Public record
Software health reportschema 0.26.0 · metrics 1.13.0 · 2026-07-22 03:16 UTC

kernalix7 / winpodx

Windows pod system for Linux

PythonMIT★ 1,620 stars⑂ 70 forkssince Apr 2026View on GitHub ↗

kernalix7/winpodx holds a health index of 66 out of 100, placing it in the Moderate band. It scores highest on Community & Adoption (82/100) and lowest on Security (44/100). It was last updated today. A single contributor accounts for most of its recent work.

66
overall / 100
Moderate

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

66
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

Kim DaeHyunPersonal account
39 followers17 public repossince Nov 2025

This repository is owned by a personal account. A single-owner project carries more continuity risk than an organization-backed one.

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

80Good · 22% of overall
How it's scored
36/36Push recency — last push 0 days ago
10.4/36Commit cadence — 15/52 weeks with commits
18/18Commit volume — 788 commits in the last year
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 25 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year788
human_commit_share1
days_since_last_push0
active_weeks_last_year15
How it's scored
27/27Ships releases — 38 releases published
36/36Release recency — latest release 1 days ago
27/27Release cadence — a release every ~4 days
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Inputs used
releases_count38
latest_release_tagv0.10.3
releases_from_tagsno
days_since_latest_release1
mean_days_between_releases4

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

82Good · 18% of overall
How it's scored
52.1/60Stars — 1,620 stars
15.3/25Forks — 70 forks
5.3/15Watchers — 10 watchers
Inputs used
forks70
stars1,620
watchers10
growth_stateorganic
growth_factor_pct100

Community health

92Excellent
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (MIT)
18/18CONTRIBUTING guide
13.5/13.5Code of conduct
0/7.2Issue template
6.3/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingyes
has_issue_templateno
has_code_of_conductyes
has_pull_request_templateyes

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

48At risk · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
0.7/22.5Commit distribution — top contributor authored 97% of commits
13.5/13.5Contributor breadth — 11 contributors
10/10OpenSSF Scorecard: Contributors — project has 5 contributing companies or organizations
Inputs used
bus_factor1
contributors_sampled11
top_contributor_share0.97
How it's scored
36/46.8Issue resolution — 77% of issues closed
37.6/38.3PR acceptance — 585/595 decided PRs merged
0/15OpenSSF Scorecard: Code-Review — Found 1/30 approved changesets -- score normalized to 0
Inputs used
merged_prs585
open_issues41
closed_issues137
issue_closed_ratio0.77
closed_unmerged_prs10
How it's scored
10/30Ownership backing — personal (user) account
0/20Verified domain — not applicable to user accounts
11.5/25Owner reach — 39 followers of kernalix7
10.5/25Track record — 17 public repos, account ~0 yr old
Inputs used
followers39
owner_typeUser
is_verified
owner_loginkernalix7
public_repos17
account_age_days243
Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.

Engineering Quality

Are baseline engineering and documentation practices in place?

77Good · 20% of overall
How it's scored
24/24CI workflows — 9 workflow(s)
24/24Tests present
0/16Linter config
0/9.6Pre-commit hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configno
has_precommit_configno

Documentation

90Excellent
How it's scored
30/30README
25/25Documentation directory
15/15Documentation / homepage site — https://www.winpodx.org/
10/10Repository description
0/10Topics
10/10Wiki
Inputs used
topics
has_wikiyes
homepagehttps://www.winpodx.org/
has_readmeyes
has_docs_diryes
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

44At risk · 16% of overall
How it's scored
6/7.5Binary-Artifacts — binaries present in source code
0/7.5Branch-Protection — branch protection not enabled on development/release branches
2.5/2.5CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 1/30 approved changesets -- score normalized to 0
2.5/2.5Contributors — project has 5 contributing companies or organizations
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
7.5/7.5Maintained — 30 commit(s) and 25 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — no data
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate4.3
Excluded from scoring (no data or not applicable): packaging. Remaining weights renormalized.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

45At risk · 0% of overall
How it's scored
0/45Agent instructions — no CLAUDE.md / AGENTS.md / editor rules
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 100 of 100 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share1
agent_instruction_files
agent_instruction_max_bytes
How it's scored
12.6/18One-command bootstrap — config/oem/reverse-open/shim/Cargo.toml (toolchain convention, no task runner)
22/22Automated tests
0/11Lint / format config
0/11Static type checking
10/10Reproducible environment — Dockerfile, Nix
0/10Demonstrated agent practice — no agent-authored commits among the last 100
0/8Automated maintenance — no automated dependency updates observed
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Inputs used
has_nixyes
has_testsyes
lockfiles
has_dockerfileyes
typed_languageno
bootstrap_files
has_devcontainerno
has_linter_configno
typecheck_configs
agent_commit_share0
toolchain_manifestsconfig/oem/reverse-open/shim/Cargo.toml
dependency_bot_commit_share0
How it's scored
0/45Type-checkable code — Python without a type-check config
53.7/55Manageable file sizes — 6/259 source files over 60KB
Inputs used
primary_languagePython
largest_source_bytes164,528
source_files_sampled259
oversized_source_files6

Key facts

1,620GitHub stars
11contributors
788commits, last 12 months
0days since last push
38releases
1bus factor
41open issues
PyPIpackage ecosystems

Data collection warnings

  • Could not fetch pypi package 'winpodx' from its registry
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

More detail

Star and fork history 1,620 ★ / 70 ⇿
1,620Stars
70Forks
32Releases

When each star and fork was added, collected from GitHub and bucketed by day. Cumulative growth sits directly above the daily additions it is made of, so the two read against each other: steady organic accretion looks nothing like an abrupt, short-lived burst. Where that difference is measurable, it is reported as growth authenticity.

Only the most recent history is shown — this repository exceeds the collection window, so the earliest history is not captured.

04008001,2001,6002,0001,62070892026-042026-062026-07
Major 0Minor 6Patch 24
OpenSSF Scorecard 4.3 / 10
4.3aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-22 03:16 UTC

8Binary-Artifactsbinaries present in source code
0Branch-Protectionbranch protection not enabled on development/release branches
10CI-Tests30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 1/30 approved changesets -- score normalized to 0
10Contributorsproject has 5 contributing companies or organizations
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 25 issue activity found in the last 90 days -- score normalized to 10
n/aPackagingpackaging workflow not detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
10Security-Policysecurity policy file detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
10Vulnerabilities0 existing vulnerabilities detected
Direct dependencies 1
RegistryPackageVersion constraintManifest
PyPItomli>=1.1.0pyproject.toml
All dependencies not collected

The resolved dependency set could not be collected for this report: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 17229,
      "has_wiki": true,
      "homepage": "https://www.winpodx.org/",
      "languages": {
        "ASL": 3402,
        "CSS": 21761,
        "Nix": 3836,
        "HTML": 80144,
        "Rust": 12545,
        "Shell": 165323,
        "Python": 3159055,
        "VBScript": 2329,
        "Batchfile": 43625,
        "Dockerfile": 6754,
        "JavaScript": 2657,
        "PowerShell": 178133
      },
      "pushed_at": "2026-07-22T02:54:28Z",
      "created_at": "2026-04-08T01:29:08Z",
      "owner_type": "User",
      "updated_at": "2026-07-22T02:54:33Z",
      "description": "Windows pod system for Linux",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "Python",
      "significant_languages": [
        "Python"
      ]
    },
    "owner": {
      "blog": null,
      "name": "Kim DaeHyun",
      "type": "User",
      "login": "kernalix7",
      "company": null,
      "location": "Seoul, Republic of Korea",
      "followers": 39,
      "avatar_url": "https://avatars.githubusercontent.com/u/245287466?v=4",
      "created_at": "2025-11-21T01:03:40Z",
      "is_verified": null,
      "public_repos": 17,
      "account_age_days": 243
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.10.3",
          "kind": "patch",
          "published_at": "2026-07-21T03:13:20Z"
        },
        {
          "tag": "v0.10.2",
          "kind": "patch",
          "published_at": "2026-07-20T09:05:38Z"
        },
        {
          "tag": "v0.10.1",
          "kind": "patch",
          "published_at": "2026-07-16T07:28:39Z"
        },
        {
          "tag": "v0.10.0",
          "kind": "minor",
          "published_at": "2026-07-15T01:29:17Z"
        },
        {
          "tag": "v0.9.1",
          "kind": "patch",
          "published_at": "2026-07-14T02:24:06Z"
        },
        {
          "tag": "v0.9.0",
          "kind": "minor",
          "published_at": "2026-07-11T07:39:27Z"
        },
        {
          "tag": "v0.8.0",
          "kind": "minor",
          "published_at": "2026-07-01T03:02:00Z"
        },
        {
          "tag": "v0.7.4",
          "kind": "patch",
          "published_at": "2026-06-23T06:53:21Z"
        },
        {
          "tag": "v0.7.3",
          "kind": "patch",
          "published_at": "2026-06-20T13:36:18Z"
        },
        {
          "tag": "v0.7.2",
          "kind": "patch",
          "published_at": "2026-06-15T06:18:16Z"
        },
        {
          "tag": "v0.7.1",
          "kind": "patch",
          "published_at": "2026-06-13T15:03:48Z"
        },
        {
          "tag": "v0.7.0",
          "kind": "minor",
          "published_at": "2026-06-11T07:37:44Z"
        },
        {
          "tag": "v0.6.0",
          "kind": "minor",
          "published_at": "2026-06-05T07:59:49Z"
        },
        {
          "tag": "v0.5.9",
          "kind": "patch",
          "published_at": "2026-05-27T04:35:45Z"
        },
        {
          "tag": "v0.5.8",
          "kind": "patch",
          "published_at": "2026-05-24T12:39:54Z"
        },
        {
          "tag": "v0.5.7",
          "kind": "patch",
          "published_at": "2026-05-21T13:19:50Z"
        },
        {
          "tag": "v0.5.6",
          "kind": "patch",
          "published_at": "2026-05-21T05:42:27Z"
        },
        {
          "tag": "v0.5.5",
          "kind": "patch",
          "published_at": "2026-05-21T04:15:39Z"
        },
        {
          "tag": "v0.5.4",
          "kind": "patch",
          "published_at": "2026-05-19T14:04:16Z"
        },
        {
          "tag": "v0.5.2",
          "kind": "patch",
          "published_at": "2026-05-15T04:23:53Z"
        },
        {
          "tag": "v0.5.1",
          "kind": "patch",
          "published_at": "2026-05-14T12:53:14Z"
        },
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2026-05-13T00:23:58Z"
        },
        {
          "tag": "v0.4.4",
          "kind": "patch",
          "published_at": "2026-05-10T13:12:03Z"
        },
        {
          "tag": "v0.4.3",
          "kind": "patch",
          "published_at": "2026-05-06T06:54:51Z"
        },
        {
          "tag": "v0.4.2",
          "kind": "patch",
          "published_at": "2026-05-05T13:04:06Z"
        },
        {
          "tag": "v0.4.1",
          "kind": "patch",
          "published_at": "2026-05-05T09:51:46Z"
        },
        {
          "tag": "v0.4.0rc1",
          "kind": "other",
          "published_at": "2026-05-05T08:36:08Z"
        },
        {
          "tag": "v0.3.0-RTM1",
          "kind": "prerelease",
          "published_at": "2026-05-01T02:04:16Z"
        },
        {
          "tag": "v0.2.1",
          "kind": "patch",
          "published_at": "2026-04-29T22:50:20Z"
        },
        {
          "tag": "v0.1.9",
          "kind": "patch",
          "published_at": "2026-04-25T14:51:15Z"
        },
        {
          "tag": "v0.1.8",
          "kind": "patch",
          "published_at": "2026-04-24T23:45:25Z"
        },
        {
          "tag": "v0.1.7",
          "kind": "patch",
          "published_at": "2026-04-23T05:33:19Z"
        },
        {
          "tag": "v0.1.5",
          "kind": "patch",
          "published_at": "2026-04-21T07:33:18Z"
        },
        {
          "tag": "v0.1.4",
          "kind": "patch",
          "published_at": "2026-04-21T06:25:10Z"
        },
        {
          "tag": "v0.1.3",
          "kind": "patch",
          "published_at": "2026-04-21T06:16:18Z"
        },
        {
          "tag": "v0.1.2",
          "kind": "patch",
          "published_at": "2026-04-21T06:04:28Z"
        },
        {
          "tag": "v0.1.1",
          "kind": "patch",
          "published_at": "2026-04-21T05:48:01Z"
        },
        {
          "tag": "v0.1.0",
          "kind": "minor",
          "published_at": "2026-04-20T23:03:46Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "80d92689baeeed48addef86ae35aa4ff6d1a922b",
          "body": "…odx setup) (#767) (#774)\n\nA user read the homepage's install.sh --storage-dir flag and tried it on\nwinpodx setup, which uses --storage-path, and reported the doc as wrong.\nThe doc is correct for install.sh; add a sentence noting the equivalent\nflag name when running winpodx setup directly. Synced across all 7\nweb/lang catalogs + the HTML fallback.",
          "is_bot": false,
          "headline": "docs(web): clarify --storage-dir (install.sh) vs --storage-path (winp…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-22T02:54:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c6bf3c4fca027cd555d92a2093d2f05e4fc32e23",
          "body": "…696) (#696)\n\nExpands the telemetry, ads, and widgets debloat scripts with additional\nprivacy tweaks: activity/timeline off, handwriting/ink/speech collection\nrestricted, typing insights (TIPC) off, program-launch tracking off,\nfeedback frequency zeroed, cloud + device search-history off, extra\ntele\n[…]\ne for a throwaway VM (a CompatTelRunner\nIFEO redirect, disabling SafeSearch, blocking Store app updates, cloud\nsettings-sync toggles, the location sensor, and a few app-compat-risky\nservice disables).",
          "is_bot": false,
          "headline": "debloat: add privacy-focused telemetry/ads/widgets registry tweaks (#…",
          "author_name": "GameSoul7Eugene",
          "author_login": "GameSoul7Eugene",
          "committed_at": "2026-07-22T02:50:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2e4b2f57ee26f3d5fd646bcf16a2b91585f7c81c",
          "body": "…ss (#767) (#773)\n\nWhen a leftover podman named volume from an earlier attempt still exists\n(deleting winpodx.toml does not remove it), setup hit Case 2 and silently\nkept the old storage location, ignoring an explicitly-passed\n--storage-path -- so the VM stayed on the user's btrfs home instead of\nth\n[…]\natment for a skipped --win-iso.\n- the fully-silent config_existed+non_interactive early return now prints\n  the same note when --storage-path/--win-iso were passed but ignored.\n\nthanks @realahmed7777.",
          "is_bot": false,
          "headline": "fix(setup): make an ignored --storage-path/--win-iso impossible to mi…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-22T00:24:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d238d91ef0fd371167d1beab656e522910e4801d",
          "body": "Hotfix over 0.10.2.\n\nFixed: rootless Podman RDP regression from dropping NETWORK=user in\n0.10.1 (#770); Homebrew podman-compose detection off the session PATH,\nfixing setup/doctor/tray Pod>Start (#765, #725).\n\nContributors: @vrvy-live, @realahmed7777.",
          "is_bot": false,
          "headline": "chore(release): 0.10.3 (#772)",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-21T03:03:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0885125630f2dc9bacd955c1e1ee994a0c63d020",
          "body": "…dman-compose detection (#765) (#771)\n\n#770 (thanks @vrvy-live): dropping the forced NETWORK=user in 0.10.1\n(#735) let the container auto-pick bridge NAT, but on rootless Podman\nthe guest landed on a NAT-internal 172.x address the host's forwarded\n127.0.0.1:3390 could never reach, so RDP never conne\n[…]\nbrew bin dirs + ~/.local/bin\nand returns an absolute path so the pod-start subprocess finds it\nregardless of inherited PATH. Fixed all three call sites (setup_cmd,\ndoctor, PodmanBackend._compose_cmd).",
          "is_bot": false,
          "headline": "fix: 0.10.3 hotfix — rootless network regression (#770) + Homebrew po…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-21T02:18:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e95a0da1bee231b5a0469479d3523d6b550793bc",
          "body": "Bug-fix release over 0.10.1.\n\nFixed: guest agent stays responsive during long execs (#751), installer\nno longer shadows an existing venv install on rpm-ostree hosts (#752),\nmissing compose provider fails loudly instead of a cryptic 'no such\ncontainer' (#753), pod start preflights host-port conflicts (#754).\n\nChanged: dockur image pinned to v6.02 with live download progress in\nwait-ready (#735).\n\nContributors: @notnotno, @realahmed7777, @kubycsolutions, @jltorres60,\n@kroese.",
          "is_bot": false,
          "headline": "chore(release): 0.10.2 (#766)",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-20T08:55:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "39cd875d4542ec68a0a4adc6333aae6fa10b3923",
          "body": "… follow-up) (#764)\n\n* fix(wait-ready): scrape progress tokens off completed lines too (#735 follow-up)\n\nA live experiment (alpine container printing a newline-less token,\npodman logs -f observed for 4s: zero bytes) proved podman withholds\npartial writes entirely -- the partial-tail scrape can never\n[…]\n), and the\npartial-tail scan stays for docker's raw streaming. CHANGELOG en+ko\ncorrected to describe what actually works today.\n\n* docs(changelog): drop the upstream-proposal phrasing (#735 follow-up)",
          "is_bot": false,
          "headline": "fix(wait-ready): scrape progress tokens off completed lines too (#735…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-20T07:03:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ace9e748bba013a6b2b77a370a05ce57fcf22b2f",
          "body": "…shadow false positive (#735/#752 follow-ups) (#763)\n\nSmoke findings from the first fresh install on v6.02:\n\n- When the download server reports no total size, dockur's progress.sh\n  emits a size chain (512MiB -> 1GiB -> ...) instead of percentages, so\n  the heartbeat showed only the bare clock. Scra\n[…]\nnt.\n- The install.sh PATH-shadow warning compared unnormalized strings, so\n  a PATH entry like ~/.local/share/../bin false-positived against the\n  same file. Compare realpath-normalized paths instead.",
          "is_bot": false,
          "headline": "fix(wait-ready): scrape dockur's size-mode download chain + fix PATH-…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-20T04:43:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "da8d4f00be61bdbdf5ded32609ecff5d74ad06b2",
          "body": "…ic 'no such container' (#753) (#762)\n\nThree stacked defects made a missing podman-compose look like a broken\ninstall with no usable diagnostics:\n\n- install.sh pkg_name() had no podman-compose arm in any distro branch,\n  so the detected-missing dep was 'installed' as an empty string no-op.\n  Added t\n[…]\n(Linux) apps for\nWindows Open with') so it can't be read as Windows-app discovery; app\nlist's empty-state hint points at 'winpodx app refresh'. Locale\ncatalogs (6) synced for the changed tr() sources.",
          "is_bot": false,
          "headline": "fix(install/setup): surface missing compose provider instead of crypt…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-20T02:09:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5e41203899dfb9a8af6fa114a5b426cb33c37a5b",
          "body": "…#754) (#761)\n\nUbuntu's GNOME Remote Desktop binds 127.0.0.1:3390 by default, the same\nloopback port winpodx's RDP forward uses. The bind failure happened deep\ninside podman-compose and surfaced as an hour-long boot timeout with no\ndiagnostics.\n\n- new core/pod/ports.py: bind-test preflight over the \n[…]\nend; skipped when the pod is already running/paused (it holds\n  its own ports). Covers CLI, GUI, tray and setup via the single\n  choke point.\n- winpodx doctor gains the same check (warn, no auto-fix).",
          "is_bot": false,
          "headline": "fix(pod): preflight host-port conflicts before start + doctor check (…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-20T02:06:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b99b3855008426cf82f0a5266844016df352a83b",
          "body": "…nstall (#752) (#760)\n\nA bare 'curl | bash' re-run on an rpm-ostree host (Bazzite) always took\nthe Atomic RPM-layering branch and exit 0'd, never touching an existing\n~/.local/bin/winpodx-app venv install. Since ~/.local/bin precedes\n/usr/bin on PATH, the layered RPM copy never ran and the user's wi\n[…]\nts, warn and fall\n  through to the git/venv upgrade path.\n- After install, warn when PATH resolves 'winpodx' to a different copy\n  than the one this run installed (catches any dual-install shadowing).",
          "is_bot": false,
          "headline": "fix(install): don't let the rpm-ostree path shadow an existing venv i…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-20T02:06:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0e851f278fac7b496db11f6496bbe24f24447761",
          "body": "…5 follow-up) (#757)\n\nv6.02 writes the ISO-download progress as one no-newline-until-done\nline in the container log, invisible to a line-based reader until the\ndownload completes. Read the podman-logs pipe byte-wise (_LineSplitter\n+ _iter_container_lines, bufsize=0), scrape the latest NN% off the\nst\n[…]\ninto the\ndownload heartbeat clock in both clean and --verbose modes. Complete\nlines keep identical semantics; falls back to the bare elapsed clock\nwhen no percentage has arrived (older dockur images).",
          "is_bot": false,
          "headline": "feat(wait-ready): stream dockur v6.02's live download percentage (#73…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-19T14:11:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "12d794b700a3c99b61278ad58150214760c8742f",
          "body": "- QEMU base image v7.37; improved download-progress output in the\n  container log (upstream follow-up to v6.01's buffered download);\n  better Windows reinstall detection; QEMU errors surfaced on\n  unexpected exit. Requested by @kroese.\n- Pin is the manifest-list digest of :6.02; VERSIONS.txt updated.\n  ARM pin unchanged (dockur-arm v5.16).",
          "is_bot": false,
          "headline": "chore(image): roll dockur/windows pin forward to v6.02 (#735) (#756)",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-18T15:10:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4897c5ab39260d240e6d23689e66ecb99de4bdd5",
          "body": "…uble-launch race (#751) (#755)\n\n- agent.ps1 0.2.2-rev4 -> 0.2.3: POST /exec now runs on a background\n  runspace pool (max 4) so the single-threaded accept loop no longer\n  blocks GET /health for up to 300s; the host's 5s health timeout was\n  declaring a merely-busy agent dead and falling back to Fr\n[…]\nx and logged a FATAL. Now waits 10s and re-checks process + port\n  before launching.\n- OEM bundle v28 -> v29 (guest-sync delivers to existing guests);\n  OEM-version test pins updated; CHANGELOG en+ko.",
          "is_bot": false,
          "headline": "fix(agent): keep /health responsive during long execs + kill logon do…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-18T10:44:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "11950d1cd4ec4a7e7f59c3a9e496f2dee73a2fc9",
          "body": "…heartbeat (#735 follow-up) (#750)\n\nThe heartbeat is winpodx's own self-timed line, not a dockur container log\nline, so it shouldn't wear the [container] tag the drained container lines use.",
          "is_bot": false,
          "headline": "fix(wait-ready): drop the [container] prefix on the verbose download …",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-16T07:15:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f5375fc8f119c3d9c671c59e632cfee85e039d5d",
          "body": "…5 follow-up) (#749)\n\nThe self-timed download clock only rendered in clean mode (it used the\nself-erasing live line). Under --verbose there is no live line, so the\ndownload was still a silent multi-minute gap. Add a sparse verbose heartbeat:\nprint '(downloading Windows ISO... Nm Ns)' every 15s while the download runs,\nresetting when it ends.",
          "is_bot": false,
          "headline": "fix(wait-ready): show the download heartbeat under --verbose too (#73…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-16T07:13:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9a9b4f832df908cde05365909e7b6bca779fab2a",
          "body": "… follow-up) (#748)\n\ndockur v6.01 buffers the ISO-download progress inside the container -- wget's\nbyte counter only reaches winpodx once the whole download finishes -- so\nneither a percentage bar nor a per-line spinner can ever stream (confirmed:\n`podman logs -f` directly is also not live, so it's \n[…]\n extends the\ndeadline while it runs (so a slow download can't false-timeout). Removed the\nnow-useless dots regex, spinner, and CR line-splitter + their test.\n\n+ CHANGELOG (en + ko) rewritten to match.",
          "is_bot": false,
          "headline": "fix(wait-ready): self-timed download heartbeat for dockur v6.01 (#735…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-16T07:07:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4b13e91e8446b3b419cbfe85fd0ffd6b40ad554a",
          "body": "… read (#735 follow-up) (#747)\n\nThe dots spinner + deadline-liveness added in the previous commit never\nactually ran: dockur v6.01 redraws the ISO-download progress line with a bare\ncarriage-return (no newline until the whole download ends), so the drain's\n`for line in stream` (newline-terminated) b\n[…]\nk lines on `\\r` as well\nas `\\n`, so each redraw surfaces live. v6.00's newline-terminated wget output\nand real dockur milestone lines are unaffected (same handling once split).\n\n+ CHANGELOG (en + ko).",
          "is_bot": false,
          "headline": "fix(wait-ready): stream v6.01 download progress live via CR-aware log…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-16T06:32:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "739a3550e3595230444316aa219069d4445dc634",
          "body": "* release: v0.10.1 -- bug-fix roll-up (#694 #725 #702 #735)\n\n- CHANGELOG (en + ko): [Unreleased] -> [0.10.1] - 2026-07-16, added a ### Fixed\n  section for #694 / #725 / #702 and a ### Contributors section\n  (@notnotno, @realahmed7777, @twkirk161, @MirzaAyBaig12, @kroese)\n- version bump 0.10.0 -> 0.1\n[…]\nentage isn't recoverable\nsince v6.01 doesn't emit one). v6.00 wget progress + real dockur milestones keep\ntheir existing handling.\n\n+ CHANGELOG (en + ko) Fixed entry + dots-regex discrimination tests.",
          "is_bot": false,
          "headline": "release: v0.10.1 — bug-fix roll-up (#694 #725 #702 #735) (#746)",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-16T04:47:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9c7713ee8828e2e2524e3f82a9653831bd35020a",
          "body": "…osed (#745)\n\nThe recent bug fixes surfaced gaps in the manual smoke checklist. Add:\nRAIL window icon on X11 (#702), UWP taskbar re-list (#472), multi-monitor\nsame/mixed scale (#574 / #544), XWayland discovery rc=12 (#694), a new\nNetworking section (port reachability + host DNS not leaking, #735 / #737),\nand GUI/tray Start/Stop/Restart actually acting instead of no-op (#725).",
          "is_bot": false,
          "headline": "docs(release-testing): add manual-smoke checks this cycle's fixes exp…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-16T01:49:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8810b0a1404da0ac60e0a10542c66245eeaebd40",
          "body": "…744)\n\n@kroese (dockur maintainer) traced the old #269/#387 hang to its root: on\nrootless Podman, dockur set up bridge NAT but never forwarded the published\nports on to the VM -- which is exactly why winpodx had pinned NETWORK=user\n(passt) to route around it. He rewrote the rootless-Podman NAT port-\n[…]\n / agent 8765 / SMB 4445 / web viewer 8007) reachable\n-- no regression for the common rootless case. The NAT path benefits rootful /\nprivileged hosts and is pending their confirmation (asked on #735).",
          "is_bot": false,
          "headline": "feat(pod): roll dockur to v6.01 + stop forcing NETWORK=user (#735) (#…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-16T01:33:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "46219784d5b05f5a86e71ad8d234d0fd9841bf2e",
          "body": "…(#743)\n\nX11 panels match a RAIL window to its .desktop (and its icon) by\nres_class == StartupWMClass, but some X11 DEs (Cinnamon, GNOME-X11) fail that\nmatch for FreeRDP RAIL windows -- res_name is the fixed \"RAIL\" and no\n_NET_WM_ICON is set -- so they show FreeRDP's own icon instead (#702,\ntwkirk16\n[…]\nnd only; a clean no-op off X11 or when Qt / libX11 / wmctrl are\nmissing. Verified on XWayland (icon shows + window re-lists in the taskbar);\nneeds Cinnamon / GNOME-X11 confirmation from the reporters.",
          "is_bot": false,
          "headline": "fix(rdp): stamp the app icon on RAIL windows via _NET_WM_ICON (#702) …",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-16T00:43:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d9579e3bae2874b0de5b8d8795d86403547e6b85",
          "body": "… (#739)\n\nThe #573 fix gave submenu actions a parent, but the top-level menu actions\n(Start/Stop/Restart Pod, Open Dashboard, Quit, Full Desktop, Maintenance\nentries, ...) stayed parentless. On KDE Plasma the DBusMenu export can\ngarbage-collect a parentless QAction, so its 'triggered' never fires an\n[…]\nzzite / KDE Wayland: the tray right-click Stop Pod\n(and Start) do nothing, while 'winpodx pod stop' on the CLI works. (The GUI\nsquare Stop button is a QPushButton, not GC-prone -- tracked separately.)",
          "is_bot": false,
          "headline": "fix(tray): parent top-level QActions so Plasma doesn't GC them (#725)…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-15T07:33:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a5dc706bb6448140b4cc23f78930b04dcb1c7d0c",
          "body": "…rc=12 (#694) (#738)\n\nThe exec/discovery RemoteApp runs a PowerShell script headless (the window is\nnever shown), but FreeRDP's default GFX pipeline still tries to map a RAIL\nsurface, and on XWayland that fails (\"xf_MapWindowForSurface: function not\nimplemented\") and aborts the session with no resul\n[…]\nditionally to this channel (not the visible RAIL app launches).\n\nReported by @notnotno while verifying the #421/#694 URL-scheme fix on Fedora\nKinoite 44 / FreeRDP 3.27.1 / KDE Plasma Wayland+XWayland.",
          "is_bot": false,
          "headline": "fix(discovery): disable GFX on the headless exec channel -- XWayland …",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-15T06:10:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e9dc2e8d85b3e3fc1cdedbc060e6177447b02fd1",
          "body": "* docs(changelog): correct v6.00 networking + env-var descriptions (#721 feedback)\n\nPer @kroese's feedback on #721: (a) v6.00 does not switch Podman to passt --\nit broadens NAT so passt fallback happens less often; winpodx still pins\nNETWORK=user (passt) deliberately, revisited in #735. (b) DISK_IO/\n[…]\nsed] -> [0.10.0] - 2026-07-15, + Contributors (@kroese)\n\nMinor bump for the dockur/windows v6.00 networking-backend roll-forward\n(#721, requested by @kroese). Details + follow-up #735 in CHANGELOG.md.",
          "is_bot": false,
          "headline": "release: v0.10.0 — dockur v6.00 roll-forward (passt networking) (#736)",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-15T01:19:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7984b84671801640d855d993dcef098efffb4acd",
          "body": "…follow-up) (#732)\n\nThe v6.00 roll-forward wired DISK_IO:\"io_uring\" from the tuning profile, but\nthe container backend's default seccomp blocks io_uring_setup with ENOSYS, so\nQEMU falls back to the thread pool and only logs an error -- no benefit inside\nthe container. That's the real reason io_uring\n[…]\nSmoke (v6.00 clean install, rootless podman): \"qemu: Unable to use linux\nio_uring, falling back to thread pool: Function not implemented\" -- confirmed a\nharmless fallback but noisy; removed the cause.",
          "is_bot": false,
          "headline": "fix(pod): drop DISK_IO:io_uring -- container seccomp blocks it (#721 …",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-14T08:08:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7e4a88ca0a3ece383ec1fc1b12cca899ecd5ac6f",
          "body": "…21) (#729)\n\nRequested by @kroese (dockur/windows maintainer). dockur v6.00 moves\nPodman networking to the user-mode passt backend, fixing the rootless\nport-forwarding problems that affected earlier images.\n\n- pin DOCKUR_IMAGE_PIN to v6.00 (5f8b87b0, == current :latest list digest)\n- VERSIONS.txt x8\n[…]\nst)\n- CHANGELOG (en + ko), compose env regression tests\n\nBoot smoke: container comes up in Mode: User (passt); RDP 3390 / agent\n8765 / SMB 4445 all reachable; bare-metal disguise (SMBIOS/ACPI) intact.",
          "is_bot": false,
          "headline": "feat(pod): roll dockur image forward to v6.00 -- passt networking (#7…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-14T07:06:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d2305c908928291d13d4483d8ad38f61b2ba3e70",
          "body": "Version badge 0.9.0->0.9.1 + the new reverse-open app-launcher capability (#616) across HTML + 7 locales.",
          "is_bot": false,
          "headline": "docs(web): homepage 0.9.1 + reverse-open app-launcher (#616)",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-14T02:24:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6795c0940c1ca1fee7660ecf394c234b1fb03108",
          "body": "Version 0.9.0 -> 0.9.1 (bug-fix + hardening: #716 data-loss, #720/#722 install/uninstall/packaging hardening, #616 app-launcher, #712 libxcb-cursor, #723 reinstall discovery). pyproject/rpm/debian + README(en/ko) + CHANGELOG(en/ko) [0.9.1] + Contributors (@notnotno, @numericOverflow, @munir-abbasi).",
          "is_bot": false,
          "headline": "chore(release): stamp 0.9.1",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-14T02:14:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3e2dda7d37119750916bd25bf40d65fb035c2c83",
          "body": "Gate fixes: install.sh rollback marker rm now guarded (was rollback()'s first line; a failing rm under set -e aborted the ERR-trap restore, stranding the user with no install + no restore); shim main.rs gains SPDX-License-Identifier: MIT + rebuilt exe.\n\nRefs #716",
          "is_bot": false,
          "headline": "fix: guard rollback marker-removal + SPDX header on shim (0.9.1 gate)",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-14T02:09:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9e958d84630d66f2fb86ebfd00e136f727a9f710",
          "body": "… menu\n\nA non-purge uninstall removes the app .desktop entries but keeps the config, so a reinstall was 'already current' and never re-ran discovery -> empty menu / first-run until the GUI self-healed. The 'already current' migrate path now queues discovery when the app menu is empty (new _apps_registered helper). Found via real reinstall-after-uninstall smoke.",
          "is_bot": false,
          "headline": "fix(migrate): reinstall after non-purge uninstall repopulates the app…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-14T01:35:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "47186193dfa4cf996e6ae9da4e3984970fa72f27",
          "body": "…e (#716 follow-up)\n\nA non-purge uninstall keeps the config but removes the install dir, so a reinstall took the upgrade path with no INSTALL_DIR to move aside -> mv failed and the install aborted. Only stash INSTALL_DIR when it exists; otherwise drop the staged tree straight in. 3-case smoke + install.sh tests pass.\n\nRefs #716",
          "is_bot": false,
          "headline": "fix(install): atomic swap must handle a missing INSTALL_DIR on upgrad…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-13T07:49:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fc87d9e5bce6563b7519b9fb8fd3cd6d698c122f",
          "body": "4-lens audit follow-up to #716: uninstall --purge actually purges (was exec-then-skip), storage_path read from config + absolute-path guard; package cleanup moved to pre-remove hooks (deb prerm / rpm %preun / pacman pre_remove) so apt/dnf/pacman removal actually cleans up and upgrades never touch user data; install.sh atomic upgrade swap + XDG_CONFIG_HOME + pip-symlink backup + honest setup status. bash -n/shellcheck/35 tests/uninstall smoke all pass.\n\nRefs #716",
          "is_bot": false,
          "headline": "fix: install/uninstall/packaging hardening (#716 deep audit)",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-13T05:23:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4cdbbbb2624d51aa02d9962a32e172cd94ff28d8",
          "body": "Data-loss fix (thanks @munir-abbasi): a non-purge uninstall recursively rm -rf'd\n~/.local/share/winpodx, deleting the VM disk under storage/. Now preserves the\nstorage subtree unless --purge. Audit follow-ups: resolve real storage_path from\nwinpodx.toml, require absolute path, always keep a top-level storage entry, and\nguard the desktop-entry find under set -euo pipefail. Regression tests in\ntests/uninstall_smoke.sh (postrm re-entry path).\n\nReported-by: @munir-abbasi (#716)",
          "is_bot": false,
          "headline": "fix(uninstall): non-purge must not delete the Windows VM disk (#716)",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-13T04:23:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "229d98fb2b84b34cb6befa0d8c2cf07e21053f77",
          "body": "…(#712)\n\nThe #712 fix probed ldconfig -p, but on openSUSE libxcb-cursor.so.0 exists in\n/usr/lib64 yet is absent from the ld.so cache, so it re-prompted every run even\nwith libxcb-cursor0 installed. Detection now checks the real .so across the\nstandard lib dirs (incl. Debian/Ubuntu multiarch), ldconfig fallback only.\n\nRefs #712",
          "is_bot": false,
          "headline": "fix(install): detect libxcb-cursor by real .so on disk, not ldconfig …",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-12T14:13:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0ce50fa7ca2765e87a8f163dd9ec24372e68bade",
          "body": "…rtcut (#616)\n\nClicking a Linux app's 'Linux Apps' shortcut directly (no file) did nothing:\nthe guest shim required a file argument and exited before writing any request.\nGuest shim now emits a launch-only request (origin='launch', empty path); the\nhost listener spawns the app with the %f/%u placeho\n[…]\nped rather than\nfilled. Rebuilt the Windows shim (x86_64-pc-windows-gnu); cargo/ruff clean,\nreverse_open suite 355 passed.\n\nNEEDS real-Windows smoke (guest shim change).\n\nReported-by: @notnotno (#616)",
          "is_bot": false,
          "headline": "feat(reverse-open): run a Linux app with no file from its Windows sho…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-12T13:54:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4d825df2d5aaf7b419ed843b68d8737931b1029c",
          "body": "…esktops (#712)\n\nQt 6.5+ (PySide6) refuses to start its xcb platform plugin without\nlibxcb-cursor.so.0, and it isn't pulled in transitively on a fresh minimal\ninstall (e.g. Linux Mint 22). install.sh now installs it when the GUI is enabled\nand the lib isn't present (ldconfig probe), mapped per-distro (libxcb-cursor0 on\nDebian/Ubuntu/openSUSE, xcb-util-cursor on Fedora/Arch).\n\nReported-by: @numericOverflow (#712)",
          "is_bot": false,
          "headline": "fix(install): auto-install libxcb-cursor0 for the Qt GUI on minimal d…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-11T14:21:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9d717edad4cc55c84519c6e8f19843303bf7dbcf",
          "body": "Marketing-site refresh for 0.9.0: version bump across all 7 locales, new\nURL-scheme handler feature (opt-in wording for http/https per the security\nchange), reverse-open of guest files + idle auto-stop, and a truthfulness fix\nremoving the stale USB drive-letter auto-map claim (removed in 0.7.3).",
          "is_bot": false,
          "headline": "docs(web): homepage 0.9.0 update + truthfulness fixes",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-11T09:44:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "22d0e5f1f727331bf3d89a573b65afec4ae1579b",
          "body": "The 0.9.0 AppImage build hard-failed at the LGPL compliance gate because the\nPySide6 wheels ship no license text. Vendor the verbatim GPL-3.0 + LGPL-3.0\ntexts (from the Qt6 system package) + a NOTICE under\npackaging/appimage/licenses/pyside6/; the build copies those in.\n\nRefs #710",
          "is_bot": false,
          "headline": "fix(appimage): vendor PySide6/Qt LGPL texts for the compliance gate",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-11T08:06:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "15349beaf4fb7eefc30abdb01b506f870d7a78e3",
          "body": "Version bump 0.8.0 -> 0.9.0 (minor: URL-scheme handler feature + trust-boundary\nhardening). pyproject/rpm/debian + README(en/ko) + CHANGELOG(en/ko) [0.9.0]\nheading with ### Contributors (@notnotno, @twkirk161, @mdshahalam3,\n@ajeshchrist, @numericOverflow, @GameSoul7Eugene).",
          "is_bot": false,
          "headline": "chore(release): stamp 0.9.0",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-11T07:25:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b9fb0e87aae51893a21ca238a4ca7aae68c097bb",
          "body": "…, #697)\n\nRelease-gate follow-ups (docs + packaging only, no runtime code):\n\n- CHANGELOG en+ko: fix #697 attribution (@notnotno -> @twkirk161); add the\n  #669/#684 debloat expansion crediting @GameSoul7Eugene; document the two\n  security-gate fixes.\n- AppImage LGPL: build now copies PySide6/Qt licen\n[…]\n the dist-info carries them.\n- Apache-2.0 alignment: debian/copyright 'MIT and Apache-2.0' + standalone\n  paragraph; AUR PKGBUILD license array adds Apache-2.0 (matches RPM spec).\n\nRefs #669 #684 #697",
          "is_bot": false,
          "headline": "docs(release): 0.8.1 changelog + license compliance fixes (#669, #684…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-11T06:34:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "03e069dc7bee84832df67466fcb4755b24f08889",
          "body": "… (#421, #694, #680)\n\nPre-release security gate (5-team review, adversarially verified):\n\n1. Guest web-handler hijack — NEVER_AUTO_DEFAULT_SCHEMES (http/https) so a\n   discovered semi-trusted guest app can't seize the host web-link default via\n   the xdg-mime grab; they stay routable + candidate han\n[…]\n— kill_session gains expected_pid; both reapers\n   snapshot the PID they armed against and reap only if the .cproc still holds it.\n\nFull suite: 2153 passed, 2 skipped; ruff clean.\n\nRefs #421 #694 #680",
          "is_bot": false,
          "headline": "fix(security): close guest web-handler hijack + reaper mis-kill races…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-11T06:34:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ebb078ec28a5dc7b008f49483b3c467669f01f57",
          "body": "Update the VERSIONS.txt baseline (tag + :latest digest) for dockur/windows-arm\nv5.15 -> v5.16 so the weekly upstream checker goes quiet. DOCKUR_IMAGE_ARM_PIN\nis left at v5.15 deliberately (no aarch64 host to smoke v5.16-arm); pin\nroll-forward deferred to ARM host support (#140, #141). x86 already tracks v5.16.\n\nRefs #682",
          "is_bot": false,
          "headline": "chore(deps): baseline dockur-arm to v5.16 (#682)",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-10T06:06:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "85d48505076a78ef70769ef566541ee9dfc40f64",
          "body": "…#705)\n\nFresh systems without git (e.g. Linux Mint 22) failed the curl|bash installer\nat the clone step, even though every other dependency is auto-installed.\ninstall.sh now installs git via the existing install_pkg path before cloning,\nand only errors (with a manual-install hint) if the package manager can't\nprovide it.\n\nReported-by: @numericOverflow (#705)",
          "is_bot": false,
          "headline": "fix(install): auto-install git in the one-liner instead of aborting (…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-10T04:50:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "db5ac7d060cac275989ee8ccc6d20ea622619983",
          "body": "Completes the host-side #701 groundwork: discover_apps.ps1 harvests each app URL\nschemes (per-scheme UserChoice default, per-app Capabilities\\URLAssociations, UWP\nmanifest windows.protocol) into the url_schemes array, mirroring the proven file-\nextension harvest (Add-SchemeTo/Build-SchemeMap/Get-App\n[…]\nbcal/tel/..., phone-link got tel, per-app UWP protocols\ncaptured, dangerous schemes filtered; a subsequent app refresh backfilled\nurl_schemes into all 27 app.toml files.\n\nReported-by: @notnotno (#694)",
          "is_bot": false,
          "headline": "feat(discovery): guest URL-scheme harvest + backfill (#694, #421)",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-08T03:11:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "127d0d43843a0dd398c07075e70dfc219f321cfb",
          "body": "… #694)\n\nHost-side groundwork so clicking a URL on the Linux host opens it in the Windows\napp that handles that scheme (mailto:->Outlook, https:, slack:, vnc:, ...). New\nleaf policy module core/url_schemes.py (SAFE_SCHEME_RE + DANGEROUS_SCHEMES +\nurl_scheme_of + sanitize_url_arg) shared by discovery\n[…]\n. Three\nsecurity gates: scheme regex forbids inner colon, denylist, sanitize_url_arg.\nHost-only + 310 tests. Guest discover_apps.ps1 scheme harvest is a separate\nsmoke-gated follow-up.\n\nRefs #421 #694",
          "is_bot": false,
          "headline": "feat(url-scheme): host-side forward URL-scheme handler support (#421,…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-08T00:29:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1ad3273c41dba1643a7ac7ba3e9448672f6d458f",
          "body": "…c (#697)\n\nkio_fuse_available() only checked the kio-fuse binary in a fixed path set, so\ndistros that put it elsewhere read as \"not installed\" even though reverse-open\nguest-disk mounting works (Fedora Kinoite / KF6-versioned libexec; Debian\nmultiarch /usr/lib/<triplet>/libexec/kio-fuse, missed by t\n[…]\ntative signal,\nprobe the org.kde.KIOFuse D-Bus activation service file across XDG_DATA_DIRS --\nwhich is exactly what _kio_fuse_mount calls. No regression on the dev box.\n\nReported-by: @notnotno (#697)",
          "is_bot": false,
          "headline": "fix(guest-disk): detect kio-fuse via D-Bus service + multiarch libexe…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-07T07:53:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fc4ac282cf684e4650ee65a20283648639508a26",
          "body": "…up, stop on Quit (#691)\n\nThe listener was only (re)started by pod start / the app-launch ensure_ready\npath, so a GUI/tray-only start (incl. login autostart) left Windows->Linux\n\"Open with\" silently dead. And Quit killed it only as collateral: the double-\nforked daemon inherits its parent argv, so p\n[…]\nrunning self-heal at startup (off the UI thread) and\nQuit calls stop_listener() explicitly. Live-verified: dead listener + running\npod -> tray-startup ensure revives it.\n\nReported-by: @notnotno (#691)",
          "is_bot": false,
          "headline": "fix(tray): own the reverse-open listener lifecycle -- ensure at start…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-06T06:29:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "18f04aace6fac47851315d910a70e17aa617b514",
          "body": "…r + SLOT (#690)\n\nQDBusConnection.connect has no overload taking a bare Python callable; the tray\npassed the plain handler, PySide6 raised \"called with wrong argument types\", and\nthe TypeError guard downgraded it to a per-start warning -- so the fast\nsuspend/resume recovery (#225) never actually sub\n[…]\ny icon so the receiver is not\nGC-d out from under the connection. Live-verified: subscribe ok against\norg.freedesktop.login1; old form reproduces the reported TypeError.\n\nReported-by: @notnotno (#690)",
          "is_bot": false,
          "headline": "fix(tray): PrepareForSleep D-Bus subscription needs a QObject receive…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-06T05:32:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d7c62bf1fcade93915e381225374f7e47ab2e178",
          "body": "…immed to safe scope (#684)\n\nRefactors ads / web_search / visual_effects into value arrays and adds a few\nRDP-friendly visual-effect disables (Aero Peek, saved-thumbnail caching; keeps\nthumbnails + font smoothing on). Explicit -Type restored on every\nSet-ItemProperty.\n\nTrimmed on review to the safe,\n[…]\nd the\nspeculative DragFullWindows=0; kept the UserPreferencesMask + ListView values at\ntheir prior tested settings.\n\nCo-authored-by: GameSoul7Eugene <59319082+GameSoul7Eugene@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(debloat): array refactor + RDP-friendly visual-effect tweaks, tr…",
          "author_name": "GameSoul7Eugene",
          "author_login": "GameSoul7Eugene",
          "committed_at": "2026-07-03T07:29:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6ebbd699a0ae2fb26bff13ce2380f72f46c6039f",
          "body": "…ting app-run (#680)\n\nRefs #680. The per-launch _window_reaper (#687) never fired on the real launch\npaths -- `winpodx app run` returns immediately unless --wait (app.py:352), so its\ndaemon thread died at once, and menu .desktop entries + the reporter CLI both use\nplain `app run`. Moved reaping into\n[…]\nn once a window\nhas stayed gone for a 6s debounce. Safe-by-omission. Live-verified: a visible app\nis not reaped; a lingering session dies ~9s after its window closes.\n\nReported-by: @mdshahalam3 (#680)",
          "is_bot": false,
          "headline": "fix(daemon): reap RAIL sessions from the long-lived tray, not the exi…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-03T06:14:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "89ca8f357ae84f847ebcdf88bea14da6b80f1dd7",
          "body": "…680/#675)\n\nRefs #680 #675. Under multi-session guest RDP a warm delivery connection lands\nin a different session than the visible app, so the old warm path just spun ~30s\nbefore a fresh spawn -- removed it: opening a file while the app runs goes\nstraight to a fresh RAIL window with the file (unmapp\n[…]\nSessionIds so a lock screen in another session no\nlonger flips the app session to LOCKED. Deletes dead _open_file_in_session +\n_WARM_READY_PROBE.\n\nReported-by: @mdshahalam3 (#680), @ajeshchrist (#675)",
          "is_bot": false,
          "headline": "fix(rdp): drop futile warm delivery + session-scope the lock probe (#…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-03T04:32:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4cd4ade82ed39a820ee7115a6ec9d74368c42176",
          "body": "…inate)\n\nRefs #680. _reaper_thread only proc.wait()s the xfreerdp PID, which exits only\nwhen the guest disconnects; Office keeps its process + RemoteApp session resident\nafter the document window closes, so the session never terminated (app RUNNING\nforever, half-stuck \\tsclient\\home). A host-side _w\n[…]\nterminates the session\nvia kill_session. Safe-by-omission (no wmctrl / scan error / no window ever\nappeared -> no-op); RemoteApp only. Smoke-verified on a live guest.\n\nReported-by: @mdshahalam3 (#680)",
          "is_bot": false,
          "headline": "fix(rdp): reap a RAIL session when its windows close (#680 never-term…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-03T04:06:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c352ae9650c5166e80ba02d648018a85b8d69c88",
          "body": "Refs #680. Run the FreeRDP subprocess with WLOG_FILTER=com.winpr.commandline:FATAL\nto mute the cosmetic per-launch [get_next_comma]: Invalid quoted argument warning\n(from the quoted cmd:\"<UNC>\" form kept for spaced paths, #473). Delivered argv\nunchanged; /log-filters flag parses too late so the env var is used instead.\n\nReported-by: @mdshahalam3 (#680)",
          "is_bot": false,
          "headline": "fix(rdp): silence FreeRDP get_next_comma warning via WLOG_FILTER (#680)",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-03T01:51:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e7e5c8c33d4b8f2382b0ecca05a4e115c3e84d35",
          "body": "…0 regression)\n\nRefs #680. 0.8.0 Start-Menu-only discovery read each shortcut raw .TargetPath;\nMSI installs (Office 2016) use advertised shortcuts (Darwin descriptors) whose\ntarget resolves to a shared icon stub under C:\\Windows\\Installer\\{ProductCode}\\\n(xlicons.exe etc., all described \"Microsoft Of\n[…]\nne dead entry and vanished from\n`winpodx app list`. Now resolved to the real installed exe via\nMsiGetShortcutTarget + MsiGetComponentPath; normal shortcuts unchanged.\n\nReported-by: @mdshahalam3 (#680)",
          "is_bot": false,
          "headline": "fix(discovery): resolve advertised MSI shortcuts to the real exe (#68…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-03T01:07:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1123f664825fbb1111fce79107a4138bbd1a5275",
          "body": "…ssion agent (#680)\n\nThe already-running-app file delivery used the HTTP agent's Start-Process, but\nthe agent runs in the autologon console session, which has no per-RDP-session\n\\\\tsclient\\home drive redirect. So Start-Process <app> \\\\tsclient\\home\\doc opened\na path that did not exist there -- the a\n[…]\n(run_in_windows,\nwhich carries +home-drive -> \\\\tsclient\\home), so the document reaches the\nvisible instance. The agent channel is dropped from _open_file_in_session.\n\nReported-by: @mdshahalam3 (#680)",
          "is_bot": false,
          "headline": "fix(rdp): deliver \"Open with\" files via RemoteApp, not the console-se…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-02T07:13:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "257cd6f91e7f0c7e84e7adfea979681301e90e86",
          "body": "…est session is locked (#675)\n\nRight-clicking a document -> \"Open with <app>\" silently did nothing once the\napp was already running, and (on a slow guest) kept failing after a couple of\nopens once the RDP session had cycled to the lock/logon screen.\n\n- The already-running-session path swallowed ever\n[…]\name.\n- Hardened the silent-failure surface: .desktop Exec uses %f, and notify-send /\n  file:// URIs resolve by absolute path so toasts + args survive a stripped PATH.\n\nReported-by: @ajeshchrist (#675)",
          "is_bot": false,
          "headline": "fix(rdp): \"Open with\" works when the app is already running or the gu…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-07-02T06:08:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dfbc6e69a3392e23add312422745be6b8f6abad8",
          "body": "…afe scope (#669)\n\nAdds a broader set of HKCU advertising / suggestion opt-outs (File Explorer,\nStart-menu recommendations & account nags, tailored experiences, advertising ID,\nlock-screen tips, Settings suggested content, ContentDeliveryManager switches)\nand the SQM (CEIP) scheduled task, plus more\n[…]\nInfo) so the scope\nstays telemetry/ad-only per the scheduled_tasks header and PR #590. Undo scripts\nkept symmetric.\n\nCo-authored-by: GameSoul7Eugene <59319082+GameSoul7Eugene@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(debloat): expand ad/suggestion opt-outs + SQM task, trimmed to s…",
          "author_name": "GameSoul7Eugene",
          "author_login": "GameSoul7Eugene",
          "committed_at": "2026-07-02T05:36:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d1a2cf155ebaef353b19d912b935f153a164417e",
          "body": "This cycle flips the app-discovery DEFAULT (Start-Menu-only, #581) and migrates\nthe menu on refresh (removes apps no longer discovered) + adds Start Menu folder\ngrouping — a default-behaviour change + new feature, so it's a minor bump per the\nproject's convention (minors = feature/behaviour shifts: \n[…]\n heading\n/ README[.ko] / THIRD_PARTY_LICENSES note / web badges + 7 lang JSONs +\ntranslations.js / one test docstring. netavark's vendored 'yoke v0.7.5' left\nuntouched. verify_versions OK; ruff clean.",
          "is_bot": false,
          "headline": "chore(release): retarget 0.7.5 -> 0.8.0 (#679)",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-06-30T04:29:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4e96b8a6a402842c630a26b107d7ce7e03511e01",
          "body": "…s, homepage) (#678)\n\nPre-release prep surfaced by the 5-team review (security/audit/legal all clean):\n\n- Version 0.7.4 -> 0.7.5: pyproject.toml, packaging/rpm/winpodx.spec, debian/changelog\n  (verify_versions OK; __version__ derives from metadata, flake.nix from pyproject).\n- CHANGELOG.md + docs/CH\n[…]\nd\n  translations.js (no more 0.7.4).\n\nNo src/ code change (the 0.7.5 features/fixes already merged via #659/#660/#581/\n#666/#674/#676/#677). Tag (v0.7.5 + REL-v0.7.5) only AFTER user smoke + approval.",
          "is_bot": false,
          "headline": "chore(release): prepare 0.7.5 (version, CHANGELOG + Contributors, doc…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-06-30T03:15:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "15a7df3cd9cba75cfeacc6ac48142b0b90fce589",
          "body": "…cursion SIGSEGV (#553) (#677)\n\n#550 — the Debloat/maintenance BusyDialog never auto-closed. _run_busy_op\nmarshaled the close with QTimer.singleShot(0, dlg.finish) from inside the\nworker, but that worker is a bare threading.Thread with no Qt event loop, so\nthe timer never fired and the dialog hung o\n[…]\nialog; empty-panel wrap labels are fixed-width.\n\nFollow-up (flagged, not in this PR): reverse_open_panel.py has the same\nworker-thread QTimer.singleShot(0, _done) pattern and needs its own marshaling.",
          "is_bot": false,
          "headline": "fix(gui): BusyDialog auto-close from worker thread (#550) + layout-re…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-06-30T02:39:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bc13d0d0e1fbe43c6c56753a7b6f6814c2ff6d57",
          "body": "…SIGSEGV) (#676)\n\nThe parentless, Python-owned DiscoveryWorker had TWO delete paths: its own\nworker.deleteLater on the worker thread AND the Python ref-drop in\n_cleanup_refresh_worker on the main thread. Qt6 QThreadPrivate::finish() emits\nQThread.finished BEFORE it flushes the worker's DeferredDelet\n[…]\n WinpodxWindow.closeEvent joins in-flight refresh/info worker threads so a\n  close mid-scan can't destroy a running QThread.\n\nStructural-invariant guard test added (this teardown has regressed twice).",
          "is_bot": false,
          "headline": "fix(gui): stop Refresh Apps double-freeing the worker on completion (…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-06-29T23:20:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "471e05bcb2021e15baa84e7528f903650bfc10dd",
          "body": "…674)\n\nThe GUI's worker threads (InfoWorker running gather_info -> _display_section\n-> scaling, and other background probes) reached _qt_max_device_pixel_ratio,\nwhich calls QGuiApplication.screens(). QScreen / QGuiApplication.screens() are\nGUI-thread-only: off-thread they emit 'QObject::setParent: .\n[…]\neturn None on any non-main thread so callers fall back to the\nsubprocess / env scale detection. Pre-existing latent bug (not introduced by\n#581); fixed now since it breaks the GUI on main. Test added.",
          "is_bot": false,
          "headline": "fix(gui): don't call QGuiApplication.screens() off the main thread (#…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-06-29T07:21:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c88a5107388717ed8ef5faa5e97db30ca601d601",
          "body": "…chy (#581) (#673)\n\n* feat(discovery): default to Start-Menu-only app detection (#581)\n\nDiscovery scanned 5 sources (registry App Paths, Start Menu .lnk, all UWP,\nchoco/scoop shims) and dumped everything into the Linux menu, flooding it with\nuninstallers, helpers and background exes (#581, @Milliw).\n[…]\n are already absent, no special handling.\n\nAlso fixes the long-standing guest-uninstall-doesn't-sync case the docstring\nalready claimed. Tests: prune-on-shrink, empty-scan-no-wipe, user-dir-untouched.",
          "is_bot": false,
          "headline": "feat(discovery): Start-Menu-only detection + Start Menu folder hierar…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-06-29T05:32:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e76b27adf4619417db1d75cc6bad2108efc9c537",
          "body": "Problem 1 (/kbd blocked by the extra_flags allowlist) was fixed in 0.7.4.\nThis adds Problem 2: cfg.pod.keyboard (the dockur install locale, e.g.\n\"hu-HU\") is now mapped to a Windows keyboard-layout id and appended to the\nFreeRDP command as /kbd:layout:0x..., so non-US keyboards work without\nhand-writ\n[…]\n, so users who never set keyboard aren't forced onto US.\n- a user-supplied /kbd in extra_flags always wins (no duplicate appended).\n- an unmapped locale falls back to auto-detect (debug log, no flag).",
          "is_bot": false,
          "headline": "feat(rdp): propagate pod.keyboard to FreeRDP /kbd:layout (#660) (#672)",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-06-29T05:20:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e22379b2616084371f42f7f0ac9372986f0c63d8",
          "body": "…#671)\n\nThe all-OK doctor fixtures stubbed every check except _check_rootless_subid,\nso handle_doctor ran the real /etc/subuid probe. In hermetic build sandboxes\nwithout UID/GID mappings (nix, #659) that probe returns FAIL -> sys.exit(1),\nspuriously erroring the --fix tests and blocking nixos-rebuild. Stub it like\nthe other checks so the all-OK path is environment-independent.",
          "is_bot": false,
          "headline": "test: make doctor _all_ok_legacy hermetic re: rootless subid (#659) (…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-06-29T05:20:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e4dd7d5d0d97cb7d441f05ac3515175da3755ff0",
          "body": "…47) (#666)\n\nThe local ISO was staged into <storage>/custom.iso *after* `winpodx setup`\nhad already run `compose up` — the container booted and dockur began its\nMicrosoft download before the file existed (dockur's findFile() looks for\ncustom.iso the moment it boots). So --win-iso silently downloaded\n[…]\nmoved the old\n  post-setup staging block that ran too late.\n\nTests: _stage_win_iso none/stage/no-storage/missing/same-file (5).\nNEEDS a real --win-iso install smoke before release (guest-side timing).",
          "is_bot": false,
          "headline": "fix(install): stage --win-iso before compose-up so dockur uses it (#6…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-06-27T09:54:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "239fa3c28a3094fab6c9f829c7f39c92ae89814d",
          "body": "* chore(oem): bump bundled rdprrap 0.1.3 -> 0.3.0\n\nrdprrap 0.3.0 derives its termsrv.dll patch sites dynamically (runtime\ndisassembly + a hand-rolled x86/x64 encoder) instead of hardcoded offsets/\nregisters/byte templates, so multi-session survives termsrv.dll struct-layout\nshifts across Windows bui\n[…]\n-Windows smoke before release: confirm rdprrap 0.3.0 installs +\nmulti-session activates (two RemoteApp windows = two sessions).\n\n* test: bump OEM-version guards 27 -> 28 for the rdprrap 0.3.0 OEM bump",
          "is_bot": false,
          "headline": "chore(oem): bump bundled rdprrap 0.1.3 → 0.3.0 (#667)",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-06-27T09:53:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ecd8670a5076c43f1409532b61f7c1770332303d",
          "body": "…ollow-up) (#662)\n\nA `winpodx pod stop` / tray Quit calls stop_listener(); while the pod kept\nrunning nothing re-spawned the reverse-open watcher, so 'Open with -> a Linux\napp' from Windows silently did nothing until the next `pod start` (hit during\nthe v0.7.4 smoke).\n\n- host_open: new reusable `ens\n[…]\nvery `winpodx app run` / GUI\n  launch revives a dead listener when reverse_open is enabled. Never blocks the\n  launch.\n\nTests: ensure_listener_running disabled/running(no double-spawn)/started/failed.",
          "is_bot": false,
          "headline": "fix(reverse-open): self-heal the listener on app launch (#544 smoke f…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-06-23T07:17:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f33abeda7a4c77d1d01234af24db6006f7782740",
          "body": "…view follow-ups\n\nVersion stamps -> 0.7.4 (pyproject + rpm spec + debian/changelog; verify_versions\nconsistent). CHANGELOG.md + docs/CHANGELOG.ko.md gain [0.7.4] (3 Added + 9 Fixed)\n+ ### Contributors; README en+ko summary + version line.\n\n5-team pre-release review (security / audit / release / lega\n[…]\nes (new feature strings fall back to English for non-en).\n- gitignore: ignore stray root build-backend wheels (/*.whl).\n\nNOT tagged — awaiting maintainer smoke test before pushing v0.7.4 / REL-v0.7.4.",
          "is_bot": false,
          "headline": "release: prep v0.7.4 — version bump, CHANGELOG, homepage, security re…",
          "author_name": "kernalix7",
          "author_login": "kernalix7",
          "committed_at": "2026-06-23T02:58:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "86ddd5b23557c2cfa3a6f5d78e219fc79cf157aa",
          "body": "* fix(gui): honor selected backend in Logs-tab diagnostics buttons\n\nThe Terminal-tab quick buttons (Status / Pod logs / Inspect) hardcoded\n\"podman\", so on a Docker-backend install they shelled out podman ps /\nlogs / inspect regardless of cfg.pod.backend — failing or probing the\nwrong runtime. Route \n[…]\nnit-testable without\nQt. Also fix the pod-log tail's on-screen $ echo to print the real\nbackend instead of a hardcoded podman.\n\n* docs(changelog): note Logs-tab diagnostics honoring the Docker backend",
          "is_bot": false,
          "headline": "fix(gui): honor selected backend in Logs-tab diagnostics buttons (#658)",
          "author_name": "cxgreat2014",
          "author_login": "cxgreat2014",
          "committed_at": "2026-06-23T02:35:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "101a41085787467e98c722bcce7e4d1bc713e008",
          "body": "…ilures (#657)\n\n* fix(rotation): check \\$LASTEXITCODE after net user to surface failures\n\nnet user writes errors to stderr but exits non-zero; the old payload\npiped stdout to Out-Null and then unconditionally ran Write-Output,\nso the agent always reported rc=0 even when the user did not exist or\nthe\n[…]\ne second-file-in-running-app\nfix and FreeRDP fallback, the absolute Exec= path for stripped-PATH\nlaunchers, the empty-password guard (#569), the net user exit-code fix\n(#569), and the /kbd extra flag.",
          "is_bot": false,
          "headline": "fix(rdp/rotation): open file in existing session; surface net user fa…",
          "author_name": "cxgreat2014",
          "author_login": "cxgreat2014",
          "committed_at": "2026-06-23T02:20:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0fbc79e9b3cbfe9ad33dca04431240dfdd90e8b2",
          "body": "…rovider (#644) (#656)\n\nOn Debian 13 the .deb installed winpodx + podman but not podman-compose, so\n`winpodx setup` couldn't run compose-up, created no container, and died\ndownstream with `no such container \"winpodx-windows\"`. podman-compose was\nnever in debian/control (the curl install.sh path alre\n[…]\ntro\n  install hint (apt/dnf/zypper/pipx) referencing #644, instead of the silent\n  'Compose command not found, skipping container recreation.'\n\nReported by @paolodongilli (Debian 13 trixie, Xfce/X11).",
          "is_bot": false,
          "headline": "fix(deb): Recommends podman-compose + loud error on missing compose p…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-06-21T06:59:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8112cd25a0023f14ab6aea579611129380463dbf",
          "body": "…storage location (#646) (#654)\n\nLet a fresh install put the Windows VM disk + ISO on a chosen partition\ninstead of ~/.local/share/winpodx/storage — useful when the home partition is\nsmall. winpodx already had cfg.pod.storage_path + --migrate-storage-target for\nrelocating an existing install; this e\n[…]\nin install.sh header + usage() + setup --help.\n\nTests: explicit_target sets storage_path on a fresh install + is ignored (with\na notice) when storage is already configured. bash -n / shellcheck clean.",
          "is_bot": false,
          "headline": "feat(install): --storage-dir / setup --storage-path to choose the VM …",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-06-21T04:21:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "33de471e67f9b336188f31470db14640a8fdc019",
          "body": "Windows 11 runs noticeably better with 8 GB, and a host with >=24 GB can spare\nit. The auto-tier that pre-fills pod.ram_gb during `winpodx setup` mapped the\nwhole 16-32 GB mid band to a 6 GB VM; now a >=24 GB host gets 8 GB (CPU tier\nunchanged, >=32 GB / >=12-thread hosts still get the 12 GB high ti\n[…]\nisting installs are untouched (this only changes the default a fresh setup\n  pre-fills); users keep any value they configured.\n\nTests: 24/28/31 GB -> 8 GB, 23 GB -> 6 GB, the high/low tiers unchanged.",
          "is_bot": false,
          "headline": "feat(setup): default the VM to 8 GB RAM on 24 GB+ hosts (#630) (#653)",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-06-21T04:09:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f432f08b174643386bf29260201683ec5f891547",
          "body": "…#550) (#652)\n\nThe BusyDialog progress window (Debloat, Grow Disk, Sync Guest, ...) had only\na 380px min width and sized its height to content, so it opened ~392x139 —\ncramped, most visibly on the Debloat 'Speed' run (reported by @ismikes). Give\nit a 480x168 floor.\n\nThe picker-window size and the fast-op auto-close (deferred worker start so a\nsub-exec() finish() isn't a no-op) were already fixed in 0.7.2; this is the\nremaining task-window-size half of #550.",
          "is_bot": false,
          "headline": "fix(gui): give the maintenance task dialog a comfortable size floor (…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-06-21T03:31:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "09054a1de8469ddcdc107ea76491fcf54e46904d",
          "body": "…#647) (#651)\n\nRepeated purge/reinstall cycles re-downloaded the ~5-8 GB Windows ISO from\nMicrosoft each time. dockur already installs from a `custom.iso` in /storage\n(bring-your-own), but that was an undocumented manual file drop. Wire it to a\nflag.\n\n- install.sh: --win-iso PATH (+ env WINPODX_WIN_\n[…]\nlp.\n\nNo Python change — uses the existing cfg.pod.storage_path + dockur's custom.iso\nconvention. Verified the staging logic standalone (copy, size report, same-file\nskip) + bash -n / shellcheck clean.",
          "is_bot": false,
          "headline": "feat(install): --win-iso <path> to install from a local Windows ISO (…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-06-21T03:07:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a64d5eb64ea3c12d9be2ea6c85535ffd3769bd96",
          "body": "…ase sign-off) (#650)\n\nCI (pytest on a Linux runner) can't exercise the Windows guest, and most\nwinpodx regressions are guest-side (OEM scripts, FreeRDP/RAIL, install flow) —\nseveral releases shipped breakage that passed CI but was never smoke-tested on\nreal Windows (media_monitor #613/#638, the 444\n[…]\nmoke\nlist, a platform/channel matrix, a per-feature checklist, and the release\nsign-off (version stamps, CHANGELOG + Contributors, v + REL- tags, publish\nchannels). Linked from CONTRIBUTING (en + ko).",
          "is_bot": false,
          "headline": "docs: add release-testing checklist (guest-side smoke gate + per-rele…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-06-20T14:56:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c1bd1d804d7e714732beb86cb1f2a2ebd2018e65",
          "body": "…ch, timeout fixes, media_monitor removal\n\n- Added: reverse-open opens Windows-VM files via SMB+kio-fuse (#616), opt-in idle\n  auto-stop to free VM RAM (#622), +multitouch/stylus passthrough flag (#623).\n- Fixed: discovery timeout unified+raised so app refresh doesn't time out (#619),\n  Dashboard RA\n[…]\n#613/#638), debloat telemetry (#590), usbredir\n  hint (#593), urlacl quoting (#614), agent token self-heal (#615).\n- Version stamps: pyproject + rpm spec + debian = 0.7.3 (verify_versions consistent).",
          "is_bot": false,
          "headline": "release: v0.7.3 — reverse-open guest files, idle auto-stop, +multitou…",
          "author_name": "kernalix7",
          "author_login": "kernalix7",
          "committed_at": "2026-06-20T13:28:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0ba6e779ca3b8ef9d2eb04f0f7b0bbbb6d47b9ec",
          "body": null,
          "is_bot": false,
          "headline": "feat: whitelisted multitouch flag for RDP (#635)",
          "author_name": "Scratch2xs",
          "author_login": "Scratch2xs",
          "committed_at": "2026-06-20T13:19:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "41a9749c442e6a1b528187da6f52c28a9bc49b38",
          "body": "Idle auto-suspend only *paused* the VM (frees CPU, RAM stays). Add an opt-in\n'stop' action so an idle VM can be shut down to free its RAM, per the request.\n\n- config: pod.idle_action = 'pause' (default) | 'stop'; validated; serialized.\n- daemon: new _apply_idle_action — on idle_timeout, 'stop' stops\n[…]\nmulti-language part of #622 already shipped: Settings -> UI\nLanguage picks from 8 languages.)\n\nTests: _apply_idle_action pauses by default, stops a running pod on 'stop',\nskips an already-stopped pod.",
          "is_bot": false,
          "headline": "feat(pod): optional idle auto-stop to free the VM's RAM (#622) (#649)",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-06-20T11:22:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "66fa07d62f725c3acd9f098c8bca799fce59f348",
          "body": "…show n/a (#634) (#648)\n\nThe Dashboard RAM + Disk C: gauges read from the guest over the agent (CPU is\nhost-side, which is why it kept working), but the quiet poll passed a tight 4s\ntimeout. On a slow or freshly-relaunched guest the RAM+disk /exec didn't\nfinish in time, so both gauges blanked to 'n/\n[…]\nd, so the longer budget never freezes or stacks the\ndashboard. Same too-tight-timeout class as the discovery #619 fix.\n\nTest: _guest_resources passes a generous (>=12s) timeout to get_guest_resources.",
          "is_bot": false,
          "headline": "fix(gui): bump Dashboard guest RAM+disk poll timeout so gauges don't …",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-06-20T03:16:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "02ae8ba03b89dfeedabb0b7883d858aafc476287",
          "body": "…n't time out (#619) (#645)\n\n`winpodx app refresh` capped discovery at 30s (CLI --timeout default), while\nthe discovery library defaulted to 180s and a third caller (scan) to 120s.\nGuest Start-Menu + AppX enumeration on a cold / low-spec guest runs over a\nminute, so `app refresh` failed with '/exec \n[…]\nUT = 300s) used by every caller; the timeout now only\nbounds a genuinely wedged guest. Raisable via `app refresh --timeout`.\n\nTests: refresh with no --timeout forwards 300 (regression guard for #619).",
          "is_bot": false,
          "headline": "fix(discovery): generous single discovery timeout so app refresh does…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-06-19T12:30:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d5540a9ca391c3b0975a4d46a35f466f641f7893",
          "body": "…e (#616) (#643)\n\n* fix(reverse-open): stop mis-mapping guest-local paths to the host home (#616, phase 1)\n\nThe Windows shim's local_to_unc rewrote EVERY drive-letter path\n(C:\\Users\\me\\Desktop\\x) to \\tsclient\\home\\... — which only makes sense\nif $HOME were the root of that drive. For a guest-local f\n[…]\nlently. Skips when\nreverse-open is disabled; host-redirect reverse-open is unaffected either way.\n\n* docs(changelog): reverse-open guest-disk + install/update fixes (#616)\n\n* style: ruff format (#616)",
          "is_bot": false,
          "headline": "feat(reverse-open): open files on the Windows VM, not just shared Hom…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-06-19T06:58:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "03e50d69721c8a09d44c4d2878f3c39e46a2676e",
          "body": "…13, #638) (#641)\n\nThe media_monitor.ps1 mapper that tried to surface each \\tsclient\\media\\<LABEL>\nUSB volume as a drive letter is removed entirely. It never worked well enough to\nkeep: it couldn't surface a drive letter reliably in RemoteApp (RAIL) app\nsessions (HKCU\\Run doesn't fire there), and sh\n[…]\nixes.\n- README / migrate note / CHANGELOG (en+ko) updated.\n- Tests: test_oem_install_bat asserts WinpodxMedia/media_monitor are absent;\n  OEM version marker 26->27 in test_oem_install_bat + test_info.",
          "is_bot": false,
          "headline": "chore(oem): remove the media_monitor USB drive-letter auto-mapper (#6…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-06-18T23:33:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "11e87e9a769a2c451369f2e6d188b86aac0d8cd5",
          "body": "… USB hotplug (#613) (#636)\" (#639)\n\nThis reverts commit 1cdb97713a121ad394def5c809e1428cb79df3f8.",
          "is_bot": false,
          "headline": "Revert \"fix(oem): deliver media_monitor.ps1 via OEM bundle + poll for…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-06-18T07:13:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1cdb97713a121ad394def5c809e1428cb79df3f8",
          "body": "…plug (#613) (#636)\n\nTwo fixes so USB drives actually auto-map to guest drive letters:\n\n1. Delivery: media_monitor.ps1 was the only first-boot guest script not in the\n   OEM bundle, so dockur never staged it and the USB auto-mapper never ran.\n   Move it into config/oem/ (staged to C:\\OEM\\, copied to\n[…]\nin after the\n   session started (confirmed via guest logs on #613). Polling \\\\tsclient\\media\n   every 5s maps a new volume within seconds and unmaps a removed one.\n\nREADME + CHANGELOG (EN/KO) updated.",
          "is_bot": false,
          "headline": "fix(oem): deliver media_monitor.ps1 via OEM bundle + poll for USB hot…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-06-18T02:41:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "07d4ad5219cd3ec427aa7b20a74b80d31cfee332",
          "body": "… restore #614 quoting (#633)\n\nismikes (#613 comment) + maintainer: fresh installs from main fail every time —\nthe guest agent's /health never answers and provisioning loops in agent_settle.\nThe cause is the #618 media_monitor change, not the urlacl line. Revert #618\nin full (install.bat media block\n[…]\n is undone. CHANGELOG: drop the\nreverted #613 entry, restore the #614 quoting wording (EN + KO).\n\n#613 (media_monitor not staged at first boot) will be re-done properly with a\nreal-Windows smoke test.",
          "is_bot": false,
          "headline": "hotfix(oem): revert #618 (media_monitor OEM move) that broke install;…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-06-17T07:41:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0cdeae73c37d41f7617f999a0cad38e2fb6b5c5c",
          "body": "…oke the agent) (#632)\n\n* hotfix(oem): revert #614 SDDL quoting — it broke the agent urlacl reservation\n\n#614 added quotes around the urlacl SDDL (sddl=\"D:(A;;GX;;;WD)\"), but netsh\ntakes the literal quotes as part of the descriptor and rejects it, so the\nreservation is never created and the guest ag\n[…]\nn descriptor to netsh, and the line is now safe\neven if it ever sits inside a parenthesized block (zephir2008's reported parse\nerror). Restore the #614 CHANGELOG entry describing the caret-escape fix.",
          "is_bot": false,
          "headline": "hotfix(oem): caret-escape the urlacl SDDL (fixes #614 quoting that br…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-06-17T06:55:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "407afcabe49f2382133229044993fe709b66df34",
          "body": "…g 401 (#615) (#631)\n\nThe guest agent reads its bearer token once at boot from a baked copy of\nC:\\OEM\\agent_token.txt. If that diverges from the host token, every\nauthenticated endpoint (guest_exec / guest_summary / any /exec) returns HTTP\n401 and the agent can't fix itself — the channel that would \n[…]\nt_exec probe hits a 401, then re-checks.\n\nAlso restores the missing '## [0.7.2]' header in the Korean CHANGELOG (the\nrelease content was sitting under [Unreleased]). Tests: tests/test_agent_resync.py.",
          "is_bot": false,
          "headline": "feat(agent): self-heal a drifted guest bearer token instead of stayin…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-06-17T06:04:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "de04cb9e9f68614d44c68d0afa0894e773f49e22",
          "body": "…#614) (#629)\n\nnetsh http add urlacl ... sddl=D:(A;;GX;;;WD) left the SDDL value unquoted, so\ncmd.exe parsed its parentheses and semicolons as metacharacters and the command\nfailed with \")\" was unexpected at this time. The agent URL reservation never\ngot created, which can leave the guest agent unable to bind port 8765. Quote\nthe SDDL value; netsh strips the quotes and receives the same descriptor.",
          "is_bot": false,
          "headline": "fix(oem): quote the urlacl SDDL so install.bat doesn't syntax-error (…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-06-17T01:01:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a73f1b0570f8f2ee56dffe6b31d38fcd20de6cda",
          "body": "…(thanks @techabsol) (#628)",
          "is_bot": false,
          "headline": "docs(changelog): log #593 usbredir install-hint fix under Unreleased …",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-06-17T00:36:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f0f71f563995db96bf951dd3131c4c9103e13be6",
          "body": "The usbredir-not-found message pointed at packages that don't carry the usbredirect binary. Fix the hints: Debian/Ubuntu `usbredirect`, Fedora `usbredir-tools` (+ Atomic Fedora rpm-ostree), openSUSE `usbredir` unchanged.",
          "is_bot": false,
          "headline": "fix(usbredir): correct the missing-binary install hint per distro (#593)",
          "author_name": "TechAbsol",
          "author_login": "techabsol",
          "committed_at": "2026-06-17T00:25:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b5178009efefb32a14c5d53c4f8b88e6eed3bc58",
          "body": "Adds extra ContentDeliveryManager ad keys + RotatingLockScreen, and pure-telemetry scheduled tasks (AitAgent, ProgramInventoryUpdater, CEIP BthSQM, Feedback Siuf, WindowsAI Copilot/Insights data collection, Office telemetry). Security/system-critical tasks (Defender, licensing, certificate services, Windows Update repair, language packs, Windows Hello) are deliberately excluded so debloat can't break activation, updates, or the IME.",
          "is_bot": false,
          "headline": "feat(debloat): add telemetry-safe ad keys and scheduled tasks (#590)",
          "author_name": "GameSoul7Eugene",
          "author_login": "GameSoul7Eugene",
          "committed_at": "2026-06-17T00:01:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "daad933ee7cdcde32e4ed16ef90ad5aa921d9182",
          "body": "…ttribution (#627)\n\n* Revert \"feat(debloat): adopt safe telemetry/ad subset from #590 (#625)\"\n\nThis reverts commit 5d6c0d4a6db301d16d8315f750e24ee243877e94.\n\n* docs(changelog): point debloat credit at #590 (merging the contributor PR directly)",
          "is_bot": false,
          "headline": "revert(debloat): undo #625 so the contributor PR #590 can land with a…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-06-17T00:00:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b76d54bf56b7ffe23f9c5928d622c13c62a55c7c",
          "body": "…safe debloat subset) under Unreleased (#626)",
          "is_bot": false,
          "headline": "docs(changelog): log #613 (media_monitor in OEM bundle) + #590/#625 (…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-06-16T23:38:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5d6c0d4a6db301d16d8315f750e24ee243877e94",
          "body": "PR #590 (thanks @GameSoul7Eugene) proposed expanding the debloat lists. The\nscheduled-tasks part was a ~170-task blanket list that also disabled Windows\nDefender scans, licensing/activation, certificate services, Windows Update\nrepair (WaaSMedic/UpdateOrchestrator), language packs, and Windows Hello\n[…]\n, Office telemetry agents.\n\nMirror every addition in the undo scripts; keep 4-space indentation; drop the\ndead commented-out blocks from #590. No Defender/licensing/cert/update/language\ntasks touched.",
          "is_bot": false,
          "headline": "feat(debloat): adopt safe telemetry/ad subset from #590 (#625)",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-06-16T23:09:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c1c960877a7c9afc32e6231a0b3c8421b1cdb8e6",
          "body": "…finds it (#613) (#618)\n\nmedia_monitor.ps1 was the only first-boot guest script not in config/oem/,\nso dockur never staged it to C:\\OEM\\. install.bat's two source paths both\nfail during the unattended install: C:\\winpodx-scripts is a never-wired\ncompose mount, and \\\\tsclient\\home (RDP drive redirect\n[…]\nruda-specific).\n\nMove the script into the OEM bundle (config/oem/, already packaged + staged\nto C:\\OEM\\) and copy it from %~dp0 first; keep the old paths as harmless\nfallbacks. Update README to match.",
          "is_bot": false,
          "headline": "fix(oem): ship media_monitor.ps1 in OEM bundle so first-boot install …",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-06-16T02:35:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dc6d45c74a2b4a3ee4918d9cec5edf849e8ff35a",
          "body": "Add `pod.ssd` (Proxmox-style 'SSD emulation'): present the guest disk as\nnon-rotational so Windows enables TRIM + skips scheduled defrag and treats it\nlike an SSD. Implemented as QEMU `-global ide-hd.rotation_rate=1` +\n`scsi-hd.rotation_rate=1` injected into ARGUMENTS — set on whichever ATA/SCSI\ndis\n[…]\nmed SSD (HDD/undetectable keeps the HDD default).\nOverride with `winpodx config set pod.ssd true|false`. Takes effect on next\npod create. + tests (compose injection, config roundtrip, host detection).",
          "is_bot": false,
          "headline": "feat(pod): SSD emulation for the Windows disk (#606) (#612)",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-06-15T08:27:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7c2dd0452a54eefe9b8e82f024e8a27eb45ed08c",
          "body": "…611)\n\n#594: 'reverse-open refresh picks up only a subset of apps' (Brave missing).\ndiscover_apps silently dropped every .desktop that lacked MimeType=, was\nNoDisplay/OnlyShowIn-filtered, had an unsafe Exec, a failed TryExec, or was\nshadowed — with no way to see WHY a given app was excluded.\n\nAdd a \n[…]\ndropped .desktop with a human reason. Makes a\n'missing app' report self-diagnosable (Brave's standard .desktop IS discovered\nin testing, so the miss is environment-specific — this shows which filter).",
          "is_bot": false,
          "headline": "feat(host-open): --verbose lists why a .desktop was dropped (#594) (#…",
          "author_name": "Kim DaeHyun",
          "author_login": "kernalix7",
          "committed_at": "2026-06-15T07:41:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        }
      ],
      "releases_count": 38,
      "commits_last_year": 788,
      "latest_release_at": "2026-07-21T03:13:20Z",
      "latest_release_tag": "v0.10.3",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 15,
      "days_since_latest_release": 1,
      "mean_days_between_releases": 4
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 100,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": []
    },
    "popularity": {
      "forks": 70,
      "stars": 1620,
      "watchers": 10,
      "fork_history": {
        "days": [
          {
            "date": "2026-04-23",
            "count": 1
          },
          {
            "date": "2026-05-01",
            "count": 4
          },
          {
            "date": "2026-05-03",
            "count": 1
          },
          {
            "date": "2026-05-05",
            "count": 1
          },
          {
            "date": "2026-05-11",
            "count": 2
          },
          {
            "date": "2026-05-13",
            "count": 3
          },
          {
            "date": "2026-05-14",
            "count": 7
          },
          {
            "date": "2026-05-15",
            "count": 3
          },
          {
            "date": "2026-05-17",
            "count": 1
          },
          {
            "date": "2026-05-19",
            "count": 2
          },
          {
            "date": "2026-05-20",
            "count": 3
          },
          {
            "date": "2026-05-21",
            "count": 2
          },
          {
            "date": "2026-05-24",
            "count": 1
          },
          {
            "date": "2026-05-25",
            "count": 1
          },
          {
            "date": "2026-06-01",
            "count": 1
          },
          {
            "date": "2026-06-03",
            "count": 1
          },
          {
            "date": "2026-06-04",
            "count": 1
          },
          {
            "date": "2026-06-07",
            "count": 1
          },
          {
            "date": "2026-06-08",
            "count": 1
          },
          {
            "date": "2026-06-11",
            "count": 2
          },
          {
            "date": "2026-06-13",
            "count": 2
          },
          {
            "date": "2026-06-15",
            "count": 2
          },
          {
            "date": "2026-06-16",
            "count": 1
          },
          {
            "date": "2026-06-17",
            "count": 1
          },
          {
            "date": "2026-06-18",
            "count": 2
          },
          {
            "date": "2026-06-19",
            "count": 1
          },
          {
            "date": "2026-06-20",
            "count": 1
          },
          {
            "date": "2026-06-21",
            "count": 2
          },
          {
            "date": "2026-06-22",
            "count": 5
          },
          {
            "date": "2026-06-23",
            "count": 4
          },
          {
            "date": "2026-06-24",
            "count": 1
          },
          {
            "date": "2026-06-29",
            "count": 2
          },
          {
            "date": "2026-06-30",
            "count": 2
          },
          {
            "date": "2026-07-03",
            "count": 1
          },
          {
            "date": "2026-07-06",
            "count": 1
          },
          {
            "date": "2026-07-13",
            "count": 3
          }
        ],
        "complete": true,
        "collected": 70,
        "total_forks": 70
      },
      "star_history": {
        "days": [
          {
            "date": "2026-05-17",
            "count": 9
          },
          {
            "date": "2026-05-18",
            "count": 12
          },
          {
            "date": "2026-05-19",
            "count": 35
          },
          {
            "date": "2026-05-20",
            "count": 33
          },
          {
            "date": "2026-05-21",
            "count": 21
          },
          {
            "date": "2026-05-22",
            "count": 16
          },
          {
            "date": "2026-05-23",
            "count": 8
          },
          {
            "date": "2026-05-24",
            "count": 6
          },
          {
            "date": "2026-05-25",
            "count": 7
          },
          {
            "date": "2026-05-26",
            "count": 3
          },
          {
            "date": "2026-05-27",
            "count": 4
          },
          {
            "date": "2026-05-28",
            "count": 3
          },
          {
            "date": "2026-05-29",
            "count": 1
          },
          {
            "date": "2026-05-30",
            "count": 2
          },
          {
            "date": "2026-05-31",
            "count": 1
          },
          {
            "date": "2026-06-01",
            "count": 34
          },
          {
            "date": "2026-06-02",
            "count": 24
          },
          {
            "date": "2026-06-03",
            "count": 19
          },
          {
            "date": "2026-06-04",
            "count": 12
          },
          {
            "date": "2026-06-05",
            "count": 16
          },
          {
            "date": "2026-06-06",
            "count": 11
          },
          {
            "date": "2026-06-07",
            "count": 11
          },
          {
            "date": "2026-06-08",
            "count": 11
          },
          {
            "date": "2026-06-09",
            "count": 6
          },
          {
            "date": "2026-06-10",
            "count": 5
          },
          {
            "date": "2026-06-11",
            "count": 5
          },
          {
            "date": "2026-06-12",
            "count": 1
          },
          {
            "date": "2026-06-13",
            "count": 4
          },
          {
            "date": "2026-06-14",
            "count": 14
          },
          {
            "date": "2026-06-15",
            "count": 34
          },
          {
            "date": "2026-06-16",
            "count": 10
          },
          {
            "date": "2026-06-17",
            "count": 10
          },
          {
            "date": "2026-06-18",
            "count": 49
          },
          {
            "date": "2026-06-19",
            "count": 23
          },
          {
            "date": "2026-06-20",
            "count": 23
          },
          {
            "date": "2026-06-21",
            "count": 63
          },
          {
            "date": "2026-06-22",
            "count": 89
          },
          {
            "date": "2026-06-23",
            "count": 22
          },
          {
            "date": "2026-06-24",
            "count": 12
          },
          {
            "date": "2026-06-25",
            "count": 8
          },
          {
            "date": "2026-06-26",
            "count": 12
          },
          {
            "date": "2026-06-27",
            "count": 4
          },
          {
            "date": "2026-06-28",
            "count": 13
          },
          {
            "date": "2026-06-29",
            "count": 67
          },
          {
            "date": "2026-06-30",
            "count": 32
          },
          {
            "date": "2026-07-01",
            "count": 19
          },
          {
            "date": "2026-07-02",
            "count": 12
          },
          {
            "date": "2026-07-03",
            "count": 14
          },
          {
            "date": "2026-07-04",
            "count": 19
          },
          {
            "date": "2026-07-05",
            "count": 10
          },
          {
            "date": "2026-07-06",
            "count": 9
          },
          {
            "date": "2026-07-07",
            "count": 6
          },
          {
            "date": "2026-07-08",
            "count": 7
          },
          {
            "date": "2026-07-09",
            "count": 5
          },
          {
            "date": "2026-07-10",
            "count": 8
          },
          {
            "date": "2026-07-11",
            "count": 6
          },
          {
            "date": "2026-07-12",
            "count": 4
          },
          {
            "date": "2026-07-13",
            "count": 31
          },
          {
            "date": "2026-07-14",
            "count": 8
          },
          {
            "date": "2026-07-15",
            "count": 9
          },
          {
            "date": "2026-07-16",
            "count": 4
          },
          {
            "date": "2026-07-17",
            "count": 3
          },
          {
            "date": "2026-07-19",
            "count": 10
          },
          {
            "date": "2026-07-20",
            "count": 4
          },
          {
            "date": "2026-07-21",
            "count": 6
          },
          {
            "date": "2026-07-22",
            "count": 1
          }
        ],
        "complete": false,
        "collected": 1000,
        "total_stars": 1620
      },
      "open_issues_and_prs": 41
    },
    "ai_readiness": {
      "has_nix": true,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "config/oem/reverse-open/shim/Cargo.toml"
      ],
      "largest_source_bytes": 164528,
      "source_files_sampled": 259,
      "oversized_source_files": 6,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "pyproject.toml"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "pypi"
      ],
      "dependencies": [
        {
          "name": "tomli",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=1.1.0"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 585,
        "open_issues": 41,
        "closed_ratio": 0.77,
        "closed_issues": 137,
        "closed_unmerged_prs": 10
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "kernalix7",
          "commits": 765,
          "avatar_url": "https://avatars.githubusercontent.com/u/245287466?v=4"
        },
        {
          "type": "User",
          "login": "Mic92",
          "commits": 8,
          "avatar_url": "https://avatars.githubusercontent.com/u/96200?v=4"
        },
        {
          "type": "User",
          "login": "GameSoul7Eugene",
          "commits": 4,
          "avatar_url": "https://avatars.githubusercontent.com/u/59319082?v=4"
        },
        {
          "type": "User",
          "login": "juampe",
          "commits": 3,
          "avatar_url": "https://avatars.githubusercontent.com/u/365683?v=4"
        },
        {
          "type": "User",
          "login": "Zeik0s",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/35345686?v=4"
        },
        {
          "type": "User",
          "login": "cxgreat2014",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/15062548?v=4"
        },
        {
          "type": "User",
          "login": "MirzaAyBaig12",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/176703133?v=4"
        },
        {
          "type": "User",
          "login": "pgarciaq",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/88486249?v=4"
        },
        {
          "type": "User",
          "login": "Scratch2xs",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/104689304?v=4"
        },
        {
          "type": "User",
          "login": "techabsol",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/212185447?v=4"
        }
      ],
      "contributors_sampled": 11,
      "top_contributor_share": 0.97
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "appimage-publish.yml",
        "aur-publish.yml",
        "check-windows-updates.yml",
        "ci.yml",
        "debs-publish.yml",
        "obs-publish.yml",
        "pages.yml",
        "release.yml",
        "rhel-publish.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 8,
            "reason": "binaries present in source code",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 1/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 5 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 25 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "80d92689baeeed48addef86ae35aa4ff6d1a922b",
        "ran_at": "2026-07-22T03:16:34Z",
        "aggregate_score": 4.3,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-22T03:03:45Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-22T02:54:27Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 140,
          "created_at": "2026-05-07T11:21:03Z",
          "last_comment_at": "2026-05-20T23:33:32Z",
          "last_comment_author": "kernalix7"
        },
        {
          "number": 141,
          "created_at": "2026-05-08T00:07:52Z",
          "last_comment_at": "2026-05-13T03:28:22Z",
          "last_comment_author": "kernalix7"
        },
        {
          "number": 142,
          "created_at": "2026-05-08T00:08:43Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 188,
          "created_at": "2026-05-14T02:35:32Z",
          "last_comment_at": "2026-05-20T23:29:43Z",
          "last_comment_author": "kernalix7"
        },
        {
          "number": 285,
          "created_at": "2026-05-22T08:04:54Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 286,
          "created_at": "2026-05-22T13:54:46Z",
          "last_comment_at": "2026-06-01T14:24:13Z",
          "last_comment_author": "kernalix7"
        },
        {
          "number": 299,
          "created_at": "2026-05-23T13:08:38Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 381,
          "created_at": "2026-05-28T21:49:29Z",
          "last_comment_at": "2026-05-29T01:41:14Z",
          "last_comment_author": "kernalix7"
        },
        {
          "number": 393,
          "created_at": "2026-05-29T06:56:06Z",
          "last_comment_at": "2026-06-14T17:12:58Z",
          "last_comment_author": "ismikes"
        },
        {
          "number": 431,
          "created_at": "2026-06-02T01:38:25Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 469,
          "created_at": "2026-06-04T00:27:32Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 503,
          "created_at": "2026-06-06T01:29:12Z",
          "last_comment_at": "2026-07-16T07:44:37Z",
          "last_comment_author": "kernalix7"
        },
        {
          "number": 526,
          "created_at": "2026-06-07T21:15:04Z",
          "last_comment_at": "2026-06-30T02:04:30Z",
          "last_comment_author": "kernalix7"
        },
        {
          "number": 544,
          "created_at": "2026-06-08T21:17:56Z",
          "last_comment_at": "2026-07-10T06:11:51Z",
          "last_comment_author": "kernalix7"
        },
        {
          "number": 570,
          "created_at": "2026-06-11T19:34:09Z",
          "last_comment_at": "2026-07-18T20:36:05Z",
          "last_comment_author": "notnotno"
        },
        {
          "number": 574,
          "created_at": "2026-06-12T05:31:16Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 655,
          "created_at": "2026-06-21T04:45:40Z",
          "last_comment_at": "2026-06-21T06:50:28Z",
          "last_comment_author": "ismikes"
        },
        {
          "number": 661,
          "created_at": "2026-06-23T05:52:40Z",
          "last_comment_at": "2026-06-30T02:03:11Z",
          "last_comment_author": "kernalix7"
        },
        {
          "number": 664,
          "created_at": "2026-06-24T17:01:19Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 665,
          "created_at": "2026-06-24T19:40:09Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/kernalix7/winpodx",
    "host": "github.com",
    "name": "winpodx",
    "owner": "kernalix7"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 66,
      "inputs": {
        "security": 44,
        "vitality": 80,
        "community": 82,
        "governance": 48,
        "engineering": 77
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 80,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 74,
            "inputs": {
              "commits_last_year": 788,
              "human_commit_share": 1,
              "days_since_last_push": 0,
              "active_weeks_last_year": 15
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "15/52 weeks with commits",
                "points": 10.4,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 15
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "788 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 788
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 25 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 38,
              "latest_release_tag": "v0.10.3",
              "releases_from_tags": false,
              "days_since_latest_release": 1,
              "mean_days_between_releases": 4
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "38 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 38
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 1 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~4 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 4
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "good",
        "name": "Community & Adoption",
        "value": 82,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "good",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 73,
            "inputs": {
              "forks": 70,
              "stars": 1620,
              "watchers": 10,
              "growth_state": "organic",
              "growth_factor_pct": 100
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "1,620 stars",
                "points": 52.1,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 1620
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "70 forks",
                "points": 15.3,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 70
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "10 watchers",
                "points": 5.3,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 10
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 48,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "at_risk",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 33,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 11,
              "top_contributor_share": 0.97
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 97% of commits",
                "points": 0.7,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 97
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "11 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 11
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 5 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 74,
            "inputs": {
              "merged_prs": 585,
              "open_issues": 41,
              "closed_issues": 137,
              "issue_closed_ratio": 0.77,
              "closed_unmerged_prs": 10
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "77% of issues closed",
                "points": 36,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 77
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "585/595 decided PRs merged",
                "points": 37.6,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 585,
                      "decided": 595
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 1/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 40,
            "inputs": {
              "followers": 39,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "kernalix7",
              "public_repos": 17,
              "account_age_days": 243
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "39 followers of kernalix7",
                "points": 11.5,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 39,
                      "login": "kernalix7"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "17 public repos, account ~0 yr old",
                "points": 10.5,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 17
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 77,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "9 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 9
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": "https://www.winpodx.org/",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://www.winpodx.org/",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 44,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Packaging. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "packaging"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 44,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 4.3
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "binaries present in source code",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 1/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 5 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 25 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 9
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "at_risk",
        "name": "AI Readiness",
        "value": 45,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "100 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 100,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "at_risk",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 45,
            "inputs": {
              "has_nix": true,
              "has_tests": true,
              "lockfiles": [],
              "has_dockerfile": true,
              "typed_language": false,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "config/oem/reverse-open/shim/Cargo.toml"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "config/oem/reverse-open/shim/Cargo.toml (toolchain convention, no task runner)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "toolchain_convention",
                    "params": {
                      "files": "config/oem/reverse-open/shim/Cargo.toml"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, Nix",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, Nix"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "moderate",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 54,
            "inputs": {
              "primary_language": "Python",
              "largest_source_bytes": 164528,
              "source_files_sampled": 259,
              "oversized_source_files": 6
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Python without a type-check config",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_typecheck_config_language",
                    "params": {
                      "language": "Python"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "6/259 source files over 60KB",
                "points": 53.7,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 259,
                      "oversized": 6
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Could not fetch pypi package 'winpodx' from its registry",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-22T03:16:56.307212Z",
  "schema_version": "0.26.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/k/kernalix7/winpodx.svg",
  "full_name": "kernalix7/winpodx",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.26.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statistics.