (CUSTOM_AUTH) first and then awaited an indefinitely-pending\nautofill credentials.get(). Cognito invalidates the challenge session\nafter AuthSessionValidity minutes (3 by default), so any user picking an\nautofill passkey m\n[…]\nnvisible to the user. The loop stops when the credential resolves, on\nerror, or when the caller aborts. Also document the session-validity\nconstraint on PreparedFido2SignIn and the prepared parameter.",
          "is_bot": false,
          "headline": "Renew Cognito session while conditional passkey request is pending (#53)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T18:54:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9c1327655c25cadb5a2203c51d105b2b916754fd",
          "body": "…#52)\n\nBackground refreshes persist refreshed tokens via storeTokens, but the\nReact hook's only re-sync path was the \"storage\" event, which per the\nWHATWG HTML spec never fires in the document that performed the write.\nIn the active tab the hook therefore kept the stale access token until\nexpiry and\n[…]\nsubscribe in the React hook's\nmount effect to reload tokens from storage on same-context stores.\nThe subscription is removed on unmount and reloads are no-ops after\nabort. Public API is additive only.",
          "is_bot": false,
          "headline": "Propagate background token refresh into React state in the same tab (…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T18:54:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c863424b2bab73e1acaa4c93b2875f935be53799",
          "body": "… (#51)\n\nThe HKDF salt was derived from the raw SHA-256 digest hex of the\nscramble parameter u (leading zero bytes preserved), but Cognito's\nserver and the reference client (amazon-cognito-identity-js) encode u\nas a big integer: leading zero bytes stripped, with a '00' sign byte\nprepended only when \n[…]\n\narrayBufferToBigInt(uBuf).toString(16) passed through padHex, and add\nregression tests covering both the leading-zero-byte case and the\nsign-byte case against an independent reference implementation.",
          "is_bot": false,
          "headline": "Fix SRP HKDF salt to use big-integer encoding of scramble parameter u…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T18:52:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b903644934969b054bb16443b434d1a678550cdc",
          "body": "The unmount cleanup in useAwaitableState sets isMounted.current = false\nbut nothing ever set it back to true. Under React 18+ StrictMode's\nmount -> unmount -> remount cycle (default in dev), refs survive the\nsimulated remount, so resolve() and reject() — both guarded by\nisMounted.current — became pe\n[…]\naitable() returned a\npromise that never settled, hanging every MFA/new-password prompt flow\nin dev. Reset the flag in the effect body before returning the cleanup,\nand add StrictMode regression tests.",
          "is_bot": false,
          "headline": "Fix useAwaitableState hanging under React StrictMode (#72)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T18:52:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2ec99f9e9d22c20257cf06e3f8282dcb0ccaa9ce",
          "body": "Abort the SRP handshake when the server-supplied B is congruent to\n0 mod N (required by RFC 5054 section 2.5.3) or when the scramble\nparameter u is 0 (required by the SRP-6a design). Both checks live in\ncalculateSrpSignature so they cover the user-password and device-\npassword flows. Also make hexToArrayBuffer reject empty or non-hex\ninput with a descriptive error instead of throwing an opaque TypeError\nfrom a non-null assertion on a failed match.",
          "is_bot": false,
          "headline": "Add SRP-6a safety checks for B mod N and u, validate hex input (#73)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T18:51:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c4dd0f6013a2d6be4fd921d63fcac2ef0b1b4fd0",
          "body": "With tokenRefresh.useActivityTracking enabled, a 1s interval dispatched\nSET_NOW_TICK into the provider's reducer, and the derived\ntimeSinceLastActivityMs was a dep of the context useMemo — so the context\nvalue identity changed every second, re-rendering every usePasswordless()\nconsumer even if it ne\n[…]\n.\nAlso correct the inaccurate memo-deps comment claiming the API methods\nwere memoized with useCallback, and add render-count regression tests\ncovering the live fields and the config-flag propagation.",
          "is_bot": false,
          "headline": "Stop per-second context churn when activity tracking is enabled (#74)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T18:51:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "67a926af658549c3888bfc665166d64986d200e6",
          "body": "At device confirmation, x was hashed over the raw 16 random salt bytes\nand those raw bytes were uploaded in DeviceSecretVerifierConfig.Salt.\nCognito stores/echoes the salt as a big integer, so a salt with a\nleading zero byte (P ~ 1/128) came back stripped in the\nDEVICE_PASSWORD_VERIFIER SALT paramet\n[…]\nquals what the\nserver stores and echoes. The explicit top-bit masking is no longer\nneeded since padHex now provides the \"00\" sign prefix when the MSB is\nset, exactly like the reference implementation.",
          "is_bot": false,
          "headline": "Canonicalize device-verifier salt as big integer before hashing (#77)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T18:49:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "57ce5dedcb68ac88cef7affb56a2af247155c75e",
          "body": "The wait helper in createFetchWithRetry registered an \"abort\" listener\non the caller's AbortSignal for every backoff sleep, but { once: true }\nonly removes the listener when the signal actually aborts. When the\ntimer resolved normally, the listener stayed attached, so a long-lived\nsignal reused acro\n[…]\no the handler reference is shared by both\npaths: the timer callback now removes the abort listener before\nresolving, and the abort handler still clears the timer and rejects\nwith AbortError as before.",
          "is_bot": false,
          "headline": "Remove abort listener when retry backoff timer fires normally (#79)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T18:48:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ff8d61545aee65751dc603ceaef9445cfc2b2f78",
          "body": "…#80)\n\nThe catch-all in authenticateWithFido2 emitted FIDO2_SIGNIN_FAILED for\nevery error, including deliberate cancellations (Fido2AbortError from a\ncancelled WebAuthn ceremony, or an unwrapped DOMException AbortError\nescaping the Cognito fetch calls when the caller invokes the returned\nabort()). S\n[…]\nn-ins.\n\nNow the catch path detects abort errors and reverts the status to\nSIGNED_OUT (the idle state the flow started from) while still\nrethrowing, so callers' promise rejection behavior is unchanged.",
          "is_bot": false,
          "headline": "Report aborted FIDO2 sign-in as SIGNED_OUT, not FIDO2_SIGNIN_FAILED (…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T18:48:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b476aef2cf9166fc9804e9f59d09d9ae619c0fe0",
          "body": "The region regex /^[a-z]{2}-[a-z]+-\\d$/ in client/config.ts and\nclient/cognito-api.ts (AWS_REGION_REGEXP) only matched standard-partition\nregions. Multi-segment regions such as us-gov-west-1, us-gov-east-1\n(GovCloud) and eusc-de-east-1 (European Sovereign Cloud) were treated as\nhostnames instead: co\n[…]\nt-1 resolves to cognito-idp.eusc-de-east-1.amazonaws.eu\ninstead of the nonexistent .amazonaws.com host.\n\nAdds table-driven regression tests covering both code paths and the\nper-partition DNS suffixes.",
          "is_bot": false,
          "headline": "Broaden AWS region regex to support partitioned regions (#82)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T18:47:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dd6206ecc9351863db19d15581c8c4d101ed6069",
          "body": "…nput (#83)\n\nbufferFromBase64Url threw a raw TypeError (\"Cannot read properties of\nnull\") on an empty string because String.match returns null, and silently\ndecoded garbage for characters outside the base64url alphabet. Decoders\nnow return an empty buffer for empty input and throw a clear Error for\n\n[…]\nted in the decoder as an unclassified TypeError instead of a\nFido2ValidationError. Both checks now reject empty strings.\n\nAdds regression tests for the decoder edge cases and the tightened\nvalidation.",
          "is_bot": false,
          "headline": "Harden base64url decoding and FIDO2 option validation against empty i…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T18:46:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "416b979cf22bcb44007df0d438cdf103ca803046",
          "body": "btoa() throws InvalidCharacterError for any customState containing\nnon-Latin1 characters (e.g. emoji or accented UTF-8 app state), aborting\nsign-in. It also emits \"+\", \"/\" and \"=\" which are not URL-safe. Encode\nthe customState as base64url of its UTF-8 bytes using the existing\nbufferToBase64Url help\n[…]\nn succeeds, split the random hex prefix\nfrom the base64url suffix, decode it, and return it as the optional\ncustomState field on the resolved TokensFromSignIn. Flows without\ncustomState are unchanged.",
          "is_bot": false,
          "headline": "Make OAuth customState UTF-8 safe and surface it on the callback (#84)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T18:46:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "eb3a12b66630a5f8f4d220af1afe75fa7a9d1987",
          "body": "signOut() retrieved the session via retrieveTokens(), which drops tokens\nwhose access token has expired as a safety net and returns undefined. So\nwhen a user signed out after their access token expired, signOut logged\n\"No tokens in storage to delete\", reported SIGNED_OUT, but left\nrefreshToken, Last\n[…]\ntests covering an expired access token with a valid\nrefresh token (storage cleared + token revoked) and access-only sessions\nwith no refresh token, both valid and expired (storage cleared, no\nrevoke).",
          "is_bot": false,
          "headline": "Fix signOut no-op when access token is already expired (#85)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T18:45:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "43f19da4fa41954f658c6c5b3cf903e577fb5dda",
          "body": null,
          "is_bot": false,
          "headline": "Bump version from 1.0.98 to 1.0.99",
          "author_name": "GitHub Action",
          "author_login": "actions-user",
          "committed_at": "2026-05-31T15:48:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "155e8c1626900b1ce1efc0a1a64040afd53f7bda",
          "body": "The enterprise Actions policy requires every action — including GitHub-owned\nones — to be pinned to a full-length commit SHA. Tags (actions/checkout@v4,\nactions/setup-node@v4) are rejected and the run fails at startup\n(startup_failure) before any step ran. This is what was blocking every\nworkflow_dispatch.\n\nPin to the latest releases:\n- actions/checkout   -> de0fac2e4500dabe0009e67214ff5f5447ce83dd (v6.0.2)\n- actions/setup-node -> 48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e (v6.4.0)",
          "is_bot": false,
          "headline": "publish: pin actions to full-length commit SHAs (#50)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-05-31T15:48:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3804d7efda2fe370c6ede669812ee5dc49fad8d1",
          "body": "The repo restricts Actions to an allowlist (allowed_actions=selected) that\ndoes not include softprops/action-gh-release, so the publish workflow failed\nat startup (startup_failure) the moment it was dispatched.\n\nReplace that third-party action with the pre-installed gh CLI\n(`gh release create`), whi\n[…]\no allowlist entry and removes a\nthird-party dependency from the release path. Release-notes input is passed\nvia env to avoid shell injection, preserving the prior body + auto-generated\nnotes behavior.",
          "is_bot": false,
          "headline": "publish: create GitHub Release via gh CLI (allowlist-safe) (#49)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-05-31T15:21:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2267d89cf502e2e15c5c39bf0d98d80f33119759",
          "body": "…#48)\n\n* publish: use npm Trusted Publishing (OIDC) instead of NPM_TOKEN\n\nSwitch the npm publish step to OIDC-based Trusted Publishing:\n- add `id-token: write` permission (kept `contents: write` for the\n  version commit/tag/push and GitHub release)\n- bump Node to 22.x and upgrade npm to >= 11.5.1 (T\n[…]\n\n  default registry lets OIDC handle authentication.\n- Pin `npm@11.5.1` instead of `npm@latest` to avoid a mutable supply-chain\n  dependency on the privileged (id-token + contents:write) release path.",
          "is_bot": false,
          "headline": "publish.yml: use npm Trusted Publishing (OIDC) instead of NPM_TOKEN (…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-05-30T21:06:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ba586b6504029e13316a6455c31f491e73d4c9e8",
          "body": "Bumps the npm_and_yarn group with 2 updates in the / directory: [minimatch](https://github.com/isaacs/minimatch) and [js-yaml](https://github.com/nodeca/js-yaml).\n\n\nUpdates `minimatch` from 3.1.2 to 3.1.5\n- [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md)\n- [Commits](https://g\n[…]\n dependency-type: indirect\n  dependency-group: npm_and_yarn\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump the npm_and_yarn group across 1 directory with 2 updates (#47)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-29T19:32:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3a0011993c935c7a39d129471ebad23954c17988",
          "body": "The library talks to Cognito entirely through its own fetch-based client\n(srp.ts, cognito-api.ts, hosted-oauth.ts). @aws-sdk/client-cognito-identity-provider\nis not imported anywhere in the source and is not re-exported from any\npackage entrypoint, so it is dead weight in the dependency tree.\n\nRemov\n[…]\nuntime behavior. This supersedes the lockfile-only bumps\nin #40/#39, which only churned versions of those same unused transitives.\n\nVerified: tsc (client/tsconfig) clean, full jest suite passes (182).",
          "is_bot": false,
          "headline": "Remove unused @aws-sdk/client-cognito-identity-provider dependency (#46)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-05-29T19:27:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "702536390d4dcc2afd60b82dde6ea7b00722fd0f",
          "body": "Bumps the npm_and_yarn group with 1 update in the / directory: [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser).\n\n\nUpdates `fast-xml-parser` from 4.4.1 to 5.7.2\n- [Release notes](https://github.com/NaturalIntelligence/fast-xml-parser/releases)\n- [Changelog](https://github.co\n[…]\n dependency-type: indirect\n  dependency-group: npm_and_yarn\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump fast-xml-parser in the npm_and_yarn group across 1 directory (#40)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-29T18:49:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "71e68e902f72f7d7c7d29e7bc0645c2e4aa39c15",
          "body": "Bumps the npm_and_yarn group with 1 update in the / directory: [picomatch](https://github.com/micromatch/picomatch).\n\n\nUpdates `picomatch` from 2.3.1 to 2.3.2\n- [Release notes](https://github.com/micromatch/picomatch/releases)\n- [Changelog](https://github.com/micromatch/picomatch/blob/master/CHANGEL\n[…]\n dependency-type: indirect\n  dependency-group: npm_and_yarn\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump picomatch in the npm_and_yarn group across 1 directory (#41)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-29T18:49:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2c90089fefd74841a0ae9087a07c9155c55dfba8",
          "body": "Bumps the npm_and_yarn group with 1 update in the / directory: [flatted](https://github.com/WebReflection/flatted).\n\n\nUpdates `flatted` from 3.3.1 to 3.4.2\n- [Commits](https://github.com/WebReflection/flatted/compare/v3.3.1...v3.4.2)\n\n---\nupdated-dependencies:\n- dependency-name: flatted\n  dependency\n[…]\n dependency-type: indirect\n  dependency-group: npm_and_yarn\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump flatted in the npm_and_yarn group across 1 directory (#42)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-29T18:48:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a6a0e37bfa680ffe8fd0fcdf57061bb6179413ac",
          "body": "…p login loop) (#43)\n\n* Tolerate client clock skew when validating token expiry\n\nA device whose clock is fast by more than the access token's lifetime\ntreated every freshly-issued token as already-expired: token validity\ncompared the server-issued `exp` claim against local `Date.now()` with no\nskew \n[…]\nCarry clockDriftMs over.\n- common.ts: signOut now removes the persisted clockDriftMs storage key\n  alongside the other per-user keys.\n- test/clock-skew.test.ts: add a sign-out cleanup regression test.",
          "is_bot": false,
          "headline": "Tolerate client clock skew when validating token expiry (fixes deskto…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-05-29T18:35:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9af1cbf6a0fe103ecc36288fc4c5b121609ec64a",
          "body": null,
          "is_bot": false,
          "headline": "Bump version from 1.0.97 to 1.0.98",
          "author_name": "GitHub Action",
          "author_login": "actions-user",
          "committed_at": "2025-11-04T18:21:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0a57c18aabc3b9561e24ffa62e5e3c617fd54a14",
          "body": "* Ensure UI never hangs on MFA status loading failures\n\n* add silent retry for mfa status\n\n* run earlier",
          "is_bot": false,
          "headline": "Ensure UI never hangs on MFA status loading failures (#37)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2025-11-04T18:21:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d9b10157e45c70316905bc7d6876048cd2f83f75",
          "body": null,
          "is_bot": false,
          "headline": "Bump version from 1.0.96 to 1.0.97",
          "author_name": "GitHub Action",
          "author_login": "actions-user",
          "committed_at": "2025-10-06T20:02:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8a35c15c5c03ac3e01ebfaaa4e202f65dde0d384",
          "body": "* Add comprehensive debug logging for FIDO2 authentication flows\n\n* simpler flow\n\n* merge server and client credentials in auth flow",
          "is_bot": false,
          "headline": "Add comprehensive debug logging to FIDO2 authentication flows (#35)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2025-10-06T20:01:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c076c2e3927ffe8eca2c2b419e83c3e7245be1f8",
          "body": null,
          "is_bot": false,
          "headline": "Bump version from 1.0.95 to 1.0.96",
          "author_name": "GitHub Action",
          "author_login": "actions-user",
          "committed_at": "2025-10-06T15:41:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "af05372cb331f705f18aea1b2164e0bd10244ca2",
          "body": "… autofill (#34)\n\n* Add prepareFido2SignIn for WebAuthn conditional mediation and passkey autofill\n\n* update tests\n\n* handle case when username is different",
          "is_bot": false,
          "headline": "Add prepareFido2SignIn for WebAuthn conditional mediation and passkey…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2025-10-06T15:40:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f73a826cdbfeb353fd2896f8df163267b29e6006",
          "body": null,
          "is_bot": false,
          "headline": "Bump version from 1.0.94 to 1.0.95",
          "author_name": "GitHub Action",
          "author_login": "actions-user",
          "committed_at": "2025-10-05T19:49:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "223c4a9afabc6d59845e02634cfb5f7d120f0fc0",
          "body": "* Add WebAuthn conditional mediation and passkey autofill support\n\n* rm create mediation",
          "is_bot": false,
          "headline": "Add WebAuthn conditional mediation and passkey autofill support (#33)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2025-10-05T19:49:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "61eab67deb8e3bfde3227879a19d676fafda481d",
          "body": "…cation flows (#32)\n\n* Add support for conditional mediation and automatic passkey creation\n\n* proper types and immediate mode\n\n* refactor tests",
          "is_bot": false,
          "headline": "Add WebAuthn mediation support for conditional and immediate authenti…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2025-10-05T19:13:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "112c801a45c9b7c0e4e0461d7eba07c7e76cc326",
          "body": null,
          "is_bot": false,
          "headline": "Bump version from 1.0.93 to 1.0.94",
          "author_name": "GitHub Action",
          "author_login": "actions-user",
          "committed_at": "2025-10-03T00:04:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2db9179d0f520cddab113ddbb48b3a05472b34a3",
          "body": null,
          "is_bot": false,
          "headline": "fix build (#31)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2025-10-03T00:03:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d893ddca8f3d8d96c5fe4eae45da25d67865dc7b",
          "body": null,
          "is_bot": false,
          "headline": "Bump version from 1.0.92 to 1.0.93",
          "author_name": "GitHub Action",
          "author_login": "actions-user",
          "committed_at": "2025-10-02T23:53:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f261fb4b0f035bc34eb10eaa513c6c3c6895159a",
          "body": null,
          "is_bot": false,
          "headline": "user friendly error messages (#30)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2025-10-02T23:52:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "59cc1a0dd9a9b2bd4e1b998db6f6829b6a9e4462",
          "body": null,
          "is_bot": false,
          "headline": "Bump version from 1.0.91 to 1.0.92",
          "author_name": "GitHub Action",
          "author_login": "actions-user",
          "committed_at": "2025-10-02T22:13:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1b7bb64e506e1a73049452b48c1e43a9e5e85c25",
          "body": null,
          "is_bot": false,
          "headline": "export errors in package (#29)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2025-10-02T22:12:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eff8756a7a991f699f1bd2d70a506e67100314ff",
          "body": null,
          "is_bot": false,
          "headline": "Bump version from 1.0.90 to 1.0.91",
          "author_name": "GitHub Action",
          "author_login": "actions-user",
          "committed_at": "2025-10-02T21:53:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "01d5888f8e1efb51f8c9306b4e3cf70819088802",
          "body": "* Add typed error handling with custom error classes for FIDO2/WebAuthn operations\n\n* tests and better runtime checker\n\n* add more tests",
          "is_bot": false,
          "headline": "Add typed error handling for WebAuthn operations (#28)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2025-10-02T21:52:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8127dc061d49bbb7a9a8e63af927866db7588ada",
          "body": null,
          "is_bot": false,
          "headline": "Bump version from 1.0.89 to 1.0.90",
          "author_name": "GitHub Action",
          "author_login": "actions-user",
          "committed_at": "2025-09-09T20:17:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d4b74532af98697a58a40daee40885681e4e5812",
          "body": null,
          "is_bot": false,
          "headline": "Bump version from 1.0.88 to 1.0.89",
          "author_name": "GitHub Action",
          "author_login": "actions-user",
          "committed_at": "2025-09-09T19:58:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4eb658593dfde16f721fe218ef0c88c288ebad63",
          "body": "* react: add reliable MFA readiness signal (mfaStatusReady)\n\n- Add mfaStatusReady to PasswordlessState and initialize to false\n- Extend action union with SET_MFA_STATUS_READY and reducer case\n- Include mfaStatusReady in context memo deps and hook state\n- Mark readiness true after successful getUser/\n[…]\nhat TOTP MFA status has been fetched and is current for the active access token.\n\n* test(react): increase hooks.tsx patch coverage (REDIRECT parsing, OAuth callback, error boundary, activity tracking)",
          "is_bot": false,
          "headline": "react: add reliable MFA readiness signal (mfaStatusReady) (#27)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2025-09-09T19:57:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "94e2ed9173c40ef18a81049741d754e22454e74a",
          "body": null,
          "is_bot": false,
          "headline": "Bump version from 1.0.87 to 1.0.88",
          "author_name": "GitHub Action",
          "author_login": "actions-user",
          "committed_at": "2025-07-28T15:12:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4c8e57dac8821d98a05ca0692340e78a3311f8b8",
          "body": "* Add grace period during token refresh to prevent temporary logout\n\n* Add grace period during token refresh to prevent temporary logout\n\nThis fix addresses the \"30-minute lottery bug\" where users were temporarily\nlogged out when their tokens expired during page navigation while refresh\nwas in progr\n[…]\nsers remain signed in during the refresh process,\npreventing the temporary logout that occurred in 0.08% of sessions.\n\n* Update hooks.tsx\n\n* prettier\n\n* fix NaN check\n\n* fix test to match source logic",
          "is_bot": false,
          "headline": "Add grace period during token refresh to prevent temporary logout (#25)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2025-07-28T14:44:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "607fc3a657558e9b927d5ae8b0b90e328d85c47e",
          "body": null,
          "is_bot": false,
          "headline": "Bump version from 1.0.86 to 1.0.87",
          "author_name": "GitHub Action",
          "author_login": "actions-user",
          "committed_at": "2025-07-23T13:32:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "40dbb3794dd75dae31c306a54e55d4faf9d7bf03",
          "body": null,
          "is_bot": false,
          "headline": "add more tests (#24)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2025-07-23T13:31:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dcdf7e57c0cce438e354307b1586e55a654a87e6",
          "body": null,
          "is_bot": false,
          "headline": "Bump version from 1.0.85 to 1.0.86",
          "author_name": "GitHub Action",
          "author_login": "actions-user",
          "committed_at": "2025-07-23T12:02:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 96,
      "commits_last_year": 97,
      "latest_release_at": "2026-07-20T22:36:18Z",
      "latest_release_tag": "v1.0.104",
      "releases_from_tags": false,
      "days_since_last_push": 4,
      "active_weeks_last_year": 11,
      "days_since_latest_release": 6,
      "mean_days_between_releases": 32
    },
    "community": {
      "has_readme": false,
      "has_license": false,
      "has_description": false,
      "has_contributing": false,
      "health_percentage": null,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "@joinmeow/cognito-passwordless-auth",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [
            "AWS",
            "Cognito",
            "FIDO2",
            "Passwordless",
            "WebAuthn",
            "passkeys"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@joinmeow/cognito-passwordless-auth",
          "is_deprecated": false,
          "latest_version": "1.0.104",
          "repository_url": "https://github.com/joinmeow/amazon-cognito-passwordless-auth",
          "versions_count": 100,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 2,
          "monthly_downloads": 8713,
          "first_published_at": "2025-04-23T17:21:03.075000Z",
          "latest_published_at": "2026-07-20T22:36:16.595000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 6
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0,
        "collected_at": null
      },
      "open_issues_and_prs": 1
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "client/tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 96149,
      "source_files_sampled": 92,
      "oversized_source_files": 3,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 3,
        "malicious_count": 0,
        "assessed_package": "npm:@joinmeow/cognito-passwordless-auth@1.0.104",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "aws-jwt-verify",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.0.1"
        },
        {
          "name": "cbor",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^9.0.2"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "aws-jwt-verify",
            "direct": true,
            "version": "4.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "cbor",
            "direct": true,
            "version": "9.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@ampproject/remapping",
            "direct": false,
            "version": "2.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@asamuzakjp/css-color",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/code-frame",
            "direct": false,
            "version": "7.27.1",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/compat-data",
            "direct": false,
            "version": "7.27.3",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/core",
            "direct": false,
            "version": "7.27.3",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/generator",
            "direct": false,
            "version": "7.27.3",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-compilation-targets",
            "direct": false,
            "version": "7.27.2",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-module-imports",
            "direct": false,
            "version": "7.27.1",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-module-transforms",
            "direct": false,
            "version": "7.27.3",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-plugin-utils",
            "direct": false,
            "version": "7.27.1",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-string-parser",
            "direct": false,
            "version": "7.27.1",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-validator-identifier",
            "direct": false,
            "version": "7.27.1",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-validator-option",
            "direct": false,
            "version": "7.27.1",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helpers",
            "direct": false,
            "version": "7.27.3",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/parser",
            "direct": false,
            "version": "7.27.3",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-async-generators",
            "direct": false,
            "version": "7.8.4",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-bigint",
            "direct": false,
            "version": "7.8.3",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-class-properties",
            "direct": false,
            "version": "7.12.13",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-class-static-block",
            "direct": false,
            "version": "7.14.5",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-import-attributes",
            "direct": false,
            "version": "7.27.1",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-import-meta",
            "direct": false,
            "version": "7.10.4",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-json-strings",
            "direct": false,
            "version": "7.8.3",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-jsx",
            "direct": false,
            "version": "7.27.1",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-logical-assignment-operators",
            "direct": false,
            "version": "7.10.4",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-nullish-coalescing-operator",
            "direct": false,
            "version": "7.8.3",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-numeric-separator",
            "direct": false,
            "version": "7.10.4",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-object-rest-spread",
            "direct": false,
            "version": "7.8.3",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-optional-catch-binding",
            "direct": false,
            "version": "7.8.3",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-optional-chaining",
            "direct": false,
            "version": "7.8.3",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-private-property-in-object",
            "direct": false,
            "version": "7.14.5",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-top-level-await",
            "direct": false,
            "version": "7.14.5",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-typescript",
            "direct": false,
            "version": "7.27.1",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/runtime",
            "direct": false,
            "version": "7.27.6",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/template",
            "direct": false,
            "version": "7.27.2",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/traverse",
            "direct": false,
            "version": "7.27.3",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/types",
            "direct": false,
            "version": "7.27.3",
            "ecosystem": "npm"
          },
          {
            "name": "@bcoe/v8-coverage",
            "direct": false,
            "version": "0.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "@cspotcode/source-map-support",
            "direct": false,
            "version": "0.8.1",
            "ecosystem": "npm"
          },
          {
            "name": "@csstools/color-helpers",
            "direct": false,
            "version": "5.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@csstools/css-calc",
            "direct": false,
            "version": "2.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "@csstools/css-color-parser",
            "direct": false,
            "version": "3.0.10",
            "ecosystem": "npm"
          },
          {
            "name": "@csstools/css-parser-algorithms",
            "direct": false,
            "version": "3.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "@csstools/css-tokenizer",
            "direct": false,
            "version": "3.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/aix-ppc64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-arm",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/darwin-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/darwin-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/freebsd-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/freebsd-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-arm",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-ia32",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-loong64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-mips64el",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-ppc64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-riscv64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-s390x",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/netbsd-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/netbsd-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openbsd-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openbsd-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openharmony-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/sunos-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-ia32",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint-community/eslint-utils",
            "direct": false,
            "version": "4.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint-community/regexpp",
            "direct": false,
            "version": "4.10.1",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/eslintrc",
            "direct": false,
            "version": "2.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/js",
            "direct": false,
            "version": "8.57.0",
            "ecosystem": "npm"
          },
          {
            "name": "@humanwhocodes/config-array",
            "direct": false,
            "version": "0.11.14",
            "ecosystem": "npm"
          },
          {
            "name": "@humanwhocodes/module-importer",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "@humanwhocodes/object-schema",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@istanbuljs/load-nyc-config",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@istanbuljs/schema",
            "direct": false,
            "version": "0.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/console",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/core",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/environment",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/environment",
            "direct": false,
            "version": "30.0.0-beta.3",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/environment-jsdom-abstract",
            "direct": false,
            "version": "30.0.0-beta.3",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/expect",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/expect-utils",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/fake-timers",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/fake-timers",
            "direct": false,
            "version": "30.0.0-beta.3",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/globals",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/pattern",
            "direct": false,
            "version": "30.0.0-beta.3",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/reporters",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/schemas",
            "direct": false,
            "version": "29.6.3",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/schemas",
            "direct": false,
            "version": "30.0.0-beta.3",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/source-map",
            "direct": false,
            "version": "29.6.3",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/test-result",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/test-sequencer",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/transform",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/types",
            "direct": false,
            "version": "29.6.3",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/types",
            "direct": false,
            "version": "30.0.0-beta.3",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/gen-mapping",
            "direct": false,
            "version": "0.3.8",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/resolve-uri",
            "direct": false,
            "version": "3.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/set-array",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/sourcemap-codec",
            "direct": false,
            "version": "1.4.15",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/trace-mapping",
            "direct": false,
            "version": "0.3.25",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/trace-mapping",
            "direct": false,
            "version": "0.3.9",
            "ecosystem": "npm"
          },
          {
            "name": "@nodelib/fs.scandir",
            "direct": false,
            "version": "2.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "@nodelib/fs.stat",
            "direct": false,
            "version": "2.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "@nodelib/fs.walk",
            "direct": false,
            "version": "1.2.8",
            "ecosystem": "npm"
          },
          {
            "name": "@sinclair/typebox",
            "direct": false,
            "version": "0.27.8",
            "ecosystem": "npm"
          },
          {
            "name": "@sinclair/typebox",
            "direct": false,
            "version": "0.34.33",
            "ecosystem": "npm"
          },
          {
            "name": "@sinonjs/commons",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "@sinonjs/fake-timers",
            "direct": false,
            "version": "10.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@sinonjs/fake-timers",
            "direct": false,
            "version": "13.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "@testing-library/dom",
            "direct": false,
            "version": "10.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "@testing-library/react",
            "direct": false,
            "version": "16.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@tsconfig/node10",
            "direct": false,
            "version": "1.0.11",
            "ecosystem": "npm"
          },
          {
            "name": "@tsconfig/node12",
            "direct": false,
            "version": "1.0.11",
            "ecosystem": "npm"
          },
          {
            "name": "@tsconfig/node14",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@tsconfig/node16",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "@types/aria-query",
            "direct": false,
            "version": "5.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "@types/babel__core",
            "direct": false,
            "version": "7.20.5",
            "ecosystem": "npm"
          },
          {
            "name": "@types/babel__generator",
            "direct": false,
            "version": "7.27.0",
            "ecosystem": "npm"
          },
          {
            "name": "@types/babel__template",
            "direct": false,
            "version": "7.4.4",
            "ecosystem": "npm"
          },
          {
            "name": "@types/babel__traverse",
            "direct": false,
            "version": "7.20.7",
            "ecosystem": "npm"
          },
          {
            "name": "@types/graceful-fs",
            "direct": false,
            "version": "4.1.9",
            "ecosystem": "npm"
          },
          {
            "name": "@types/istanbul-lib-coverage",
            "direct": false,
            "version": "2.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "@types/istanbul-lib-report",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@types/istanbul-reports",
            "direct": false,
            "version": "3.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "@types/jest",
            "direct": false,
            "version": "29.5.14",
            "ecosystem": "npm"
          },
          {
            "name": "@types/jsdom",
            "direct": false,
            "version": "21.1.7",
            "ecosystem": "npm"
          },
          {
            "name": "@types/json5",
            "direct": false,
            "version": "0.0.29",
            "ecosystem": "npm"
          },
          {
            "name": "@types/node",
            "direct": false,
            "version": "20.14.5",
            "ecosystem": "npm"
          },
          {
            "name": "@types/prop-types",
            "direct": false,
            "version": "15.7.12",
            "ecosystem": "npm"
          },
          {
            "name": "@types/react",
            "direct": false,
            "version": "18.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "@types/stack-utils",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@types/tough-cookie",
            "direct": false,
            "version": "4.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "@types/yargs",
            "direct": false,
            "version": "17.0.33",
            "ecosystem": "npm"
          },
          {
            "name": "@types/yargs-parser",
            "direct": false,
            "version": "21.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/eslint-plugin",
            "direct": false,
            "version": "7.13.1",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/parser",
            "direct": false,
            "version": "7.13.1",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/scope-manager",
            "direct": false,
            "version": "7.13.1",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/type-utils",
            "direct": false,
            "version": "7.13.1",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/types",
            "direct": false,
            "version": "7.13.1",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/typescript-estree",
            "direct": false,
            "version": "7.13.1",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/utils",
            "direct": false,
            "version": "7.13.1",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/visitor-keys",
            "direct": false,
            "version": "7.13.1",
            "ecosystem": "npm"
          },
          {
            "name": "@ungap/structured-clone",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "acorn",
            "direct": false,
            "version": "8.12.0",
            "ecosystem": "npm"
          },
          {
            "name": "acorn-jsx",
            "direct": false,
            "version": "5.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "acorn-walk",
            "direct": false,
            "version": "8.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "agent-base",
            "direct": false,
            "version": "7.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "ajv",
            "direct": false,
            "version": "6.12.6",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-escapes",
            "direct": false,
            "version": "4.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-escapes",
            "direct": false,
            "version": "7.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-regex",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-regex",
            "direct": false,
            "version": "6.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-styles",
            "direct": false,
            "version": "4.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-styles",
            "direct": false,
            "version": "5.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-styles",
            "direct": false,
            "version": "6.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "anymatch",
            "direct": false,
            "version": "3.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "arg",
            "direct": false,
            "version": "4.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "argparse",
            "direct": false,
            "version": "1.0.10",
            "ecosystem": "npm"
          },
          {
            "name": "argparse",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "aria-query",
            "direct": false,
            "version": "5.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "array-buffer-byte-length",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "array-includes",
            "direct": false,
            "version": "3.1.8",
            "ecosystem": "npm"
          },
          {
            "name": "array-union",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "array.prototype.findlast",
            "direct": false,
            "version": "1.2.5",
            "ecosystem": "npm"
          },
          {
            "name": "array.prototype.findlastindex",
            "direct": false,
            "version": "1.2.5",
            "ecosystem": "npm"
          },
          {
            "name": "array.prototype.flat",
            "direct": false,
            "version": "1.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "array.prototype.flatmap",
            "direct": false,
            "version": "1.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "array.prototype.toreversed",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "array.prototype.tosorted",
            "direct": false,
            "version": "1.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "arraybuffer.prototype.slice",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "async",
            "direct": false,
            "version": "3.2.6",
            "ecosystem": "npm"
          },
          {
            "name": "available-typed-arrays",
            "direct": false,
            "version": "1.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "babel-jest",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "babel-plugin-istanbul",
            "direct": false,
            "version": "6.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "babel-plugin-jest-hoist",
            "direct": false,
            "version": "29.6.3",
            "ecosystem": "npm"
          },
          {
            "name": "babel-preset-current-node-syntax",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "babel-preset-jest",
            "direct": false,
            "version": "29.6.3",
            "ecosystem": "npm"
          },
          {
            "name": "balanced-match",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "1.1.11",
            "ecosystem": "npm"
          },
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "braces",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "browserslist",
            "direct": false,
            "version": "4.25.0",
            "ecosystem": "npm"
          },
          {
            "name": "bs-logger",
            "direct": false,
            "version": "0.2.6",
            "ecosystem": "npm"
          },
          {
            "name": "bser",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "buffer-from",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "call-bind",
            "direct": false,
            "version": "1.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "callsites",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "camelcase",
            "direct": false,
            "version": "5.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "camelcase",
            "direct": false,
            "version": "6.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "caniuse-lite",
            "direct": false,
            "version": "1.0.30001720",
            "ecosystem": "npm"
          },
          {
            "name": "chalk",
            "direct": false,
            "version": "4.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "chalk",
            "direct": false,
            "version": "5.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "char-regex",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "ci-info",
            "direct": false,
            "version": "3.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "ci-info",
            "direct": false,
            "version": "4.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "cjs-module-lexer",
            "direct": false,
            "version": "1.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "cli-cursor",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "cli-truncate",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "cliui",
            "direct": false,
            "version": "8.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "co",
            "direct": false,
            "version": "4.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "collect-v8-coverage",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "color-convert",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "color-name",
            "direct": false,
            "version": "1.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "colorette",
            "direct": false,
            "version": "2.0.20",
            "ecosystem": "npm"
          },
          {
            "name": "commander",
            "direct": false,
            "version": "14.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "concat-map",
            "direct": false,
            "version": "0.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "convert-source-map",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "create-jest",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "create-require",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "cross-spawn",
            "direct": false,
            "version": "7.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "cssstyle",
            "direct": false,
            "version": "4.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "csstype",
            "direct": false,
            "version": "3.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "data-urls",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "data-view-buffer",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "data-view-byte-length",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "data-view-byte-offset",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "debug",
            "direct": false,
            "version": "3.2.7",
            "ecosystem": "npm"
          },
          {
            "name": "debug",
            "direct": false,
            "version": "4.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "decimal.js",
            "direct": false,
            "version": "10.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "dedent",
            "direct": false,
            "version": "1.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "deep-is",
            "direct": false,
            "version": "0.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "deepmerge",
            "direct": false,
            "version": "4.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "define-data-property",
            "direct": false,
            "version": "1.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "define-properties",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "dequal",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "detect-newline",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "diff",
            "direct": false,
            "version": "4.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "diff-sequences",
            "direct": false,
            "version": "29.6.3",
            "ecosystem": "npm"
          },
          {
            "name": "dir-glob",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "doctrine",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "doctrine",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "dom-accessibility-api",
            "direct": false,
            "version": "0.5.16",
            "ecosystem": "npm"
          },
          {
            "name": "ejs",
            "direct": false,
            "version": "3.1.10",
            "ecosystem": "npm"
          },
          {
            "name": "electron-to-chromium",
            "direct": false,
            "version": "1.5.161",
            "ecosystem": "npm"
          },
          {
            "name": "emittery",
            "direct": false,
            "version": "0.13.1",
            "ecosystem": "npm"
          },
          {
            "name": "emoji-regex",
            "direct": false,
            "version": "10.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "emoji-regex",
            "direct": false,
            "version": "8.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "entities",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "environment",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "error-ex",
            "direct": false,
            "version": "1.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "es-abstract",
            "direct": false,
            "version": "1.23.3",
            "ecosystem": "npm"
          },
          {
            "name": "es-define-property",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "es-errors",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "es-iterator-helpers",
            "direct": false,
            "version": "1.0.19",
            "ecosystem": "npm"
          },
          {
            "name": "es-object-atoms",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "es-set-tostringtag",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "es-shim-unscopables",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "es-to-primitive",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "esbuild",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "escalade",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "escape-string-regexp",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "escape-string-regexp",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "eslint",
            "direct": false,
            "version": "8.57.0",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-import-resolver-node",
            "direct": false,
            "version": "0.3.9",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-module-utils",
            "direct": false,
            "version": "2.8.1",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-plugin-header",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-plugin-import",
            "direct": false,
            "version": "2.29.1",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-plugin-react",
            "direct": false,
            "version": "7.34.2",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-plugin-react-hooks",
            "direct": false,
            "version": "4.6.2",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-plugin-security",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-scope",
            "direct": false,
            "version": "7.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-visitor-keys",
            "direct": false,
            "version": "3.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "espree",
            "direct": false,
            "version": "9.6.1",
            "ecosystem": "npm"
          },
          {
            "name": "esprima",
            "direct": false,
            "version": "4.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "esquery",
            "direct": false,
            "version": "1.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "esrecurse",
            "direct": false,
            "version": "4.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "estraverse",
            "direct": false,
            "version": "5.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "esutils",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "eventemitter3",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "execa",
            "direct": false,
            "version": "5.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "exit",
            "direct": false,
            "version": "0.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "expect",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "fast-deep-equal",
            "direct": false,
            "version": "3.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "fast-glob",
            "direct": false,
            "version": "3.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "fast-json-stable-stringify",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "fast-levenshtein",
            "direct": false,
            "version": "2.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "fastq",
            "direct": false,
            "version": "1.17.1",
            "ecosystem": "npm"
          },
          {
            "name": "fb-watchman",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "file-entry-cache",
            "direct": false,
            "version": "6.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "filelist",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "fill-range",
            "direct": false,
            "version": "7.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "find-up",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "find-up",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "flat-cache",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "flatted",
            "direct": false,
            "version": "3.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "for-each",
            "direct": false,
            "version": "0.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "fs.realpath",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "fsevents",
            "direct": false,
            "version": "2.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "function-bind",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "function.prototype.name",
            "direct": false,
            "version": "1.1.6",
            "ecosystem": "npm"
          },
          {
            "name": "functions-have-names",
            "direct": false,
            "version": "1.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "gensync",
            "direct": false,
            "version": "1.0.0-beta.2",
            "ecosystem": "npm"
          },
          {
            "name": "get-caller-file",
            "direct": false,
            "version": "2.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "get-east-asian-width",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "get-intrinsic",
            "direct": false,
            "version": "1.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "get-package-type",
            "direct": false,
            "version": "0.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "get-stream",
            "direct": false,
            "version": "6.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "get-symbol-description",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "glob",
            "direct": false,
            "version": "7.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "glob-parent",
            "direct": false,
            "version": "5.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "glob-parent",
            "direct": false,
            "version": "6.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "globals",
            "direct": false,
            "version": "11.12.0",
            "ecosystem": "npm"
          },
          {
            "name": "globals",
            "direct": false,
            "version": "13.24.0",
            "ecosystem": "npm"
          },
          {
            "name": "globalthis",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "globby",
            "direct": false,
            "version": "11.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "gopd",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "graceful-fs",
            "direct": false,
            "version": "4.2.11",
            "ecosystem": "npm"
          },
          {
            "name": "graphemer",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "has-bigints",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "has-flag",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "has-property-descriptors",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "has-proto",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "has-symbols",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "has-tostringtag",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "hasown",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "html-encoding-sniffer",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "html-escaper",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "http-proxy-agent",
            "direct": false,
            "version": "7.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "https-proxy-agent",
            "direct": false,
            "version": "7.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "human-signals",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "husky",
            "direct": false,
            "version": "9.1.7",
            "ecosystem": "npm"
          },
          {
            "name": "iconv-lite",
            "direct": false,
            "version": "0.6.3",
            "ecosystem": "npm"
          },
          {
            "name": "ignore",
            "direct": false,
            "version": "5.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "import-fresh",
            "direct": false,
            "version": "3.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "import-local",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "imurmurhash",
            "direct": false,
            "version": "0.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "inflight",
            "direct": false,
            "version": "1.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "inherits",
            "direct": false,
            "version": "2.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "internal-slot",
            "direct": false,
            "version": "1.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "is-array-buffer",
            "direct": false,
            "version": "3.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "is-arrayish",
            "direct": false,
            "version": "0.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-async-function",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-bigint",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "is-boolean-object",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "is-callable",
            "direct": false,
            "version": "1.2.7",
            "ecosystem": "npm"
          },
          {
            "name": "is-core-module",
            "direct": false,
            "version": "2.13.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-data-view",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-date-object",
            "direct": false,
            "version": "1.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "is-extglob",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-finalizationregistry",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "is-fullwidth-code-point",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-fullwidth-code-point",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-fullwidth-code-point",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-generator-fn",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-generator-function",
            "direct": false,
            "version": "1.0.10",
            "ecosystem": "npm"
          },
          {
            "name": "is-glob",
            "direct": false,
            "version": "4.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "is-map",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "is-negative-zero",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "is-number",
            "direct": false,
            "version": "7.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-number-object",
            "direct": false,
            "version": "1.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "is-path-inside",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "is-potential-custom-element-name",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-regex",
            "direct": false,
            "version": "1.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "is-set",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "is-shared-array-buffer",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "is-stream",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-string",
            "direct": false,
            "version": "1.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "is-symbol",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "is-typed-array",
            "direct": false,
            "version": "1.1.13",
            "ecosystem": "npm"
          },
          {
            "name": "is-weakmap",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "is-weakref",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "is-weakset",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "isarray",
            "direct": false,
            "version": "2.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "isexe",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-lib-coverage",
            "direct": false,
            "version": "3.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-lib-instrument",
            "direct": false,
            "version": "5.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-lib-instrument",
            "direct": false,
            "version": "6.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-lib-report",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-lib-source-maps",
            "direct": false,
            "version": "4.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-reports",
            "direct": false,
            "version": "3.1.7",
            "ecosystem": "npm"
          },
          {
            "name": "iterator.prototype",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "jake",
            "direct": false,
            "version": "10.9.2",
            "ecosystem": "npm"
          },
          {
            "name": "jest",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-changed-files",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-circus",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-cli",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-config",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-diff",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-docblock",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-each",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-environment-jsdom",
            "direct": false,
            "version": "30.0.0-beta.3",
            "ecosystem": "npm"
          },
          {
            "name": "jest-environment-node",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-get-type",
            "direct": false,
            "version": "29.6.3",
            "ecosystem": "npm"
          },
          {
            "name": "jest-haste-map",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-leak-detector",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-localstorage-mock",
            "direct": false,
            "version": "2.4.26",
            "ecosystem": "npm"
          },
          {
            "name": "jest-matcher-utils",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-message-util",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-message-util",
            "direct": false,
            "version": "30.0.0-beta.3",
            "ecosystem": "npm"
          },
          {
            "name": "jest-mock",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-mock",
            "direct": false,
            "version": "30.0.0-beta.3",
            "ecosystem": "npm"
          },
          {
            "name": "jest-pnp-resolver",
            "direct": false,
            "version": "1.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "jest-regex-util",
            "direct": false,
            "version": "29.6.3",
            "ecosystem": "npm"
          },
          {
            "name": "jest-regex-util",
            "direct": false,
            "version": "30.0.0-beta.3",
            "ecosystem": "npm"
          },
          {
            "name": "jest-resolve",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-resolve-dependencies",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-runner",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-runtime",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-snapshot",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-util",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-util",
            "direct": false,
            "version": "30.0.0-beta.3",
            "ecosystem": "npm"
          },
          {
            "name": "jest-validate",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-watcher",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-worker",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "js-tokens",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "js-yaml",
            "direct": false,
            "version": "3.14.2",
            "ecosystem": "npm"
          },
          {
            "name": "js-yaml",
            "direct": false,
            "version": "4.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "jsdom",
            "direct": false,
            "version": "26.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "jsesc",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "json-buffer",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "json-parse-even-better-errors",
            "direct": false,
            "version": "2.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "json-schema-traverse",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "json-stable-stringify-without-jsonify",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "json5",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "json5",
            "direct": false,
            "version": "2.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "jsx-ast-utils",
            "direct": false,
            "version": "3.3.5",
            "ecosystem": "npm"
          },
          {
            "name": "keyv",
            "direct": false,
            "version": "4.5.4",
            "ecosystem": "npm"
          },
          {
            "name": "kleur",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "leven",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "levn",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "lilconfig",
            "direct": false,
            "version": "3.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "lines-and-columns",
            "direct": false,
            "version": "1.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "lint-staged",
            "direct": false,
            "version": "16.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "listr2",
            "direct": false,
            "version": "8.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "locate-path",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "locate-path",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "lodash.memoize",
            "direct": false,
            "version": "4.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "lodash.merge",
            "direct": false,
            "version": "4.6.2",
            "ecosystem": "npm"
          },
          {
            "name": "log-update",
            "direct": false,
            "version": "6.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "loose-envify",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "lru-cache",
            "direct": false,
            "version": "10.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "lru-cache",
            "direct": false,
            "version": "5.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "lz-string",
            "direct": false,
            "version": "1.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "make-dir",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "make-error",
            "direct": false,
            "version": "1.3.6",
            "ecosystem": "npm"
          },
          {
            "name": "makeerror",
            "direct": false,
            "version": "1.0.12",
            "ecosystem": "npm"
          },
          {
            "name": "merge-stream",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "merge2",
            "direct": false,
            "version": "1.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "micromatch",
            "direct": false,
            "version": "4.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "mimic-fn",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "mimic-function",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "minimatch",
            "direct": false,
            "version": "3.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "minimatch",
            "direct": false,
            "version": "5.1.9",
            "ecosystem": "npm"
          },
          {
            "name": "minimatch",
            "direct": false,
            "version": "9.0.9",
            "ecosystem": "npm"
          },
          {
            "name": "minimist",
            "direct": false,
            "version": "1.2.8",
            "ecosystem": "npm"
          },
          {
            "name": "ms",
            "direct": false,
            "version": "2.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "nano-spawn",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "natural-compare",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "node-int64",
            "direct": false,
            "version": "0.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "node-releases",
            "direct": false,
            "version": "2.0.19",
            "ecosystem": "npm"
          },
          {
            "name": "nofilter",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "normalize-path",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "npm-run-path",
            "direct": false,
            "version": "4.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "nwsapi",
            "direct": false,
            "version": "2.2.20",
            "ecosystem": "npm"
          },
          {
            "name": "object-assign",
            "direct": false,
            "version": "4.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "object-inspect",
            "direct": false,
            "version": "1.13.1",
            "ecosystem": "npm"
          },
          {
            "name": "object-keys",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "object.assign",
            "direct": false,
            "version": "4.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "object.entries",
            "direct": false,
            "version": "1.1.8",
            "ecosystem": "npm"
          },
          {
            "name": "object.fromentries",
            "direct": false,
            "version": "2.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "object.groupby",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "object.hasown",
            "direct": false,
            "version": "1.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "object.values",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "once",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "onetime",
            "direct": false,
            "version": "5.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "onetime",
            "direct": false,
            "version": "7.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "optionator",
            "direct": false,
            "version": "0.9.4",
            "ecosystem": "npm"
          },
          {
            "name": "p-limit",
            "direct": false,
            "version": "2.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "p-limit",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "p-locate",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "p-locate",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "p-try",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "parent-module",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "parse-json",
            "direct": false,
            "version": "5.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "parse5",
            "direct": false,
            "version": "7.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "path-exists",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "path-is-absolute",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "path-key",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "path-parse",
            "direct": false,
            "version": "1.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "path-type",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "picocolors",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "picomatch",
            "direct": false,
            "version": "2.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "picomatch",
            "direct": false,
            "version": "4.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "pidtree",
            "direct": false,
            "version": "0.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "pirates",
            "direct": false,
            "version": "4.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "pkg-dir",
            "direct": false,
            "version": "4.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "possible-typed-array-names",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "prelude-ls",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "prettier",
            "direct": false,
            "version": "3.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "pretty-format",
            "direct": false,
            "version": "27.5.1",
            "ecosystem": "npm"
          },
          {
            "name": "pretty-format",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "pretty-format",
            "direct": false,
            "version": "30.0.0-beta.3",
            "ecosystem": "npm"
          },
          {
            "name": "prompts",
            "direct": false,
            "version": "2.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "prop-types",
            "direct": false,
            "version": "15.8.1",
            "ecosystem": "npm"
          },
          {
            "name": "punycode",
            "direct": false,
            "version": "2.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "pure-rand",
            "direct": false,
            "version": "6.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "queue-microtask",
            "direct": false,
            "version": "1.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "react",
            "direct": false,
            "version": "18.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "react-dom",
            "direct": false,
            "version": "18.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "react-is",
            "direct": false,
            "version": "16.13.1",
            "ecosystem": "npm"
          },
          {
            "name": "react-is",
            "direct": false,
            "version": "17.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "react-is",
            "direct": false,
            "version": "18.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "reflect.getprototypeof",
            "direct": false,
            "version": "1.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "regexp-tree",
            "direct": false,
            "version": "0.1.27",
            "ecosystem": "npm"
          },
          {
            "name": "regexp.prototype.flags",
            "direct": false,
            "version": "1.5.2",
            "ecosystem": "npm"
          },
          {
            "name": "require-directory",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "resolve",
            "direct": false,
            "version": "1.22.8",
            "ecosystem": "npm"
          },
          {
            "name": "resolve",
            "direct": false,
            "version": "2.0.0-next.5",
            "ecosystem": "npm"
          },
          {
            "name": "resolve-cwd",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "resolve-from",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "resolve-from",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "resolve.exports",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "restore-cursor",
            "direct": false,
            "version": "5.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "reusify",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "rfdc",
            "direct": false,
            "version": "1.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "rimraf",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "rrweb-cssom",
            "direct": false,
            "version": "0.8.0",
            "ecosystem": "npm"
          },
          {
            "name": "run-parallel",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "safe-array-concat",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "safe-regex",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "safe-regex-test",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "safer-buffer",
            "direct": false,
            "version": "2.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "saxes",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "scheduler",
            "direct": false,
            "version": "0.23.2",
            "ecosystem": "npm"
          },
          {
            "name": "semver",
            "direct": false,
            "version": "6.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "semver",
            "direct": false,
            "version": "7.6.2",
            "ecosystem": "npm"
          },
          {
            "name": "semver",
            "direct": false,
            "version": "7.7.2",
            "ecosystem": "npm"
          },
          {
            "name": "set-function-length",
            "direct": false,
            "version": "1.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "set-function-name",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "shebang-command",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "shebang-regex",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "side-channel",
            "direct": false,
            "version": "1.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "signal-exit",
            "direct": false,
            "version": "3.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "signal-exit",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "sisteransi",
            "direct": false,
            "version": "1.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "slash",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "slice-ansi",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "slice-ansi",
            "direct": false,
            "version": "7.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "source-map",
            "direct": false,
            "version": "0.6.1",
            "ecosystem": "npm"
          },
          {
            "name": "source-map-support",
            "direct": false,
            "version": "0.5.13",
            "ecosystem": "npm"
          },
          {
            "name": "sprintf-js",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "stack-utils",
            "direct": false,
            "version": "2.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "string-argv",
            "direct": false,
            "version": "0.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "string-length",
            "direct": false,
            "version": "4.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "string-width",
            "direct": false,
            "version": "4.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "string-width",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "string.prototype.matchall",
            "direct": false,
            "version": "4.0.11",
            "ecosystem": "npm"
          },
          {
            "name": "string.prototype.trim",
            "direct": false,
            "version": "1.2.9",
            "ecosystem": "npm"
          },
          {
            "name": "string.prototype.trimend",
            "direct": false,
            "version": "1.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "string.prototype.trimstart",
            "direct": false,
            "version": "1.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "strip-ansi",
            "direct": false,
            "version": "6.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "strip-ansi",
            "direct": false,
            "version": "7.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "strip-bom",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "strip-bom",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "strip-final-newline",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "strip-json-comments",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "supports-color",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "supports-color",
            "direct": false,
            "version": "8.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "supports-preserve-symlinks-flag",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "symbol-tree",
            "direct": false,
            "version": "3.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "test-exclude",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "text-table",
            "direct": false,
            "version": "0.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "tldts",
            "direct": false,
            "version": "6.1.86",
            "ecosystem": "npm"
          },
          {
            "name": "tldts-core",
            "direct": false,
            "version": "6.1.86",
            "ecosystem": "npm"
          },
          {
            "name": "tmpl",
            "direct": false,
            "version": "1.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "to-regex-range",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "tough-cookie",
            "direct": false,
            "version": "5.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "tr46",
            "direct": false,
            "version": "5.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "ts-api-utils",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "ts-jest",
            "direct": false,
            "version": "29.3.4",
            "ecosystem": "npm"
          },
          {
            "name": "ts-node",
            "direct": false,
            "version": "10.9.2",
            "ecosystem": "npm"
          },
          {
            "name": "tsconfig-paths",
            "direct": false,
            "version": "3.15.0",
            "ecosystem": "npm"
          },
          {
            "name": "type-check",
            "direct": false,
            "version": "0.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "type-detect",
            "direct": false,
            "version": "4.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "type-fest",
            "direct": false,
            "version": "0.20.2",
            "ecosystem": "npm"
          },
          {
            "name": "type-fest",
            "direct": false,
            "version": "0.21.3",
            "ecosystem": "npm"
          },
          {
            "name": "type-fest",
            "direct": false,
            "version": "4.41.0",
            "ecosystem": "npm"
          },
          {
            "name": "typed-array-buffer",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "typed-array-byte-length",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "typed-array-byte-offset",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "typed-array-length",
            "direct": false,
            "version": "1.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "typescript",
            "direct": false,
            "version": "5.4.5",
            "ecosystem": "npm"
          },
          {
            "name": "unbox-primitive",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "undici-types",
            "direct": false,
            "version": "5.26.5",
            "ecosystem": "npm"
          },
          {
            "name": "update-browserslist-db",
            "direct": false,
            "version": "1.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "uri-js",
            "direct": false,
            "version": "4.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "v8-compile-cache-lib",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "v8-to-istanbul",
            "direct": false,
            "version": "9.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "w3c-xmlserializer",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "walker",
            "direct": false,
            "version": "1.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "webidl-conversions",
            "direct": false,
            "version": "7.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "whatwg-encoding",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "whatwg-mimetype",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "whatwg-url",
            "direct": false,
            "version": "14.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "which",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "which-boxed-primitive",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "which-builtin-type",
            "direct": false,
            "version": "1.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "which-collection",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "which-typed-array",
            "direct": false,
            "version": "1.1.15",
            "ecosystem": "npm"
          },
          {
            "name": "word-wrap",
            "direct": false,
            "version": "1.2.5",
            "ecosystem": "npm"
          },
          {
            "name": "wrap-ansi",
            "direct": false,
            "version": "7.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "wrap-ansi",
            "direct": false,
            "version": "9.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "wrappy",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "write-file-atomic",
            "direct": false,
            "version": "4.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "ws",
            "direct": false,
            "version": "8.18.2",
            "ecosystem": "npm"
          },
          {
            "name": "xml-name-validator",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "xmlchars",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "y18n",
            "direct": false,
            "version": "5.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "yallist",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "yaml",
            "direct": false,
            "version": "2.8.0",
            "ecosystem": "npm"
          },
          {
            "name": "yargs",
            "direct": false,
            "version": "17.7.2",
            "ecosystem": "npm"
          },
          {
            "name": "yargs-parser",
            "direct": false,
            "version": "21.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "yn",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "yocto-queue",
            "direct": false,
            "version": "0.1.0",
            "ecosystem": "npm"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 619,
        "direct_count": 2,
        "indirect_count": 617
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 1,
        "merged_prs": 105,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 5
      },
      "bus_factor": 2,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "akbisw",
          "commits": 188,
          "avatar_url": "https://avatars.githubusercontent.com/u/8528636?v=4"
        },
        {
          "type": "User",
          "login": "actions-user",
          "commits": 102,
          "avatar_url": "https://avatars.githubusercontent.com/u/65916846?v=4"
        },
        {
          "type": "User",
          "login": "ottokruse",
          "commits": 96,
          "avatar_url": "https://avatars.githubusercontent.com/u/6275520?v=4"
        },
        {
          "type": "User",
          "login": "EricBorland",
          "commits": 6,
          "avatar_url": "https://avatars.githubusercontent.com/u/6512144?v=4"
        },
        {
          "type": "User",
          "login": "RobHarveyDev",
          "commits": 6,
          "avatar_url": "https://avatars.githubusercontent.com/u/87716995?v=4"
        },
        {
          "type": "User",
          "login": "martinpagelaws",
          "commits": 4,
          "avatar_url": "https://avatars.githubusercontent.com/u/128691727?v=4"
        },
        {
          "type": "User",
          "login": "fahadsadiq",
          "commits": 3,
          "avatar_url": "https://avatars.githubusercontent.com/u/18647350?v=4"
        },
        {
          "type": "User",
          "login": "tinti",
          "commits": 3,
          "avatar_url": "https://avatars.githubusercontent.com/u/31630?v=4"
        },
        {
          "type": "User",
          "login": "mikemeerschaert",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/2775912?v=4"
        },
        {
          "type": "User",
          "login": "Tameyer41",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/63265436?v=4"
        }
      ],
      "contributors_sampled": 20,
      "top_contributor_share": 0.448
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "main.yml",
        "publish.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [
        ".eslintrc.cjs"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 3,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 9,
            "reason": "24 out of 25 merged PRs checked by a CI test -- score normalized to 9",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/29 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 3 contributing companies or organizations -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 3,
            "reason": "dependency not pinned by hash detected -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 10,
            "reason": "SAST tool is run on all commits",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "12 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "2ddce40e8a2b8cce16f32bf03fd4b5051de26594",
        "ran_at": "2026-07-27T16:53:56Z",
        "aggregate_score": 4.4,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-24T06:37:05Z",
      "oldest_open_prs": [
        {
          "number": 109,
          "created_at": "2026-07-20T22:38:03Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-23T16:22:55Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/joinmeow/amazon-cognito-passwordless-auth",
    "host": "github.com",
    "name": "amazon-cognito-passwordless-auth",
    "owner": "joinmeow"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 59,
      "inputs": {
        "security": 55,
        "vitality": 83,
        "community": 26,
        "governance": 68,
        "engineering": 53
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 83,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 72,
            "inputs": {
              "commits_last_year": 97,
              "human_commit_share": 0.95,
              "days_since_last_push": 4,
              "active_weeks_last_year": 11
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 4 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 4
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "11/52 weeks with commits",
                "points": 7.6,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 11
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "97 commits in the last year",
                "points": 17.9,
                "status": "partial",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 97
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 96,
              "latest_release_tag": "v1.0.104",
              "releases_from_tags": false,
              "days_since_latest_release": 6,
              "mean_days_between_releases": 32
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "96 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 96
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 6 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~32 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 32
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 4,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 4 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 4
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 26,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "critical",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 25,
            "inputs": {
              "has_readme": false,
              "has_license": false,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 66,
            "inputs": {
              "packages": [
                "@joinmeow/cognito-passwordless-auth"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 8713
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "8,713 downloads/month across npm",
                "points": 52.5,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 8713,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 68,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "moderate",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 61,
            "inputs": {
              "bus_factor": 2,
              "contributors_sampled": 20,
              "top_contributor_share": 0.448
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "2 contributor(s) cover half of all commits",
                "points": 25.2,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 45% of commits",
                "points": 12.4,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 45
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "20 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 20
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 3 contributing companies or organizations -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "moderate",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 69,
            "inputs": {
              "merged_prs": 105,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 5
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "105/110 decided PRs merged",
                "points": 36.5,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 105,
                      "decided": 110
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/29 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 51,
            "inputs": {
              "followers": 4,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "joinmeow",
              "public_repos": 4,
              "account_age_days": 2000
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "4 followers of joinmeow",
                "points": 5,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 4,
                      "login": "joinmeow"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "4 public repos, account ~5 yr old",
                "points": 16,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 4
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 5
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "@joinmeow/cognito-passwordless-auth"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 6
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 6 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "100 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 100
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 53,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 82,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "2 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": ".eslintrc.cjs",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".eslintrc.cjs"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "24 out of 25 merged PRs checked by a CI test -- score normalized to 9",
                "points": 18,
                "status": "partial",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "critical",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": false,
              "has_docs_dir": false,
              "has_description": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 55,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Packaging, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "packaging",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 44,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 4.4
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "24 out of 25 merged PRs checked by a CI test -- score normalized to 9",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/29 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 3 contributing companies or organizations -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 3",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is run on all commits",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "12 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:@joinmeow/cognito-passwordless-auth@1.0.104 runtime dependency closure — what installing the published package pulls in — 3 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:@joinmeow/cognito-passwordless-auth@1.0.104",
                  "assessed": 3
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 0,
              "affected_packages": 0,
              "assessed_packages": 3,
              "unassessed_packages": 0,
              "affected_by_severity": "none",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "no indirect dependency carries a known advisory",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "no_indirect_advisories",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 3,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 3
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 64,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.8,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "76 of 95 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 76,
                      "sampled": 95
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 69,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "package-lock.json"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "client/tsconfig.json"
              ],
              "agent_commit_share": 0.02,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0.05
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": ".eslintrc.cjs",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".eslintrc.cjs"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "client/tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "client/tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "2 of the last 100 commits agent-authored or agent-credited",
                "points": 4,
                "status": "partial",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 2,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "5 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 5,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 98,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 96149,
              "source_files_sampled": 92,
              "oversized_source_files": 3
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "3/92 source files over 60KB",
                "points": 53.2,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 92,
                      "oversized": 3
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Community profile unavailable"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-27T16:54:22.870855Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/j/joinmeow/amazon-cognito-passwordless-auth.svg",
  "full_name": "joinmeow/amazon-cognito-passwordless-auth",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsnpm.