Public record
Software health reportschema 0.27.0 · metrics 1.13.0 · 2026-07-23 11:43 UTC

lance0 / xfr

A modern iperf3 alternative with a live TUI, multi-client server, and QUIC support. Built in Rust.

RustApache-2.0★ 517 stars⑂ 21 forkssince Jan 2026View on GitHub ↗

lance0/xfr holds a health index of 68 out of 100, placing it in the Moderate band. It scores highest on Engineering Quality (90/100) and lowest on Security (52/100). It was last updated 4 days ago. A single contributor accounts for most of its recent work.

68
overall / 100
Moderate

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

68
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

lancePersonal account
115 followers61 public repossince Jan 2013

This repository is owned by a personal account. A single-owner project carries more continuity risk than an organization-backed one.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publishTags
crates.ioxfr0.9.211793416 days agonetworktuibenchmarkbandwidthiperfcommand-line-utilitiesnetwork-programming

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

82Good · 22% of overall
How it's scored
36/36Push recency — last push 4 days ago
12.5/36Commit cadence — 18/52 weeks with commits
18/18Commit volume — 459 commits in the last year
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year459
human_commit_share0.92
days_since_last_push4
active_weeks_last_year18
How it's scored
27/27Ships releases — 29 releases published
36/36Release recency — latest release 16 days ago
27/27Release cadence — a release every ~7.5 days
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Inputs used
releases_count29
latest_release_tagv0.9.21
releases_from_tagsno
days_since_latest_release16
mean_days_between_releases7.5

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

56Moderate · 18% of overall
How it's scored
44/60Stars — 517 stars
10.8/25Forks — 21 forks
0/15Watchers — 2 watchers
Inputs used
forks21
stars517
watchers2
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (Apache-2.0)
18/18CONTRIBUTING guide
0/13.5Code of conduct
0/7.2Issue template
0/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingyes
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno
How it's scored
30.1/80Monthly downloads — 179 downloads/month across crates
0/20Registry dependents — not reported by this ecosystem
Inputs used
packagesxfr
dependents
ecosystemscrates
total_downloads1,328
monthly_downloads179
Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

58Moderate · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
0.2/22.5Commit distribution — top contributor authored 99% of commits
4.1/13.5Contributor breadth — 3 contributors
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Inputs used
bus_factor1
contributors_sampled3
top_contributor_share0.993
How it's scored
43.5/46.8Issue resolution — 93% of issues closed
29.2/38.3PR acceptance — 77/101 decided PRs merged
0/15OpenSSF Scorecard: Code-Review — Found 0/15 approved changesets -- score normalized to 0
Inputs used
merged_prs77
open_issues3
closed_issues40
issue_closed_ratio0.93
closed_unmerged_prs24
How it's scored
10/30Ownership backing — personal (user) account
0/20Verified domain — not applicable to user accounts
14.8/25Owner reach — 115 followers of lance0
25/25Track record — 61 public repos, account ~13 yr old
Inputs used
followers115
owner_typeUser
is_verified
owner_loginlance0
public_repos61
account_age_days4,931
Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.
How it's scored
25/25Published & resolvable — 1 package(s) on crates
35/35Publish recency — latest publish 16 days ago
20/20Version history — 34 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packagesxfr
ecosystemscrates
any_deprecatedno
min_days_since_publish16

Engineering Quality

Are baseline engineering and documentation practices in place?

90Excellent · 20% of overall
How it's scored
24/24CI workflows — 3 workflow(s)
24/24Tests present
16/16Linter config
9.6/9.6Pre-commit hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 9 out of 9 merged PRs checked by a CI test -- score normalized to 10
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configyes
has_precommit_configyes

Documentation

85Excellent
How it's scored
30/30README
25/25Documentation directory
0/15Documentation / homepage site
10/10Repository description
10/10Topics — 7 topics
10/10Wiki
Inputs used
topicsbandwidth, benchmark, cli, iperf, network, rust, tui
has_wikiyes
homepage
has_readmeyes
has_docs_diryes
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

52Moderate · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
2.5/2.5CI-Tests — 9 out of 9 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/15 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
7.5/7.5Maintained — 30 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
6.8/7.5Vulnerabilities — 1 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated18
scorecard_versionv5.5.0
checks_inconclusive0
scorecard_aggregate5.2

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

61Moderate · 0% of overall
How it's scored
0/45Agent instructions — no CLAUDE.md / AGENTS.md / editor rules
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 88 of 92 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share0.957
agent_instruction_files
agent_instruction_max_bytes
How it's scored
12.6/18One-command bootstrap — Cargo.toml (toolchain convention, no task runner)
22/22Automated tests
11/11Lint / format config
11/11Static type checking — Rust (statically typed)
10/10Reproducible environment — Dockerfile, Nix, lockfile
0/10Demonstrated agent practice — no agent-authored commits among the last 100
8/8Automated maintenance — 8 of the last 100 commits are automated dependency updates
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Inputs used
has_nixyes
has_testsyes
lockfilesCargo.lock
has_dockerfileyes
typed_languageyes
bootstrap_files
has_devcontainerno
has_linter_configyes
typecheck_configs
agent_commit_share0
toolchain_manifestsCargo.toml
dependency_bot_commit_share0.08
How it's scored
45/45Type-checkable code — Rust (statically typed)
44/55Manageable file sizes — 8/40 source files over 60KB
Inputs used
primary_languageRust
largest_source_bytes154,793
source_files_sampled40
oversized_source_files8
How it's scored
0/40API schema (OpenAPI/GraphQL/proto)
0/20MCP server
40/40Runnable examples — examples
Inputs used
example_dirsexamples
has_mcp_signalno
api_schema_files

Key facts

517GitHub stars
3contributors
459commits, last 12 months
4days since last push
29releases
1bus factor
3open issues
crates.iopackage ecosystems

Data collection warnings

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

More detail

Star and fork history 0 ★ / 21 ⇿
0Stars
21Forks
27Releases

When each star and fork was added, collected from GitHub and bucketed by day. Cumulative growth sits directly above the daily additions it is made of, so the two read against each other: steady organic accretion looks nothing like an abrupt, short-lived burst. Where that difference is measurable, it is reported as growth authenticity.

48121620242162026-022026-042026-06
Major 0Minor 4Patch 23
OpenSSF Scorecard 5.2 / 10
5.2aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-23 11:43 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
10CI-Tests9 out of 9 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/15 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
10Security-Policysecurity policy file detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
9Vulnerabilities1 existing vulnerabilities detected
Direct dependencies 41
RegistryPackageVersion constraintManifest
crates.iotokio1Cargo.toml
crates.iofutures0.3Cargo.toml
crates.ioratatui0.30Cargo.toml
crates.iocrossterm0.29Cargo.toml
crates.ioclap4Cargo.toml
crates.ioclap_complete4.6Cargo.toml
crates.ioserde1Cargo.toml
crates.ioserde_json1Cargo.toml
crates.ioprometheus0.14Cargo.toml
crates.iohyper1Cargo.toml
crates.iohyper-util0.1Cargo.toml
crates.iohttp-body-util0.1Cargo.toml
crates.iomdns-sd0.20Cargo.toml
crates.iotoml1.1Cargo.toml
crates.iodirs6Cargo.toml
crates.ioasync-trait0.1Cargo.toml
crates.ioanyhow1Cargo.toml
crates.iotracing0.1Cargo.toml
crates.iotracing-subscriber0.3Cargo.toml
crates.iotracing-appender0.2Cargo.toml
crates.ioparking_lot0.12Cargo.toml
crates.iohumantime2Cargo.toml
crates.iouuid1Cargo.toml
crates.iohostname0.4Cargo.toml
crates.ioonce_cell1Cargo.toml
crates.iochrono0.4Cargo.toml
crates.ioreqwest0.12Cargo.toml
crates.ioquinn0.11Cargo.toml
crates.iorustls0.23Cargo.toml
crates.iorcgen0.14Cargo.toml
crates.iohmac0.13Cargo.toml
crates.iosha20.11Cargo.toml
crates.iorand0.10Cargo.toml
crates.iosha2_0100.10Cargo.toml
crates.iohmac_0120.12Cargo.toml
crates.iochacha20poly13050.10Cargo.toml
crates.iohkdf0.12Cargo.toml
crates.iodashmap6Cargo.toml
crates.ioipnetwork0.21Cargo.toml
crates.ioupdate-informer1Cargo.toml
crates.iosocket20.6Cargo.toml
All dependencies not collected

The resolved dependency set could not be collected for this report: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [
        "bandwidth",
        "benchmark",
        "cli",
        "iperf",
        "network",
        "rust",
        "tui"
      ],
      "is_fork": false,
      "size_kb": 2162,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "Nix": 2287,
        "Rust": 1146388,
        "Shell": 33112
      },
      "pushed_at": "2026-07-19T05:56:36Z",
      "created_at": "2026-01-31T23:43:42Z",
      "owner_type": "User",
      "updated_at": "2026-07-22T19:11:41Z",
      "description": "A modern iperf3 alternative with a live TUI, multi-client server, and QUIC support. Built in Rust.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "master",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Rust",
      "significant_languages": [
        "Rust"
      ]
    },
    "owner": {
      "blog": "lance0.com",
      "name": "lance",
      "type": "User",
      "login": "lance0",
      "company": null,
      "location": null,
      "followers": 115,
      "avatar_url": "https://avatars.githubusercontent.com/u/3323861?v=4",
      "created_at": "2013-01-20T23:43:42Z",
      "is_verified": null,
      "public_repos": 61,
      "account_age_days": 4931
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.9.21",
          "kind": "patch",
          "published_at": "2026-07-06T19:56:57Z"
        },
        {
          "tag": "v0.9.20",
          "kind": "patch",
          "published_at": "2026-06-23T13:01:21Z"
        },
        {
          "tag": "v0.9.19",
          "kind": "patch",
          "published_at": "2026-06-14T15:15:35Z"
        },
        {
          "tag": "v0.9.18",
          "kind": "patch",
          "published_at": "2026-06-11T19:41:13Z"
        },
        {
          "tag": "v0.9.17",
          "kind": "patch",
          "published_at": "2026-06-11T15:17:32Z"
        },
        {
          "tag": "v0.9.16",
          "kind": "patch",
          "published_at": "2026-06-10T18:19:52Z"
        },
        {
          "tag": "v0.9.14",
          "kind": "patch",
          "published_at": "2026-05-03T23:14:22Z"
        },
        {
          "tag": "v0.9.13",
          "kind": "patch",
          "published_at": "2026-05-03T17:08:23Z"
        },
        {
          "tag": "v0.9.12",
          "kind": "patch",
          "published_at": "2026-05-03T00:33:56Z"
        },
        {
          "tag": "v0.9.11",
          "kind": "patch",
          "published_at": "2026-04-30T15:15:43Z"
        },
        {
          "tag": "v0.9.10",
          "kind": "patch",
          "published_at": "2026-04-22T20:07:01Z"
        },
        {
          "tag": "v0.9.9",
          "kind": "patch",
          "published_at": "2026-04-21T03:55:45Z"
        },
        {
          "tag": "v0.9.8",
          "kind": "patch",
          "published_at": "2026-04-17T19:57:47Z"
        },
        {
          "tag": "v0.9.7",
          "kind": "patch",
          "published_at": "2026-04-16T15:26:12Z"
        },
        {
          "tag": "v0.9.6",
          "kind": "patch",
          "published_at": "2026-03-18T12:53:13Z"
        },
        {
          "tag": "v0.9.5",
          "kind": "patch",
          "published_at": "2026-03-17T14:41:24Z"
        },
        {
          "tag": "v0.9.4",
          "kind": "patch",
          "published_at": "2026-03-11T17:00:06Z"
        },
        {
          "tag": "v0.9.3",
          "kind": "patch",
          "published_at": "2026-03-10T14:54:18Z"
        },
        {
          "tag": "v0.9.2",
          "kind": "patch",
          "published_at": "2026-03-06T20:34:58Z"
        },
        {
          "tag": "v0.9.1",
          "kind": "patch",
          "published_at": "2026-03-05T18:48:23Z"
        },
        {
          "tag": "v0.8.0",
          "kind": "minor",
          "published_at": "2026-02-12T20:42:45Z"
        },
        {
          "tag": "v0.7.1",
          "kind": "patch",
          "published_at": "2026-02-12T15:09:14Z"
        },
        {
          "tag": "v0.7.0",
          "kind": "minor",
          "published_at": "2026-02-11T21:27:12Z"
        },
        {
          "tag": "v0.6.1",
          "kind": "patch",
          "published_at": "2026-02-10T18:19:07Z"
        },
        {
          "tag": "v0.6.0",
          "kind": "minor",
          "published_at": "2026-02-06T19:21:25Z"
        },
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2026-02-05T19:01:36Z"
        },
        {
          "tag": "v0.4.4",
          "kind": "patch",
          "published_at": "2026-02-04T21:03:35Z"
        },
        {
          "tag": "v0.4.3",
          "kind": "patch",
          "published_at": "2026-02-04T15:32:49Z"
        },
        {
          "tag": "v0.4.2",
          "kind": "patch",
          "published_at": "2026-02-03T16:29:35Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "ec39ea55ae7e0fc08984ddcedc9fc1827683ad37",
          "body": "ci: add typo checks",
          "is_bot": false,
          "headline": "Merge pull request #141 from lance0/ci/typos-check",
          "author_name": "lance",
          "author_login": "lance0",
          "committed_at": "2026-07-09T20:35:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "198c618e491000f52924d5ec913842831081ddb2",
          "body": null,
          "is_bot": false,
          "headline": "ci: trim typos allowlist",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-09T20:31:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7d7b7b46d03e8cd9f3c1c8404647737d2f31d3d5",
          "body": null,
          "is_bot": false,
          "headline": "ci: add typo checks",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-09T20:28:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "30145b64316273178f3b5516f7f2d19b6abfb221",
          "body": "ci: compile Windows paths",
          "is_bot": false,
          "headline": "Merge pull request #140 from lance0/ci/windows-cargo-check",
          "author_name": "lance",
          "author_login": "lance0",
          "committed_at": "2026-07-09T20:24:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "768beec68ce516194d00038f6b623748e923f8d8",
          "body": null,
          "is_bot": false,
          "headline": "ci: compile Windows paths",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-09T20:19:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "09f7416a3fd80833fb3e29e8ef2f5cd5769181e7",
          "body": "feat(config): add client transport defaults",
          "is_bot": false,
          "headline": "Merge pull request #139 from lance0/feat/client-config-parity",
          "author_name": "lance",
          "author_login": "lance0",
          "committed_at": "2026-07-09T20:16:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "be959e3216998438e7e97bdc6fe863821b060889",
          "body": null,
          "is_bot": false,
          "headline": "fix(tui): satisfy stable clippy",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-09T19:55:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c0bc2acc2e986b606e32eeb46cc6633c8578d4b5",
          "body": null,
          "is_bot": false,
          "headline": "feat(config): add client transport defaults",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-09T19:37:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1e723f3fe73a42c505baf35d7ee3258c86651271",
          "body": "docs/demo.gif (~198 KB) and docs/demo.tape are README/recording assets, not\nneeded to build or use the crate. crates.io resolves the README image link\nagainst the repository, so the preview still renders there — this only trims\nthe .crate tarball.",
          "is_bot": false,
          "headline": "build: exclude the demo GIF and tape from the published crate",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-07T15:01:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0d1b26fc578ea3dd868b0e5c937d4fa58caaadaf",
          "body": "docs: animated TUI demo GIF as the README preview",
          "is_bot": false,
          "headline": "Merge pull request #138 from lance0/docs/demo-gif",
          "author_name": "lance",
          "author_login": "lance0",
          "committed_at": "2026-07-07T14:22:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "59a67040a7095b347755d812e4fb7ef5a99e5748",
          "body": "Replace the static xfr-ss.png screenshot with a VHS-recorded GIF of the live\nTUI: a rate-limited (-b 1G) TCP test against a local server showing the\nreal-time throughput graph, per-second speed/RTT/retransmit stats, and the\nSettings modal. Rendered from docs/demo.tape (reproduce steps in its header);\nruns in a throwaway HOME so it is deterministic and touches no real config.",
          "is_bot": false,
          "headline": "docs: animated TUI demo GIF as the README preview",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-07T14:20:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6350eb5e60d6762918fdeac68237b44aaf810dae",
          "body": "…abling-update-check\n\nfeat(update): allow disabling the update check (LAN-235)",
          "is_bot": false,
          "headline": "Merge pull request #137 from lance0/lancey3/lan-235-feature-allow-dis…",
          "author_name": "lance",
          "author_login": "lance0",
          "committed_at": "2026-07-07T14:05:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "035adb2cb74d16ea9c5850db7948486296eb966d",
          "body": "- examples/config.toml shipped an active `no_update_check = false`. Because an\n  explicit config value wins over the saved pref (by design), that would defeat\n  a user's persisted TUI \"Update check: off\" toggle for anyone who copied the\n  example. Comment it out so an unset config lets the TUI toggl\n[…]\n table and man page CLIENT OPTIONS; DO_NOT_TRACK /\n  XFR_NO_UPDATE_CHECK in the man page ENVIRONMENT section; and a \"Disabling the\n  update check\" section in docs/FEATURES.md with the full precedence.",
          "is_bot": false,
          "headline": "docs(update): document the opt-out and fix the example config",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-07T13:59:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9bb8229b759fe6d6d7515abceae8cf06e0186e3e",
          "body": "The resolution OR-chain flattened the config/pref tristate with\nunwrap_or(false), so Some(false) (\"explicitly enabled\") and None (\"unset\")\nwere indistinguishable: an explicit no_update_check = false in config.toml\ncould not re-enable the check over a stale disable_update_check = true in\nprefs.toml.\n\n[…]\nk_disabled, where an explicit config\nvalue wins over the saved pref (matching the existing theme CLI>config>saved\nprecedence). Add a unit test covering the precedence, including the\ncompiled-out path.",
          "is_bot": false,
          "headline": "fix(update): let config.toml override a stale prefs toggle",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-07T13:39:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "61203144a8bdf0a53ce3ef10a53d2bdeab1b968d",
          "body": "The background \"newer release available\" check (update-informer against the\nGitHub API, run in TUI mode) had no opt-out, which is unwanted when xfr is\ninstalled from a package repository or run in locked-down environments.\n\nAdd opt-outs at every layer:\n- --no-update-check CLI flag\n- DO_NOT_TRACK (cr\n[…]\ne (default-on): --no-default-features drops the\n  update-informer dependency entirely, so package builds ship no phone-home code\n\nResolution precedence: compiled-out > env > CLI > config > saved pref.",
          "is_bot": false,
          "headline": "feat(update): allow disabling the update check (LAN-235)",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-07T13:33:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "689d99f6eaaab7243d5c06699ef796175bd28c08",
          "body": "Invalid pointer dereference in the fmt::Pointer impl (fixed >=0.9.20).\nTransitive dev-dependency only (criterion -> rayon -> crossbeam-deque ->\ncrossbeam-epoch), not in release binaries. Lockfile-only, MSRV 1.88 intact.",
          "is_bot": false,
          "headline": "deps: bump crossbeam-epoch 0.9.18 -> 0.9.20 (RUSTSEC-2026-0204)",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-07T13:05:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "24861f1c4e982e3550d99ae007f8fba459c62cf0",
          "body": "…pt [skip ci]",
          "is_bot": false,
          "headline": "docs: fix stale ROADMAP CI note and Cyrillic homoglyph in verify scri…",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-06T21:48:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "20607018a60354b7b70b0edb26fe12a1a770072a",
          "body": "ci: migrate cross builds to cargo-zigbuild",
          "is_bot": false,
          "headline": "Merge pull request #136 from lance0/ci/zigbuild",
          "author_name": "lance",
          "author_login": "lance0",
          "committed_at": "2026-07-06T21:13:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "82d08843843efb4f535c8598bc3d7d994ce1281c",
          "body": "Addresses the adversarial-review finding that the release toolchain was\nnon-reproducible: setup-zig defaulted to Zig master (an ephemeral nightly),\ncargo-zigbuild came from crates.io latest, and cross was built from the\nmoving main branch — any of which could drift and change or break a future\ntag b\n[…]\nused:\n- Zig 0.16.0 (latest stable; cargo-zigbuild 0.23.0 supports zig 0.15+)\n- cargo-zigbuild 0.23.0 (--version)\n- cross main @ 64b5bb4d (--rev)\n\nBump these intentionally via dependency-update review.",
          "is_bot": false,
          "headline": "ci: pin zig / cargo-zigbuild / cross to known-good versions",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-06T21:09:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e89b79f8913fcea5e5adc441149e753eff9c3f93",
          "body": "Add scripts/verify-target-binary.sh, used by both workflows:\n- resolves the binary tolerant of cargo-zigbuild's glibc-suffixed target dir,\n  failing loudly (with a find dump) if neither path holds an executable\n- gnu targets: asserts no required GLIBC symbol above the 2.17 floor\n- musl targets: asse\n[…]\nfy + package by base target,\nartifact names unchanged). ci.yml cross-smoke runs it as an ABI check on the\nzigbuild targets, so a build that links the wrong ABI fails the PR, not just a\nfuture release.",
          "is_bot": false,
          "headline": "ci: verify cross-built binary ABI and fail loudly on missing binary",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-06T20:59:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2f720617173e324503be54231753d67539854eeb",
          "body": "cross 0.2.5's aarch64 images ship an x86_64 glibc too old to run build\nscripts produced by modern Rust (1.96), so `cross build` for\naarch64-unknown-linux-{gnu,musl} fails with GLIBC_2.28+ symbol errors on a\nfresh build (masked intermittently by CI caching). release.yml built the\nsame targets with th\n[…]\nls install.\n\nci.yml cross-smoke now covers all 5 release targets in debug on every PR.\nRelease artifact names are unchanged (packaged by base target, tolerant of\nzigbuild's glibc-suffixed output dir).",
          "is_bot": false,
          "headline": "ci: migrate cross builds to cargo-zigbuild (fix aarch64 glibc failures)",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-06T20:53:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bf773aec2f18140478216546d46e60cf86820c72",
          "body": "The PR-CI build/test/clippy already pass --locked; the release job's actual\nbinary builds (native + cross, and the completions build) did not, so a\nCargo.toml/Cargo.lock drift could ship binaries built from a resolved graph\nthat differs from the committed lockfile. Add --locked to all three so the\nshipped artifacts are built from exactly the locked dependency graph.",
          "is_bot": false,
          "headline": "ci(release): build release binaries with --locked",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-06T20:28:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b80e852bef3983c84f2f1e329df65582bc0faad5",
          "body": "ci: harden the PR pipeline",
          "is_bot": false,
          "headline": "Merge pull request #135 from lance0/ci/hardening",
          "author_name": "lance",
          "author_login": "lance0",
          "committed_at": "2026-07-06T20:27:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2ccfece3687c3a235cf4d20305e918af559c5c4a",
          "body": "- cross-target smoke matrix (4 Linux/Android targets via cross) on every PR:\n  catches the release-time glibc-symbol class that killed v0.9.15 before tag;\n  subsumes the old single cross-aarch64-gnu job\n- test + clippy feature matrices (--all-features, --no-default-features):\n  catches the LAN-172 d\n[…]\nbuilt binary (ci + release)\n- audit.yml skipped on code-only PRs via Cargo.toml/lock path filter\n\nDeferred CI ideas (cargo-deny, typos, Windows check, nightly concurrency\nsanitizer) logged in ROADMAP.",
          "is_bot": false,
          "headline": "ci: harden the PR pipeline",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-06T20:22:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "213d6c34c60611309e9ae34af336bcf3007cbf11",
          "body": "Add a verify-ghcr job (needs: [docker]) that inspects the pushed\nghcr.io/lance0/xfr:<version> multi-arch tag and fails the run if either\nlinux/amd64 or linux/arm64 is missing, so a \"succeeded but incomplete\"\ncontainer push is visible. The release job's needs are unchanged, so a\ndocker/verify failure never blocks the GitHub release or crates.io -\nthe container image is a recoverable publishing incident, backfilled by\nre-running the docker job.",
          "is_bot": false,
          "headline": "ci(release): verify GHCR image after publish, document docker decoupling",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-06T20:10:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "24b93d866e9b34320e22de5b79ff2c986ccc462f",
          "body": null,
          "is_bot": false,
          "headline": "Bump version to v0.9.21",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-06T19:50:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e14851af50f60a584170965b2e82275f10fe62d3",
          "body": "fix: cancel-sender-drop busy-loops and MPTCP validation (LAN-170)",
          "is_bot": false,
          "headline": "Merge pull request #131 from lance0/lan-170",
          "author_name": "lance",
          "author_login": "lance0",
          "committed_at": "2026-07-06T19:10:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "faff760a4f64ed9ca1f2283827c6903ae1bca1da",
          "body": null,
          "is_bot": false,
          "headline": "fix(quic): reschedule tee after divert-only receive batches",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-06T19:07:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "10da7500c7de5dce9f011ae57ef9a9635fc63153",
          "body": "Fixes three classes of busy-loop bugs where `_ = cancel.changed()`\ndiscards the `Err` from a dropped watch sender, causing the receive\nloop to spin:\n\n- quic.rs receive_quic_data: extract handle_cancel_change helper,\n  break on Err (sender dropped) or cancel=true\n- tcp.rs receive_data (two sites): bi\n[…]\nancel=false → Continue\n- MAX_DIVERT_ITERATIONS constant bounds check\n- validate_mptcp probes kernel (Ok or Unsupported on Linux,\n  Unsupported elsewhere)\n- wrap_mptcp_error wraps EINVAL as Unsupported",
          "is_bot": false,
          "headline": "fix: cancel-sender-drop busy-loops and MPTCP validation (LAN-170)",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-06T19:07:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9df90d30cb7437a4a97fc7b7dae7617e773e2d5f",
          "body": "fix: pause-aware duration clock in senders and server stats (LAN-230)",
          "is_bot": false,
          "headline": "Merge pull request #133 from lance0/lan-230",
          "author_name": "lance",
          "author_login": "lance0",
          "committed_at": "2026-07-06T19:03:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "80cf39ba78a7caa7fadd394852274b60a376474d",
          "body": null,
          "is_bot": false,
          "headline": "fix(pause): exclude paused time from control clocks",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-06T18:59:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ba101c941bde5105132b5e5fbab1f0a168719f22",
          "body": "When a test is paused, the duration clock kept ticking. All data-plane\nsender tasks (TCP send_data/send_data_half, QUIC send_quic_data, UDP\nsend_udp_paced/send_udp_unlimited) computed deadline = start + duration\nusing wall-clock time that did not account for paused intervals. The\nserver stats loops \n[…]\ngression test: wait_while_paused_timed_returns_pause_duration verifies\nthe helper returns the correct pause duration.\n\n389 tests pass (258 lib + 42 + 67 integration + 20 + 2).\nclippy clean, fmt clean.",
          "is_bot": false,
          "headline": "fix: pause-aware duration clock in senders and server stats (LAN-230)",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-06T18:55:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f4f12e1a3944e54e4e0dbbbced217af9933080f9",
          "body": "fix: control-stream desync via dedicated reader task (LAN-229)",
          "is_bot": false,
          "headline": "Merge pull request #132 from lance0/lan-229",
          "author_name": "lance",
          "author_login": "lance0",
          "committed_at": "2026-07-06T18:54:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7cc6191b87bc46870828b0088cb6943672a55b81",
          "body": "ci: make MPTCP skip explicit and visible on standard runners (LAN-174)",
          "is_bot": false,
          "headline": "Merge pull request #134 from lance0/lan-174",
          "author_name": "lance",
          "author_login": "lance0",
          "committed_at": "2026-07-06T18:52:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a222dcf6924a7aed1fa9727ae718f7c2e362f3db",
          "body": "fix: dual-stack V6ONLY inconsistency and DSCP dual-stack (LAN-169)",
          "is_bot": false,
          "headline": "Merge pull request #130 from lance0/lan-169",
          "author_name": "lance",
          "author_login": "lance0",
          "committed_at": "2026-07-06T18:52:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "46d993708f224dd36af4583d858c68fd2b67df80",
          "body": null,
          "is_bot": false,
          "headline": "fix(net): tolerate unsupported IPv4 TOS on macOS IPv6 sockets",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-06T18:34:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1a47bbb9a2abff9527b7d99abccfa398866eaf72",
          "body": null,
          "is_bot": false,
          "headline": "fix(net): surface unexpected dual-stack DSCP errors",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-06T18:25:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "58f11836d66b91b5fde07daaef8c334fa38671b3",
          "body": "The MPTCP CI job exited 0 when MPTCP/netem was unavailable on standard\nrunners, silently hiding real MPTCP regressions under a passing job.\n\nFix: emit GitHub Actions ::warning:: annotations when skipping due to\nmissing kernel capability (MPTCP disabled, netem module unavailable).\nThe job still passe\n[…]\nard runners), but the\nskip is now visible in the PR check UI and job logs.\n\nRename the CI job to 'MPTCP (requires kernel MPTCP + netem)' to make\nthe runner-capability requirement explicit at a glance.",
          "is_bot": false,
          "headline": "ci: make MPTCP skip explicit and visible on standard runners (LAN-174)",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-06T18:18:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7be5252f090a10bea97862fcd5c14d1152185898",
          "body": "The TCP and QUIC client control loops ran read_message inside\ntokio::select! alongside cancel/pause watch channels. If a\ncancel/pause arm fired while read_message was between fill_buf\nand consume, the dropped future lost buffered bytes, desyncing\nthe control stream.\n\nFix: split ProtectedControl into\n[…]\nselect arm replaces the\n  old timeout_at wrapper around read_message\n- control_handle.abort() on every loop exit path\n\n388 tests pass (257 lib + 42 + 67 integration + 20 + 2).\nclippy clean, fmt clean.",
          "is_bot": false,
          "headline": "fix: control-stream desync via dedicated reader task (LAN-229)",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-06T18:11:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6db8a0f9100f74115b270834601487ac64cb953c",
          "body": "#29: Centralize IPV6_V6ONLY logic\n- Add set_v6only_for_addr helper: concrete IPv6 → V6ONLY=true,\n  unspecified :: → respects AddressFamily (DualStack=false, V6Only=true)\n- create_tcp_listener_on_addr now takes AddressFamily parameter\n- create_udp_socket_bound now takes AddressFamily parameter\n- crea\n[…]\nPv4 TCP\n- test_dualstack_udp_accepts_ipv4: [::] DualStack UDP receives IPv4\n- test_dscp_sets_both_on_dualstack_ipv6: getsockopt verifies both\n  IPV6_TCLASS and IP_TOS are set on dual-stack IPv6 socket",
          "is_bot": false,
          "headline": "Fix dual-stack V6ONLY inconsistency and DSCP dual-stack (LAN-169)",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-06T18:01:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "140aadb134f739172e0996e233a215dbb155a890",
          "body": "fix: cancel/pause latency and UDP burst after resume (LAN-160 v2)",
          "is_bot": false,
          "headline": "Merge pull request #129 from lance0/lan-160-v2",
          "author_name": "lance",
          "author_login": "lance0",
          "committed_at": "2026-07-06T15:47:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9e227a8913e457b24776659b878657dd8435a8ef",
          "body": null,
          "is_bot": false,
          "headline": "test(udp): fix macos paced resume test",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-06T15:41:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "49faa0852148bcd83c4b5e65a298d07495d63891",
          "body": "Split ProtectedControl into ControlReader/ControlWriter halves so a\ndedicated control-reader task can own the recv codec independently\nfrom the stats/interval loop that owns the send codec.\n\nServer-side changes (serve.rs):\n- Add ControlCommand enum and spawn_control_reader helper that owns\n  the rea\n[…]\n_udp_pause_resume_no_burst: smoke test for pause/resume/cancel\n- test_udp_paced_no_burst_after_resume: unit test verifying no packet\n  arrives in first 60ms after resume, then one arrives within 500ms",
          "is_bot": false,
          "headline": "Fix cancel/pause latency and UDP burst after resume (LAN-160 v2)",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-06T15:16:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cccb07f3fcc4f7cd6c10ce50a143bd778a85921f",
          "body": "feat: PSK sessions require AEAD-protected control channels (LAN-159)",
          "is_bot": false,
          "headline": "Merge pull request #126 from lance0/lan-159-protected-control",
          "author_name": "lance",
          "author_login": "lance0",
          "committed_at": "2026-07-06T14:23:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "25ed5270442c161dee1a3e43af418469e5acf88b",
          "body": "ProtectedControl::write_message split each plaintext control message into\ntwo writes (payload, then a lone \"\\n\"), so under TCP_NODELAY each message\nwent out as two segments. On a saturated, lossy link the trailing 1-byte\nnewline of the final Result frame could be stranded when the server tore\ndown, \n[…]\nreported \"Connection closed without result\" — the\ncontrol-channel skew regression test caught this. Collapse the plaintext\nbranch back to the single write used pre-LAN-159; the AEAD path is\nunchanged.",
          "is_bot": false,
          "headline": "fix(control-crypto): write plaintext control frames in a single write",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-06T14:16:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2ffd721ae6a117e92512c9edba66393ab78c6788",
          "body": "When PSK authentication is configured, the control channel is now\nencrypted with ChaCha20-Poly1305 AEAD after the handshake. Separate\nc2s/s2c keys are derived from the PSK and both peers' nonces via\nHKDF-SHA256. The server sends a transcript proof (server_proof) in\nAuthSuccess binding the exact wire\n[…]\notocol changes: client_nonce field on Hello, server_proof field on\nAuthSuccess, protected_control_v1 in SUPPORTED_CAPABILITIES.\n\nWired into all handshake sites: TCP and QUIC on both client and server.",
          "is_bot": false,
          "headline": "feat: PSK sessions require AEAD-protected control channels (LAN-159)",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-06T13:41:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a65b2520ee50b010cff6f4d7bb5b6e9f11b909ab",
          "body": "… (#124)\n\n* fix(pause): treat closed pause channel as non-paused (LAN-161)\n\n\\n\\nAdds pause::is_paused and guards the pause.changed() select arms so a dropped pause sender cannot spin the send/receive loops or bypass pacing sleeps/tickers.\n\n* fix(client, pause): address review feedback on cleanup and\n[…]\nrved) while the sender is alive; only `Err(Closed)` means the channel is gone.\n\n* comment: clarify iter_mut() preserves handles for abort on timeout\n\n---------\n\nCo-authored-by: Lance <lance@lance.dev>",
          "is_bot": false,
          "headline": "fix: LAN-161 pause channel closure busy-loop and unawaited QUIC tasks…",
          "author_name": "lance",
          "author_login": "lance0",
          "committed_at": "2026-07-06T12:40:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2a9bb20eb535f1330d1f3b494698a4a24428b320",
          "body": null,
          "is_bot": false,
          "headline": "fix: address post-release review regressions (#123)",
          "author_name": "lance",
          "author_login": "lance0",
          "committed_at": "2026-07-02T20:09:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d732e233fd477feb72849314bf8950c6c09742de",
          "body": null,
          "is_bot": false,
          "headline": "ci: skip markdown-only changes",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-01T18:06:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "511bdb7f7697c5df01e643db0cc6188513e5c837",
          "body": null,
          "is_bot": false,
          "headline": "docs: align roadmap and changelog with current work",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-01T18:02:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dad7b894093e998ea0a98797a78d0efe572b811e",
          "body": null,
          "is_bot": false,
          "headline": "chore: ignore local review marker",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-01T17:57:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d40f9e00ff97c3b87308200e4c0dc30cfd9a55bd",
          "body": "…s-0543a7c382\n\nBump the rust-dependencies group across 1 directory with 6 updates",
          "is_bot": false,
          "headline": "Merge pull request #112 from lance0/dependabot/cargo/rust-dependencie…",
          "author_name": "lance",
          "author_login": "lance0",
          "committed_at": "2026-07-01T17:53:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d5e4c08c9a651f951afb7e6748dd169d055a31b2",
          "body": "…/cache-6\n\nBump actions/cache from 5 to 6",
          "is_bot": false,
          "headline": "Merge pull request #111 from lance0/dependabot/github_actions/actions…",
          "author_name": "lance",
          "author_login": "lance0",
          "committed_at": "2026-07-01T17:53:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3211583cd030541399e6d4ef9ef297775bbb2ddf",
          "body": "…/checkout-7\n\nBump actions/checkout from 6 to 7",
          "is_bot": false,
          "headline": "Merge pull request #109 from lance0/dependabot/github_actions/actions…",
          "author_name": "lance",
          "author_login": "lance0",
          "committed_at": "2026-07-01T17:53:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4470ea481c9990e73781dcbdc2da157bbd2d1bb5",
          "body": "chore(tests): clean stale rate-limit timeout comment",
          "is_bot": false,
          "headline": "Merge pull request #122 from lance0/fix/misc-low-risk-cleanups",
          "author_name": "lance",
          "author_login": "lance0",
          "committed_at": "2026-07-01T17:49:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "af558e70fbfc6e4bbc2cd52455f3445fb42baad1",
          "body": "fix(protocol,tcp): harden version and receive teardown",
          "is_bot": false,
          "headline": "Merge pull request #121 from lance0/fix/tcp-version-compat",
          "author_name": "lance",
          "author_login": "lance0",
          "committed_at": "2026-07-01T17:49:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8dc67f316334e7bfa5bfa1034c8ea0b64e6dea2f",
          "body": "The test now requires an explicit Ok(Err(_)) for the rejected connection; remove the outdated note that allowed an outer timeout.",
          "is_bot": false,
          "headline": "test(integration): clean up stale rate-limit timeout comment",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-01T17:43:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5bd5f1731b4c3390720df9db1add445d58676746",
          "body": null,
          "is_bot": false,
          "headline": "fix(protocol,tcp): harden version and receive teardown",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-01T17:35:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "32de0fcb7955be10685db98e99b19eab0800454a",
          "body": "fix(misc): LAN-172 low-risk cleanups batch",
          "is_bot": false,
          "headline": "Merge pull request #120 from lance0/fix/misc-low-risk-cleanups",
          "author_name": "lance",
          "author_login": "lance0",
          "committed_at": "2026-07-01T17:30:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e7c6dc6276de9dd4111848a0cd86e35df83f1851",
          "body": "- Suppress --no-default-features dead-code warning for discovery fallback register_server stub.\n\n- Strengthen integration test_rate_limit to assert the second concurrent connection is rejected and abort the first client to avoid long waits.\n\n- Distinguish unset -t/--time from the 10s default so expl\n[…]\ne MTU probe size_ladder compute the family-aware max payload from 9216-byte jumbo minus IP overhead so IPv6 uses 9168 instead of 9188.\n\n- Add unit tests for duration resolution and IPv6 ladder bounds.",
          "is_bot": false,
          "headline": "fix(misc): LAN-172 low-risk cleanups batch",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-01T17:26:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "57a8de507ab847b75dbfc50429d9d8a7ab08534b",
          "body": "fix(tui,config,main): LAN-163 + LAN-173 TUI/preset polish",
          "is_bot": false,
          "headline": "Merge pull request #119 from lance0/fix/tui-preset-polish",
          "author_name": "lance",
          "author_login": "lance0",
          "committed_at": "2026-07-01T17:19:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3b6d7bf434c7044b221cbf7edaf4dd29b8fffa9b",
          "body": "- Count zero-throughput intervals in the live TUI average speed.\n\n- Keep retransmit fallback cumulative by accumulating per-stream interval deltas.\n\n- Apply preset max_duration_secs when --max-duration is not supplied.\n\n- Document bandwidth_limit as reserved/unused in config structs, sample, and docs.\n\n- Add unit tests for average speed, retransmit fallback, preset max_duration, and config parsing.",
          "is_bot": false,
          "headline": "fix(tui,config,main): LAN-163 + LAN-173 TUI/preset polish",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-01T17:14:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "316a076f5789825fdf6d32540d90234073dcb1d3",
          "body": "fix(protocol,probe,net): LAN-167 + LAN-168 protocol/probe validation",
          "is_bot": false,
          "headline": "Merge pull request #118 from lance0/fix/protocol-probe-validation",
          "author_name": "lance",
          "author_login": "lance0",
          "committed_at": "2026-07-01T17:10:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d494f34000486471b73c1c22781421d758ee64e7",
          "body": "- Reject TestAck messages that contain both udp_token and data_ports.\n\n- Validate padded probe packets: declared_size must be >= header and <= datagram length; acks may still carry larger declared_size.\n\n- Count echo receipt as forward-path success and stop waiting once the echo arrives.\n\n- Wrap literal IPv6 addresses in brackets in resolve_host.\n\n- Add regression tests for each fix.",
          "is_bot": false,
          "headline": "fix(protocol,probe,net): LAN-167 + LAN-168 protocol/probe validation",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-01T17:09:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f820fd47a6ff046ad78317afbf9bf41411f6a6d0",
          "body": "fix(auth,serve,cli): LAN-158 + LAN-171 security hardening",
          "is_bot": false,
          "headline": "Merge pull request #117 from lance0/fix/security-hardening-batch",
          "author_name": "lance",
          "author_login": "lance0",
          "committed_at": "2026-07-01T16:59:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d3c88d549577528fc7a0200aa34a7a54d2f75417",
          "body": "- Add --preset server arg; enforce ServerPreset.allowed_clients as an additional AND ACL at TCP and QUIC accept time.\n\n- Harden constant_time_eq to avoid length-mismatch short-circuit and trailing-zero false positives.\n\n- Reject PSK files with group/other access on Unix.\n\n- Warn users that --psk and XFR_PSK leak through process metadata; update --psk help text on both client and server.\n\n- Add regression tests for preset allow/deny and PSK file permissions/constant-time comparison.",
          "is_bot": false,
          "headline": "fix(auth,serve,cli): LAN-158 and LAN-171 security hardening",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-01T16:55:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aed6e55f05f48b721546e2f0a4c6b534ad869a68",
          "body": "fix(output,ci,install): harden output and release paths",
          "is_bot": false,
          "headline": "Merge pull request #116 from lance0/fix/harden-output-and-release",
          "author_name": "lance",
          "author_login": "lance0",
          "committed_at": "2026-07-01T16:43:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9367ec13a2974a17c9614557e9afc7739f822b68",
          "body": "- PushGatewayClient::new now returns anyhow::Result and surfaces\n  reqwest builder errors instead of falling back to a default client via\n  unwrap_or_default(), which silently dropped the 30s timeout.\n- output_json() and output_interval_json() now return anyhow::Result;\n  callers propagate/log seria\n[…]\n/*.tar.gz already covers it after the move step).\n- install.sh now directs Intel macOS (x86_64) users to 'cargo install xfr'\n  instead of attempting to download a removed artifact.\n\n(LAN-156, LAN-157)",
          "is_bot": false,
          "headline": "fix(output,ci,install): harden output and release paths",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-01T16:23:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "51e5323c7ed0b0a80c0d0dfa8004407c33fca7c3",
          "body": "fix(server,stats,diff): aggregate final TCP info, round RTT averages, flag zero-baseline regressions",
          "is_bot": false,
          "headline": "Merge pull request #115 from lance0/fix/result-stats-correctness",
          "author_name": "lance",
          "author_login": "lance0",
          "committed_at": "2026-07-01T16:16:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d59fd8a4268360ad2fee358fc617ea6664e6af90",
          "body": "… flag zero-baseline regressions\n\n- Server final TestResult.tcp_info now aggregates per-stream final\n  TcpInfoSnapshot snapshots via TestStats::final_local_tcp_info() instead of\n  returning only the last-pushed snapshot.\n- Fix fractional RTT averaging in poll_local_tcp_info() and\n  final_local_tcp_i\n[…]\nthose changes in is_regression, so regressions are flagged\n  instead of reported as 0.0% / OK.\n- Add unit tests for multi-stream aggregation, fractional averages, and\n  zero-baseline diff regressions.",
          "is_bot": false,
          "headline": "fix(server,stats,diff): aggregate final TCP info, round RTT averages,…",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-01T16:13:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "901d33ccd8ee735978a0773317068f5f71c5f9d5",
          "body": "fix(server): clean up active test entry and metrics on abort/cancel/error",
          "is_bot": false,
          "headline": "Merge pull request #114 from lance0/fix/cleanup-active-tests-on-abort-v2",
          "author_name": "lance",
          "author_login": "lance0",
          "committed_at": "2026-07-01T16:00:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b35c7bc02980805b40eb816435f4357d2790f03c",
          "body": "…rror/cancel",
          "is_bot": false,
          "headline": "fix(server): always clean up active_tests entry and metrics on test e…",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-01T15:57:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4523f040d2f848299693f2b576bfcfc6072e0165",
          "body": "…n test error/cancel\"\n\nThis reverts commit 030a308f7d2c8ebf6044a99308fd1d9f368f6f30.",
          "is_bot": false,
          "headline": "Revert \"fix(server): always clean up active_tests entry and metrics o…",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-01T15:52:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "030a308f7d2c8ebf6044a99308fd1d9f368f6f30",
          "body": "…rror/cancel",
          "is_bot": false,
          "headline": "fix(server): always clean up active_tests entry and metrics on test e…",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-01T15:51:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "77e325440301db8883155246682d399656a0ab1a",
          "body": "fix(tcp): resume partial regular writes and zero-copy sends from correct offset",
          "is_bot": false,
          "headline": "Merge pull request #113 from lance0/fix/tcp-integrity-and-server-leak",
          "author_name": "lance",
          "author_login": "lance0",
          "committed_at": "2026-07-01T15:44:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8565992ede44eb0ec9122e607a655eb1ba83285c",
          "body": null,
          "is_bot": false,
          "headline": "refactor(zerocopy): make send_chunk one-shot and caller-owned offset",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-01T15:41:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b4fc2f1332d482c30f047d0a040da1138695b05d",
          "body": "…ect offset",
          "is_bot": false,
          "headline": "fix(tcp): resume partial regular writes and zero-copy sends from corr…",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-07-01T15:35:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6edd9cd6465ee730c8616fcd5585d4bbbc8faced",
          "body": "Bumps the rust-dependencies group with 6 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [ratatui](https://github.com/ratatui/ratatui) | `0.30.1` | `0.30.2` |\n| [mdns-sd](https://github.com/keepsimple1/mdns-sd) | `0.20.0` | `0.20.1` |\n| [anyhow](https://github.com/dtolnay/\n[…]\npendency-version: 0.23.41\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n  dependency-group: rust-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump the rust-dependencies group across 1 directory with 6 updates",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-28T05:54:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b7cb481cf2fac586b8f1338140033f25e2b8773b",
          "body": "Bumps [actions/cache](https://github.com/actions/cache) from 5 to 6.\n- [Release notes](https://github.com/actions/cache/releases)\n- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)\n- [Commits](https://github.com/actions/cache/compare/v5...v6)\n\n---\nupdated-dependencies:\n- dependency-name: actions/cache\n  dependency-version: '6'\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump actions/cache from 5 to 6",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-28T05:52:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1f74e23e273c7815c712747c415e39d7c9ea3ea4",
          "body": null,
          "is_bot": false,
          "headline": "Bump version to v0.9.20",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-06-23T12:54:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "639bb409b35f723d3790385008a0c38a3d38ead6",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/v6...v7)\n\n---\nupdated-dependenc\n[…]\n:\n- dependency-name: actions/checkout\n  dependency-version: '7'\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump actions/checkout from 6 to 7",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-21T05:52:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "519b16f528058984d35d0b2f359b48996b626462",
          "body": "Bumps [docker/metadata-action](https://github.com/docker/metadata-action) from 5 to 6.\n- [Release notes](https://github.com/docker/metadata-action/releases)\n- [Commits](https://github.com/docker/metadata-action/compare/v5...v6)\n\n---\nupdated-dependencies:\n- dependency-name: docker/metadata-action\n  d\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump docker/metadata-action from 5 to 6 (#107)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-16T13:48:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7bd4ce85712bc7eb4bfb5abaed8381e302fc3294",
          "body": "Bumps [docker/build-push-action](https://github.com/docker/build-push-action) from 6 to 7.\n- [Release notes](https://github.com/docker/build-push-action/releases)\n- [Commits](https://github.com/docker/build-push-action/compare/v6...v7)\n\n---\nupdated-dependencies:\n- dependency-name: docker/build-push-\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump docker/build-push-action from 6 to 7 (#106)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-16T13:48:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8c2d6e15e8119824c7267588b1379b3882eb0192",
          "body": "Bumps [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action) from 3 to 4.\n- [Release notes](https://github.com/docker/setup-qemu-action/releases)\n- [Commits](https://github.com/docker/setup-qemu-action/compare/v3...v4)\n\n---\nupdated-dependencies:\n- dependency-name: docker/setup-qemu-\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump docker/setup-qemu-action from 3 to 4 (#105)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-16T13:48:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "05fadedea33ff7772fe6633244dc93fff3937be7",
          "body": "Bumps [docker/login-action](https://github.com/docker/login-action) from 3 to 4.\n- [Release notes](https://github.com/docker/login-action/releases)\n- [Commits](https://github.com/docker/login-action/compare/v3...v4)\n\n---\nupdated-dependencies:\n- dependency-name: docker/login-action\n  dependency-versi\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump docker/login-action from 3 to 4 (#104)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-16T13:48:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0df31cb149cdd10c69a6067259361f929f5df947",
          "body": "Bumps [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) from 3 to 4.\n- [Release notes](https://github.com/docker/setup-buildx-action/releases)\n- [Commits](https://github.com/docker/setup-buildx-action/compare/v3...v4)\n\n---\nupdated-dependencies:\n- dependency-name: docker/set\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump docker/setup-buildx-action from 3 to 4 (#103)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-16T13:47:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bb12209dccced112440c2175774bec1cb55fb9ff",
          "body": null,
          "is_bot": false,
          "headline": "Bump version to v0.9.19",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-06-14T15:03:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ca219f7ea8fa51bc25aeed67d0b3502dafed6043",
          "body": "Add safe TUI restart controls",
          "is_bot": false,
          "headline": "Merge pull request #108 from lance0/feature-100-tui-restart-clean",
          "author_name": "lance",
          "author_login": "lance0",
          "committed_at": "2026-06-14T15:00:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7181039f6c757205a9951b94834c4c0037ac926f",
          "body": "Add a restartable TUI client run lifecycle so the r key and Settings -> Test Apply & Restart cancel and drain the current run before spawning a replacement.\n\nSettings restarts now apply stream count, protocol, duration, direction, and bitrate; QUIC-incompatible knobs are surfaced in the TUI history.\n[…]\nestStart/TestResult fields so all-targets clippy stays green.\n\nBased on the TUI restart/settings contribution in #101/#102 by @flotpg.\n\nCo-authored-by: Florian Obradovic <floriano@theprojectgroup.com>",
          "is_bot": false,
          "headline": "Add safe TUI restart controls",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-06-14T14:55:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "66032f98cc5b9fec31355bd270251aee7bcf41b4",
          "body": null,
          "is_bot": false,
          "headline": "Bump version to v0.9.18",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-06-11T19:35:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "29c7173a3373e37d1036f952685398c27614629c",
          "body": "PR #96 shipped without doc updates, leaving README, SCRIPTING.md,\nCOMPARISON.md, and FEATURES.md describing UDP as using ephemeral\nserver ports. All four now describe single-port UDP (with the\nfallback story for old peers and non-SO_REUSEPORT platforms).\n\nThe man page was three releases stale (0.9.14): adds --no-zerocopy,\n--probe-mtu, --connect-timeout, corrects -Z to default-on semantics,\nand documents the zerocopy_v1 / mtu_probe_v1 / single_port_udp_v1\ncapabilities.",
          "is_bot": false,
          "headline": "Docs: catch user-facing docs up to single-port UDP and recent flags",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-06-11T19:30:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4d81689b0a7ad8653477c074869ea4b7240aadd0",
          "body": "The test began failing on master after the single-port UDP merge.\nBisection plus packet captures established the mechanism:\n\nThe netem profile (50mbit FIFO, limit 10000) holds ~2.2 s of queue, so\neven a correctly-NODELAY'd control channel queues interval segments\nbehind the UDP flood, tail-drops, an\n[…]\nnd annotates the\nsampler/writer-decoupling roadmap item with the wire evidence (server\ninterval emission degrades to ~2 s because the control write blocks\nand MissedTickBehavior::Skip eats the ticks).",
          "is_bot": false,
          "headline": "Recalibrate the control-channel skew test to target collapse, not rhythm",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-06-11T19:16:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d179f195cb77a2267637febd816e114bb86469dc",
          "body": "Connect timeout, server-side client identification, CSV bidir interval\ncolumns, and tcp-nodelay propagation shipped; the QUIC parameter item\nnarrows to the remaining real fix (pacing) now that the warning half\nlanded.",
          "is_bot": false,
          "headline": "Roadmap: check off the polish batch (PRs #97-#99)",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-06-11T18:36:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8b0b0980ad1f75e6160938a6691356502663ab10",
          "body": "Propagate --tcp-nodelay to the server (wire intent, no behavior change)",
          "is_bot": false,
          "headline": "Merge pull request #99 from lance0/tcp-nodelay-propagation",
          "author_name": "lance",
          "author_login": "lance0",
          "committed_at": "2026-06-11T18:35:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d20cc3314ae610456f99069fcf1ff32b6c52da9c",
          "body": "The flag previously configured only client-created sockets; in -R and\n--bidir the server is the latency-relevant bulk sender and never heard\nabout it - the same one-direction asymmetry issues #81/#91 had for\naccounting.\n\nTestStart gains a wire-additive tcp_nodelay field (serde-default,\nomitted when \n[…]\noncept), and UDP tests send false\nlike zerocopy does.\n\nThe legacy dead-code multi-port handler now references the shared\nSERVER_DATA_NODELAY constant so the historical default has one source\nof truth.",
          "is_bot": false,
          "headline": "Propagate --tcp-nodelay to the server via TestStart",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-06-11T18:34:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c7018de743cbf682fc969bc6280d4a93557f94b3",
          "body": "Add per-direction split columns to CSV interval output",
          "is_bot": false,
          "headline": "Merge pull request #98 from lance0/csv-bidir-columns",
          "author_name": "lance",
          "author_login": "lance0",
          "committed_at": "2026-06-11T18:33:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1e98e8d5dcc51a1cbb0e96adbd203ad68071da42",
          "body": "Connect timeout, QUIC ignored-flag warnings, client hello logging",
          "is_bot": false,
          "headline": "Merge pull request #97 from lance0/quic-warnings-and-hello-logging",
          "author_name": "lance",
          "author_login": "lance0",
          "committed_at": "2026-06-11T18:32:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a7ef5c1fe9903e74089ee28214cdd97b4f23b7a4",
          "body": "Three small honesty fixes from the roadmap surface audit:\n\n--connect-timeout bounds control-connection establishment (TCP connect\nor QUIC handshake) with a clear error naming the flag. Off by default;\nwithout it a dead or filtered server is bounded only by OS defaults,\nwhich can be minutes — the fai\n[…]\nre (the features that will silently fall back that session). The\nbare 'Client connected: <addr>' line is replaced by the richer one in\nthe Hello handler; QUIC control connections get the same logging.",
          "is_bot": false,
          "headline": "Add --connect-timeout, QUIC ignored-flag warnings, client hello logging",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-06-11T18:27:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fd9a2a70b697818980fe71a35fe7734216f5b9ab",
          "body": "Bidirectional tests already expose bytes_sent/bytes_received/\nthroughput_send_mbps/throughput_recv_mbps in final JSON, the live\nAggregateInterval, and the CSV summary row -- but CSV interval rows\nonly carried the combined number, so scripted bidir consumers could\nnot see the split at all.\n\nAppend th\n[…]\nry row's existing behavior for these fields.\n\nDocs: update the SCRIPTING.md CSV section, which was also stale on\nthe summary header (missing the four columns added by #56). Mark the\nROADMAP item done.",
          "is_bot": false,
          "headline": "Add per-direction split columns to CSV interval output (#56 family)",
          "author_name": "Lance Tuller",
          "author_login": "lance0",
          "committed_at": "2026-06-11T18:24:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "687d27ff3daed3fa7b0175dc66377ccd3ec0e8a5",
          "body": "Single-port UDP data plane (single_port_udp_v1)",
          "is_bot": false,
          "headline": "Merge pull request #96 from lance0/feature-63-single-port-udp",
          "author_name": "lance",
          "author_login": "lance0",
          "committed_at": "2026-06-11T18:17:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 29,
      "commits_last_year": 459,
      "latest_release_at": "2026-07-06T19:56:57Z",
      "latest_release_tag": "v0.9.21",
      "releases_from_tags": false,
      "days_since_last_push": 4,
      "active_weeks_last_year": 18,
      "days_since_latest_release": 16,
      "mean_days_between_releases": 7.5
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 71,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "xfr",
          "exists": true,
          "license": "MIT OR Apache-2.0",
          "keywords": [
            "network",
            "tui",
            "benchmark",
            "bandwidth",
            "iperf",
            "command-line-utilities",
            "network-programming"
          ],
          "ecosystem": "crates",
          "matches_repo": true,
          "registry_url": "https://crates.io/crates/xfr",
          "is_deprecated": false,
          "latest_version": "0.9.21",
          "repository_url": "https://github.com/lance0/xfr",
          "versions_count": 34,
          "total_downloads": 1328,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 179,
          "first_published_at": "2026-02-01T00:06:23.250314Z",
          "latest_published_at": "2026-07-06T19:58:56.205456Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 16
        }
      ]
    },
    "popularity": {
      "forks": 21,
      "stars": 517,
      "watchers": 2,
      "fork_history": {
        "days": [
          {
            "date": "2026-02-04",
            "count": 6
          },
          {
            "date": "2026-02-06",
            "count": 1
          },
          {
            "date": "2026-02-07",
            "count": 2
          },
          {
            "date": "2026-02-11",
            "count": 1
          },
          {
            "date": "2026-02-27",
            "count": 1
          },
          {
            "date": "2026-03-11",
            "count": 1
          },
          {
            "date": "2026-03-15",
            "count": 1
          },
          {
            "date": "2026-04-21",
            "count": 2
          },
          {
            "date": "2026-04-24",
            "count": 1
          },
          {
            "date": "2026-05-05",
            "count": 1
          },
          {
            "date": "2026-05-07",
            "count": 1
          },
          {
            "date": "2026-05-12",
            "count": 1
          },
          {
            "date": "2026-06-13",
            "count": 1
          },
          {
            "date": "2026-06-30",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 21,
        "total_forks": 21
      },
      "star_history": null,
      "open_issues_and_prs": 4
    },
    "ai_readiness": {
      "has_nix": true,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "Cargo.toml"
      ],
      "largest_source_bytes": 154793,
      "source_files_sampled": 40,
      "oversized_source_files": 8,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "Cargo.toml"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "crates"
      ],
      "dependencies": [
        {
          "name": "tokio",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "futures",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.3"
        },
        {
          "name": "ratatui",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.30"
        },
        {
          "name": "crossterm",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.29"
        },
        {
          "name": "clap",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "4"
        },
        {
          "name": "clap_complete",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "4.6"
        },
        {
          "name": "serde",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "serde_json",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "prometheus",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.14"
        },
        {
          "name": "hyper",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "hyper-util",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.1"
        },
        {
          "name": "http-body-util",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.1"
        },
        {
          "name": "mdns-sd",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.20"
        },
        {
          "name": "toml",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.1"
        },
        {
          "name": "dirs",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "6"
        },
        {
          "name": "async-trait",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.1"
        },
        {
          "name": "anyhow",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "tracing",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.1"
        },
        {
          "name": "tracing-subscriber",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.3"
        },
        {
          "name": "tracing-appender",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.2"
        },
        {
          "name": "parking_lot",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.12"
        },
        {
          "name": "humantime",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "2"
        },
        {
          "name": "uuid",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "hostname",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4"
        },
        {
          "name": "once_cell",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "chrono",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4"
        },
        {
          "name": "reqwest",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.12"
        },
        {
          "name": "quinn",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.11"
        },
        {
          "name": "rustls",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.23"
        },
        {
          "name": "rcgen",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.14"
        },
        {
          "name": "hmac",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.13"
        },
        {
          "name": "sha2",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.11"
        },
        {
          "name": "rand",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.10"
        },
        {
          "name": "sha2_010",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.10"
        },
        {
          "name": "hmac_012",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.12"
        },
        {
          "name": "chacha20poly1305",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.10"
        },
        {
          "name": "hkdf",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.12"
        },
        {
          "name": "dashmap",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "6"
        },
        {
          "name": "ipnetwork",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.21"
        },
        {
          "name": "update-informer",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "socket2",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.6"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 1,
        "merged_prs": 77,
        "open_issues": 3,
        "closed_ratio": 0.93,
        "closed_issues": 40,
        "closed_unmerged_prs": 24
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "lance0",
          "commits": 438,
          "avatar_url": "https://avatars.githubusercontent.com/u/3323861?v=4"
        },
        {
          "type": "User",
          "login": "deephack1982",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/6213936?v=4"
        },
        {
          "type": "User",
          "login": "matttbe",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/768677?v=4"
        }
      ],
      "contributors_sampled": 3,
      "top_contributor_share": 0.993
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "audit.yml",
        "ci.yml",
        "release.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": true
    },
    "security_signals": {
      "lockfiles": [
        "Cargo.lock"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "9 out of 9 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/15 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 9,
            "reason": "1 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "ec39ea55ae7e0fc08984ddcedc9fc1827683ad37",
        "ran_at": "2026-07-23T11:43:12Z",
        "aggregate_score": 5.2,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-23T02:12:10Z",
      "oldest_open_prs": [
        {
          "number": 144,
          "created_at": "2026-07-19T05:56:37Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-09T20:35:03Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 33,
          "created_at": "2026-03-05T18:43:26Z",
          "last_comment_at": "2026-06-11T15:23:04Z",
          "last_comment_author": "lance0"
        },
        {
          "number": 142,
          "created_at": "2026-07-14T20:52:23Z",
          "last_comment_at": "2026-07-23T02:28:26Z",
          "last_comment_author": "lance0"
        },
        {
          "number": 143,
          "created_at": "2026-07-15T15:07:00Z",
          "last_comment_at": "2026-07-23T02:27:48Z",
          "last_comment_author": "lance0"
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/lance0/xfr",
    "host": "github.com",
    "name": "xfr",
    "owner": "lance0"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 68,
      "inputs": {
        "security": 52,
        "vitality": 82,
        "community": 56,
        "governance": 58,
        "engineering": 90
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 82,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 76,
            "inputs": {
              "commits_last_year": 459,
              "human_commit_share": 0.92,
              "days_since_last_push": 4,
              "active_weeks_last_year": 18
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 4 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 4
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "18/52 weeks with commits",
                "points": 12.5,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 18
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "459 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 459
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 29,
              "latest_release_tag": "v0.9.21",
              "releases_from_tags": false,
              "days_since_latest_release": 16,
              "mean_days_between_releases": 7.5
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "29 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 29
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 16 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 16
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~7.5 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 7.5
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 56,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "moderate",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 55,
            "inputs": {
              "forks": 21,
              "stars": 517,
              "watchers": 2,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "517 stars",
                "points": 44,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 517
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "21 forks",
                "points": 10.8,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 21
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "2 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "good",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 70,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "at_risk",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 38,
            "inputs": {
              "packages": [
                "xfr"
              ],
              "dependents": null,
              "ecosystems": "crates",
              "total_downloads": 1328,
              "monthly_downloads": 179
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "179 downloads/month across crates",
                "points": 30.1,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 179,
                      "ecosystems": "crates"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 58,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 13,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 3,
              "top_contributor_share": 0.993
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 99% of commits",
                "points": 0.2,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 99
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "3 contributors",
                "points": 4.1,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 73,
            "inputs": {
              "merged_prs": 77,
              "open_issues": 3,
              "closed_issues": 40,
              "issue_closed_ratio": 0.93,
              "closed_unmerged_prs": 24
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "93% of issues closed",
                "points": 43.5,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 93
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "77/101 decided PRs merged",
                "points": 29.2,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 77,
                      "decided": 101
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/15 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 62,
            "inputs": {
              "followers": 115,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "lance0",
              "public_repos": 61,
              "account_age_days": 4931
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "115 followers of lance0",
                "points": 14.8,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 115,
                      "login": "lance0"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "61 public repos, account ~13 yr old",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 61
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 13
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "xfr"
              ],
              "ecosystems": "crates",
              "any_deprecated": false,
              "min_days_since_publish": 16
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on crates",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "crates"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 16 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 16
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "34 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 34
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "excellent",
        "name": "Engineering Quality",
        "value": 90,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "excellent",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 94,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": true
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "3 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 16,
                "status": "met",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 9.6,
                "status": "met",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "9 out of 9 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "topics": [
                "bandwidth",
                "benchmark",
                "cli",
                "iperf",
                "network",
                "rust",
                "tui"
              ],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "7 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 52,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": null,
            "notes": [],
            "value": 52,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 18,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 0,
              "scorecard_aggregate": 5.2
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "9 out of 9 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/15 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "1 existing vulnerabilities detected",
                "points": 6.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 4
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 61,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.957,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "88 of 92 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 88,
                      "sampled": 92
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "has_nix": true,
              "has_tests": true,
              "lockfiles": [
                "Cargo.lock"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "Cargo.toml"
              ],
              "dependency_bot_commit_share": 0.08
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Cargo.toml (toolchain convention, no task runner)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "toolchain_convention",
                    "params": {
                      "files": "Cargo.toml"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 11,
                "status": "met",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Rust (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Rust"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, Nix, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, Nix, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "8 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 8,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 89,
            "inputs": {
              "primary_language": "Rust",
              "largest_source_bytes": 154793,
              "source_files_sampled": 40,
              "oversized_source_files": 8
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Rust (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Rust"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "8/40 source files over 60KB",
                "points": 44,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 40,
                      "oversized": 8
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-23T11:43:29.300914Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/l/lance0/xfr.svg",
  "full_name": "lance0/xfr",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticscrates.io.