Public record
Software health reportschema 0.27.0 · metrics 1.13.0 · 2026-07-25 13:14 UTC

meteora-pro / devboy-tools

Configurable tool bundle for AI coding agents — use via MCP server, CLI, or agent skills. npm wrapper for the Rust binary.

RustApache-2.0★ 13 stars⑂ 4 forkssince Jan 2026View on GitHub ↗

meteora-pro/devboy-tools holds a health index of 31 out of 100, placing it in the At risk band. It scores highest on Engineering Quality (86/100) and lowest on Security (18/100). It was last updated today. A single contributor accounts for most of its recent work.

31
overall / 100
At risk

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

31
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

High-Risk Jurisdiction Policy applies a 50% multiplier to weighted overall health and gives it an At risk ceiling of 49.

Ownership

Meteora ProOrganization
4 followers9 public repossince Oct 2020

This repository is backed by an organization — shared, accountable stewardship that can outlive any single maintainer.

Package ecosystems

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

83Good · 22% of overall
How it's scored
36/36Push recency — last push 0 days ago
15.2/36Commit cadence — 22/52 weeks with commits
18/18Commit volume — 1,798 commits in the last year
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 21 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year1,798
human_commit_share1
days_since_last_push0
active_weeks_last_year22
How it's scored
27/27Ships releases — 39 releases published
36/36Release recency — latest release 0 days ago
27/27Release cadence — a release every ~9.1 days
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Inputs used
releases_count39
latest_release_tagv0.32.0
releases_from_tagsno
days_since_latest_release0
mean_days_between_releases9.1

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

49At risk · 18% of overall
How it's scored
17.5/60Stars — 13 stars
4/25Forks — 4 forks
0/15Watchers — 0 watchers
Inputs used
forks4
stars13
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (Apache-2.0)
18/18CONTRIBUTING guide
0/13.5Code of conduct
0/7.2Issue template
0/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingyes
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno
How it's scored
49.5/80Monthly downloads — 5,114 downloads/month across crates, npm
0/20Registry dependents — not reported by this ecosystem
Inputs used
packagesdevboy-cli, devboy-mcp, devboy-core, @devboy-tools/cli, devboy-assets, devboy-skills, devboy-storage
dependents
ecosystemscrates, npm
total_downloads14,036
monthly_downloads5,114
Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

60Moderate · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
8.9/22.5Commit distribution — top contributor authored 60% of commits
9.5/13.5Contributor breadth — 7 contributors
6/10OpenSSF Scorecard: Contributors — project has 2 contributing companies or organizations -- score normalized to 6
Inputs used
bus_factor1
contributors_sampled7
top_contributor_share0.605
How it's scored
34.1/46.8Issue resolution — 73% of issues closed
34.1/38.3PR acceptance — 123/138 decided PRs merged
0/15OpenSSF Scorecard: Code-Review — Found 0/5 approved changesets -- score normalized to 0
Inputs used
merged_prs123
open_issues45
closed_issues121
issue_closed_ratio0.729
closed_unmerged_prs15
How it's scored
30/30Ownership backing — organization-owned
0/20Verified domain
5/25Owner reach — 4 followers of meteora-pro
18.9/25Track record — 9 public repos, account ~5 yr old
Inputs used
followers4
owner_typeOrganization
is_verified
owner_loginmeteora-pro
public_repos9
account_age_days2,118
How it's scored
25/25Published & resolvable — 7 package(s) on crates, npm
35/35Publish recency — latest publish 0 days ago
20/20Version history — 39 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packagesdevboy-cli, devboy-mcp, devboy-core, @devboy-tools/cli, devboy-assets, devboy-skills, devboy-storage
ecosystemscrates, npm
any_deprecatedno
min_days_since_publish0

Engineering Quality

Are baseline engineering and documentation practices in place?

86Excellent · 20% of overall
How it's scored
24/24CI workflows — 5 workflow(s)
24/24Tests present
16/16Linter config — biome.json
0/9.6Pre-commit hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 5 out of 5 merged PRs checked by a CI test -- score normalized to 10
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configyes
has_precommit_configno

Documentation

90Excellent
How it's scored
30/30README
25/25Documentation directory
15/15Documentation / homepage site — https://meteora-pro.github.io/devboy-tools/
10/10Repository description
0/10Topics
10/10Wiki
Inputs used
topics
has_wikiyes
homepagehttps://meteora-pro.github.io/devboy-tools/
has_readmeyes
has_docs_diryes
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

18Critical · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
2.5/2.5CI-Tests — 5 out of 5 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/5 approved changesets -- score normalized to 0
1.5/2.5Contributors — project has 2 contributing companies or organizations -- score normalized to 6
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
7.5/7.5Maintained — 30 commit(s) and 21 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 21 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated18
scorecard_versionv5.5.0
checks_inconclusive0
scorecard_aggregate3.5
high_risk_jurisdiction_cap49
high_risk_jurisdiction_multiplier50
security_posture_after_multiplier18
security_posture_before_jurisdiction35
High-Risk Jurisdiction Policy applies a 50% multiplier and gives Security posture an At risk ceiling of 49.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

68Moderate · 0% of overall
How it's scored
0/45Agent instructions — no CLAUDE.md / AGENTS.md / editor rules
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 96 of 100 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share0.96
agent_instruction_files
agent_instruction_max_bytes
How it's scored
18/18One-command bootstrap — docs/research/paper1-repro/Makefile
22/22Automated tests
11/11Lint / format config — biome.json
11/11Static type checking — docs/tsconfig.json
10/10Reproducible environment — devcontainer, Dockerfile, lockfile
10/10Demonstrated agent practice — 61 of the last 100 commits agent-authored or agent-credited
0/8Automated maintenance — no automated dependency updates observed
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Inputs used
has_nixno
has_testsyes
lockfilespnpm-lock.yaml
has_dockerfileyes
typed_languageyes
bootstrap_filesdocs/research/paper1-repro/Makefile
has_devcontaineryes
has_linter_configyes
typecheck_configsdocs/tsconfig.json
agent_commit_share0.61
toolchain_manifestsCargo.toml, crates/devboy-assets/Cargo.toml, crates/devboy-cli/Cargo.toml, crates/devboy-core/Cargo.toml, crates/devboy-executor/Cargo.toml, crates/devboy-mcp/Cargo.toml, crates/devboy-secret-patterns/Cargo.toml, crates/devboy-secrets-agent/Cargo.toml, crates/devboy-secrets-ui-bin/Cargo.toml, crates/devboy-secrets-ui/Cargo.toml, crates/devboy-skills/Cargo.toml, crates/devboy-storage/Cargo.toml, crates/devboy-token-catalog/Cargo.toml, crates/devboy-vault-crypto/Cargo.toml, crates/llm-eval/Cargo.toml, crates/plugins/api/clickup/Cargo.toml, crates/plugins/api/confluence/Cargo.toml, crates/plugins/api/fireflies/Cargo.toml, crates/plugins/api/github/Cargo.toml, crates/plugins/api/gitlab/Cargo.toml, crates/plugins/api/jira/Cargo.toml, crates/plugins/api/slack/Cargo.toml, crates/plugins/api/telegram/Cargo.toml, crates/plugins/format-pipeline/Cargo.toml, crates/plugins/secrets/1password/Cargo.toml, crates/plugins/secrets/env-store/Cargo.toml, crates/plugins/secrets/kdbx/Cargo.toml, crates/plugins/secrets/keychain/Cargo.toml, crates/plugins/secrets/local-vault/Cargo.toml, crates/plugins/secrets/vault/Cargo.toml
dependency_bot_commit_share0
How it's scored
45/45Type-checkable code — Rust (statically typed)
51.3/55Manageable file sizes — 22/329 source files over 60KB
Inputs used
primary_languageRust
largest_source_bytes381,128
source_files_sampled329
oversized_source_files22
How it's scored
0/40API schema (OpenAPI/GraphQL/proto)
20/20MCP server
40/40Runnable examples — examples, notebooks
Inputs used
example_dirsexamples, notebooks
has_mcp_signalyes
api_schema_files

Key facts

13GitHub stars
7contributors
1,798commits, last 12 months
0days since last push
39releases
1bus factor
45open issues
crates.io, npmpackage ecosystems

Data collection warnings

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • Could not fetch crates package 'llm-eval' from its registry
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

More detail

Star and fork history 0 ★ / 4 ⇿
0Stars
4Forks
36Releases

When each star and fork was added, collected from GitHub and bucketed by day. Cumulative growth sits directly above the daily additions it is made of, so the two read against each other: steady organic accretion looks nothing like an abrupt, short-lived burst. Where that difference is measurable, it is reported as growth authenticity.

1223344412026-022026-042026-06
Major 0Minor 29Patch 7
OpenSSF Scorecard 3.5 / 10
3.5aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-25 13:14 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
10CI-Tests5 out of 5 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/5 approved changesets -- score normalized to 0
6Contributorsproject has 2 contributing companies or organizations -- score normalized to 6
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 21 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities21 existing vulnerabilities detected
Direct dependencies 198
RegistryPackageVersion constraintManifest
crates.iodevboy-corecrates/devboy-assets/Cargo.toml
crates.iothiserrorcrates/devboy-assets/Cargo.toml
crates.ioserdecrates/devboy-assets/Cargo.toml
crates.ioserde_jsoncrates/devboy-assets/Cargo.toml
crates.iotracingcrates/devboy-assets/Cargo.toml
crates.iotomlcrates/devboy-assets/Cargo.toml
crates.iodirscrates/devboy-assets/Cargo.toml
crates.iosha2crates/devboy-assets/Cargo.toml
crates.iotempfilecrates/devboy-assets/Cargo.toml
crates.iodevboy-corecrates/devboy-cli/Cargo.toml
crates.iodevboy-executorcrates/devboy-cli/Cargo.toml
crates.iodevboy-mcpcrates/devboy-cli/Cargo.toml
crates.iodevboy-storagecrates/devboy-cli/Cargo.toml
crates.iodevboy-secret-patternscrates/devboy-cli/Cargo.toml
crates.iodevboy-secrets-agentcrates/devboy-cli/Cargo.toml
crates.iodevboy-secrets-uicrates/devboy-cli/Cargo.toml
crates.iodevboy-token-catalogcrates/devboy-cli/Cargo.toml
crates.ioregexcrates/devboy-cli/Cargo.toml
crates.ioratatui0.30crates/devboy-cli/Cargo.toml
crates.iocrossterm0.28crates/devboy-cli/Cargo.toml
crates.iodevboy-secret-keychaincrates/devboy-cli/Cargo.toml
crates.iodevboy-secret-local-vaultcrates/devboy-cli/Cargo.toml
crates.iodevboy-secret-1passwordcrates/devboy-cli/Cargo.toml
crates.iodevboy-secret-kdbxcrates/devboy-cli/Cargo.toml
crates.iodevboy-secret-env-storecrates/devboy-cli/Cargo.toml
crates.iodevboy-githubcrates/devboy-cli/Cargo.toml
crates.iodevboy-gitlabcrates/devboy-cli/Cargo.toml
crates.iodevboy-clickupcrates/devboy-cli/Cargo.toml
crates.iodevboy-jiracrates/devboy-cli/Cargo.toml
crates.iodevboy-confluencecrates/devboy-cli/Cargo.toml
crates.iodevboy-firefliescrates/devboy-cli/Cargo.toml
crates.iodevboy-slackcrates/devboy-cli/Cargo.toml
crates.iodevboy-telegramcrates/devboy-cli/Cargo.toml
crates.iodevboy-format-pipelinecrates/devboy-cli/Cargo.toml
crates.iodevboy-skillscrates/devboy-cli/Cargo.toml
crates.ioserde_yaml0.9crates/devboy-cli/Cargo.toml
crates.iotokiocrates/devboy-cli/Cargo.toml
crates.ioserdecrates/devboy-cli/Cargo.toml
crates.ioserde_jsoncrates/devboy-cli/Cargo.toml
crates.ioclapcrates/devboy-cli/Cargo.toml
crates.ioclap-markdown0.1crates/devboy-cli/Cargo.toml
crates.iotracingcrates/devboy-cli/Cargo.toml
crates.iotracing-subscribercrates/devboy-cli/Cargo.toml
crates.ioanyhowcrates/devboy-cli/Cargo.toml
crates.ioasync-traitcrates/devboy-cli/Cargo.toml
crates.iofuturescrates/devboy-cli/Cargo.toml
crates.ioreqwestcrates/devboy-cli/Cargo.toml
crates.iodialoguer0.11crates/devboy-cli/Cargo.toml
crates.iochrono0.4crates/devboy-cli/Cargo.toml
crates.iotomlcrates/devboy-cli/Cargo.toml
crates.iodirscrates/devboy-cli/Cargo.toml
crates.ioflate21.1crates/devboy-cli/Cargo.toml
crates.iotar0.4crates/devboy-cli/Cargo.toml
crates.iozip8.4crates/devboy-cli/Cargo.toml
crates.iosecrecycrates/devboy-cli/Cargo.toml
crates.iosentrycrates/devboy-cli/Cargo.toml
crates.iosentry-tracingcrates/devboy-cli/Cargo.toml
crates.iothiserrorcrates/devboy-core/Cargo.toml
crates.ioanyhowcrates/devboy-core/Cargo.toml
crates.ioserdecrates/devboy-core/Cargo.toml
crates.ioserde_jsoncrates/devboy-core/Cargo.toml
crates.ioasync-traitcrates/devboy-core/Cargo.toml
crates.iotracingcrates/devboy-core/Cargo.toml
crates.iotomlcrates/devboy-core/Cargo.toml
crates.iodirscrates/devboy-core/Cargo.toml
crates.ioreqwestcrates/devboy-core/Cargo.toml
crates.iourlcrates/devboy-core/Cargo.toml
crates.iosecrecycrates/devboy-core/Cargo.toml
crates.iosentrycrates/devboy-core/Cargo.toml
crates.iochrono0.4crates/devboy-core/Cargo.toml
crates.iowhich8.0crates/devboy-core/Cargo.toml
crates.iodevboy-corecrates/devboy-executor/Cargo.toml
crates.iodevboy-assetscrates/devboy-executor/Cargo.toml
crates.iodevboy-gitlabcrates/devboy-executor/Cargo.toml
crates.iodevboy-githubcrates/devboy-executor/Cargo.toml
crates.iodevboy-clickupcrates/devboy-executor/Cargo.toml
crates.iodevboy-jiracrates/devboy-executor/Cargo.toml
crates.iodevboy-confluencecrates/devboy-executor/Cargo.toml
crates.iodevboy-firefliescrates/devboy-executor/Cargo.toml
crates.iodevboy-slackcrates/devboy-executor/Cargo.toml
crates.iodevboy-telegramcrates/devboy-executor/Cargo.toml
crates.iodevboy-format-pipelinecrates/devboy-executor/Cargo.toml
crates.iotokiocrates/devboy-executor/Cargo.toml
crates.ioserdecrates/devboy-executor/Cargo.toml
crates.ioserde_jsoncrates/devboy-executor/Cargo.toml
crates.ioasync-traitcrates/devboy-executor/Cargo.toml
crates.iotracingcrates/devboy-executor/Cargo.toml
crates.iothiserrorcrates/devboy-executor/Cargo.toml
crates.iobase640.22crates/devboy-executor/Cargo.toml
crates.iosecrecycrates/devboy-executor/Cargo.toml
crates.iodevboy-corecrates/devboy-mcp/Cargo.toml
crates.iodevboy-assetscrates/devboy-mcp/Cargo.toml
crates.iodevboy-executorcrates/devboy-mcp/Cargo.toml
crates.iodevboy-confluencecrates/devboy-mcp/Cargo.toml
crates.iodevboy-format-pipelinecrates/devboy-mcp/Cargo.toml
crates.iodevboy-storagecrates/devboy-mcp/Cargo.toml
crates.iodevboy-secret-kdbxcrates/devboy-mcp/Cargo.toml
crates.iochrono0.4crates/devboy-mcp/Cargo.toml
crates.iotokiocrates/devboy-mcp/Cargo.toml
crates.ioserdecrates/devboy-mcp/Cargo.toml
crates.ioserde_jsoncrates/devboy-mcp/Cargo.toml
crates.iotracingcrates/devboy-mcp/Cargo.toml
crates.ioreqwestcrates/devboy-mcp/Cargo.toml
crates.ioreqwest-eventsourcecrates/devboy-mcp/Cargo.toml
crates.iofuturescrates/devboy-mcp/Cargo.toml
crates.iotokio-util0.7crates/devboy-mcp/Cargo.toml
crates.ioasync-traitcrates/devboy-mcp/Cargo.toml
crates.iothiserrorcrates/devboy-mcp/Cargo.toml
crates.iosecrecycrates/devboy-mcp/Cargo.toml
crates.iothiserrorcrates/devboy-secret-patterns/Cargo.toml
crates.ioserdecrates/devboy-secret-patterns/Cargo.toml
crates.iotomlcrates/devboy-secret-patterns/Cargo.toml
crates.ioregexcrates/devboy-secret-patterns/Cargo.toml
crates.iotracingcrates/devboy-secret-patterns/Cargo.toml
crates.iodevboy-vault-cryptocrates/devboy-secrets-agent/Cargo.toml
crates.iothiserrorcrates/devboy-secrets-agent/Cargo.toml
crates.ioserdecrates/devboy-secrets-agent/Cargo.toml
crates.ioserde_jsoncrates/devboy-secrets-agent/Cargo.toml
crates.iotokiocrates/devboy-secrets-agent/Cargo.toml
crates.iotracingcrates/devboy-secrets-agent/Cargo.toml
crates.iosecrecycrates/devboy-secrets-agent/Cargo.toml
crates.iodirscrates/devboy-secrets-agent/Cargo.toml
crates.iodevboy-secrets-uicrates/devboy-secrets-ui-bin/Cargo.toml
crates.iodevboy-storagecrates/devboy-secrets-ui-bin/Cargo.toml
crates.iodevboy-token-catalogcrates/devboy-secrets-ui-bin/Cargo.toml
crates.iodevboy-vault-cryptocrates/devboy-secrets-ui-bin/Cargo.toml
crates.iodevboy-secret-patternscrates/devboy-secrets-ui-bin/Cargo.toml
crates.iodevboy-secret-vaultcrates/devboy-secrets-ui-bin/Cargo.toml
crates.iodevboy-secret-kdbxcrates/devboy-secrets-ui-bin/Cargo.toml
crates.ioeframe0.34crates/devboy-secrets-ui-bin/Cargo.toml
crates.ioegui_kittest0.34.2crates/devboy-secrets-ui-bin/Cargo.toml
crates.ioimage0.25crates/devboy-secrets-ui-bin/Cargo.toml
crates.ioanyhowcrates/devboy-secrets-ui-bin/Cargo.toml
crates.ioclapcrates/devboy-secrets-ui-bin/Cargo.toml
crates.iosecrecycrates/devboy-secrets-ui-bin/Cargo.toml
crates.ioregexcrates/devboy-secrets-ui-bin/Cargo.toml
crates.ioreqwestcrates/devboy-secrets-ui-bin/Cargo.toml
crates.iodirscrates/devboy-secrets-ui-bin/Cargo.toml
crates.iotomlcrates/devboy-secrets-ui-bin/Cargo.toml
crates.iorfd0.15crates/devboy-secrets-ui-bin/Cargo.toml
crates.iosecrecycrates/devboy-secrets-ui/Cargo.toml
crates.iochrono0.4crates/devboy-secrets-ui/Cargo.toml
crates.ioratatui0.30crates/devboy-secrets-ui/Cargo.toml
crates.iocrossterm0.28crates/devboy-secrets-ui/Cargo.toml
crates.ioegui0.34crates/devboy-secrets-ui/Cargo.toml
crates.iothiserrorcrates/devboy-skills/Cargo.toml
crates.ioserdecrates/devboy-skills/Cargo.toml
crates.ioserde_jsoncrates/devboy-skills/Cargo.toml
crates.ioasync-traitcrates/devboy-skills/Cargo.toml
crates.iodirscrates/devboy-skills/Cargo.toml
crates.iosha2crates/devboy-skills/Cargo.toml
crates.ioserde_yaml0.9crates/devboy-skills/Cargo.toml
crates.iorust-embed8.5crates/devboy-skills/Cargo.toml
crates.iochrono0.4crates/devboy-skills/Cargo.toml
crates.ioulid1.1crates/devboy-skills/Cargo.toml
crates.iodevboy-corecrates/devboy-storage/Cargo.toml
crates.iodevboy-secret-patternscrates/devboy-storage/Cargo.toml
crates.iothiserrorcrates/devboy-storage/Cargo.toml
crates.ioserdecrates/devboy-storage/Cargo.toml
crates.ioserde_jsoncrates/devboy-storage/Cargo.toml
crates.iotomlcrates/devboy-storage/Cargo.toml
crates.iotracingcrates/devboy-storage/Cargo.toml
crates.iodirscrates/devboy-storage/Cargo.toml
crates.iosecrecycrates/devboy-storage/Cargo.toml
crates.ioasync-traitcrates/devboy-storage/Cargo.toml
crates.iobitflags2.6crates/devboy-storage/Cargo.toml
crates.ioregexcrates/devboy-storage/Cargo.toml
crates.iochrono0.4crates/devboy-storage/Cargo.toml
crates.iosha2crates/devboy-storage/Cargo.toml
crates.iohex0.4crates/devboy-storage/Cargo.toml
crates.iotokiocrates/devboy-storage/Cargo.toml
crates.ioserdecrates/devboy-token-catalog/Cargo.toml
crates.ioserde_jsoncrates/devboy-token-catalog/Cargo.toml
crates.iothiserrorcrates/devboy-token-catalog/Cargo.toml
crates.iodirscrates/devboy-token-catalog/Cargo.toml
crates.iotomlcrates/devboy-token-catalog/Cargo.toml
crates.ioreqwestcrates/devboy-token-catalog/Cargo.toml
crates.iosha2crates/devboy-token-catalog/Cargo.toml
crates.iochrono0.4crates/devboy-token-catalog/Cargo.toml
crates.iorust-embed8crates/devboy-token-catalog/Cargo.toml
crates.iothiserrorcrates/devboy-vault-crypto/Cargo.toml
crates.ioserdecrates/devboy-vault-crypto/Cargo.toml
crates.iosecrecycrates/devboy-vault-crypto/Cargo.toml
crates.iozeroize1.8crates/devboy-vault-crypto/Cargo.toml
crates.iotomlcrates/devboy-vault-crypto/Cargo.toml
crates.iobase64crates/devboy-vault-crypto/Cargo.toml
crates.iotempfilecrates/devboy-vault-crypto/Cargo.toml
crates.iochacha20poly1305crates/devboy-vault-crypto/Cargo.toml
crates.iogetrandomcrates/devboy-vault-crypto/Cargo.toml
crates.ioargon2crates/devboy-vault-crypto/Cargo.toml
crates.iobip39crates/devboy-vault-crypto/Cargo.toml
crates.iohkdfcrates/devboy-vault-crypto/Cargo.toml
crates.iosha2crates/devboy-vault-crypto/Cargo.toml
crates.iodevboy-format-pipelinecrates/llm-eval/Cargo.toml
crates.ioanyhowcrates/llm-eval/Cargo.toml
crates.ioserde_jsoncrates/llm-eval/Cargo.toml
crates.ioreqwestcrates/llm-eval/Cargo.toml
crates.iosecrecycrates/llm-eval/Cargo.toml
All dependencies not collected

The resolved dependency set could not be collected for this report: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 20179,
      "has_wiki": true,
      "homepage": "https://meteora-pro.github.io/devboy-tools/",
      "languages": {
        "Rust": 6328763,
        "Shell": 23652,
        "Python": 206422,
        "Dockerfile": 1042,
        "JavaScript": 2655
      },
      "pushed_at": "2026-07-25T12:02:50Z",
      "created_at": "2026-01-26T02:26:36Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-25T12:02:53Z",
      "description": "Configurable tool bundle for AI coding agents — use via MCP server, CLI, or agent skills. npm wrapper for the Rust binary.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Rust",
      "significant_languages": [
        "Rust"
      ]
    },
    "owner": {
      "blog": "https://meteora.pro",
      "name": "Meteora Pro",
      "type": "Organization",
      "login": "meteora-pro",
      "company": null,
      "location": null,
      "followers": 4,
      "avatar_url": "https://avatars.githubusercontent.com/u/72404657?v=4",
      "created_at": "2020-10-05T16:16:24Z",
      "is_verified": null,
      "public_repos": 9,
      "account_age_days": 2118
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.32.0",
          "kind": "minor",
          "published_at": "2026-07-25T12:01:23Z"
        },
        {
          "tag": "v0.31.1",
          "kind": "patch",
          "published_at": "2026-07-01T06:46:06Z"
        },
        {
          "tag": "v0.31.0",
          "kind": "minor",
          "published_at": "2026-06-09T16:31:36Z"
        },
        {
          "tag": "v0.30.1",
          "kind": "patch",
          "published_at": "2026-05-27T18:49:30Z"
        },
        {
          "tag": "v0.29.2",
          "kind": "patch",
          "published_at": "2026-05-26T18:55:00Z"
        },
        {
          "tag": "v0.29.0",
          "kind": "minor",
          "published_at": "2026-05-19T08:00:39Z"
        },
        {
          "tag": "v0.28.1",
          "kind": "patch",
          "published_at": "2026-05-17T19:39:06Z"
        },
        {
          "tag": "v0.28.0",
          "kind": "minor",
          "published_at": "2026-05-10T20:49:18Z"
        },
        {
          "tag": "v0.27.0",
          "kind": "minor",
          "published_at": "2026-05-09T21:42:01Z"
        },
        {
          "tag": "v0.26.0",
          "kind": "minor",
          "published_at": "2026-05-04T16:14:32Z"
        },
        {
          "tag": "v0.25.0",
          "kind": "minor",
          "published_at": "2026-05-02T20:43:42Z"
        },
        {
          "tag": "v0.24.0",
          "kind": "minor",
          "published_at": "2026-05-02T09:51:23Z"
        },
        {
          "tag": "v0.23.0",
          "kind": "minor",
          "published_at": "2026-05-01T19:36:43Z"
        },
        {
          "tag": "v0.22.0",
          "kind": "minor",
          "published_at": "2026-04-29T22:41:23Z"
        },
        {
          "tag": "v0.21.2",
          "kind": "patch",
          "published_at": "2026-04-25T15:54:28Z"
        },
        {
          "tag": "v0.21.1",
          "kind": "patch",
          "published_at": "2026-04-25T13:16:14Z"
        },
        {
          "tag": "v0.21.0",
          "kind": "minor",
          "published_at": "2026-04-25T12:59:30Z"
        },
        {
          "tag": "v0.20.0",
          "kind": "minor",
          "published_at": "2026-04-24T22:29:01Z"
        },
        {
          "tag": "v0.19.0",
          "kind": "minor",
          "published_at": "2026-04-24T14:58:14Z"
        },
        {
          "tag": "v0.18.0",
          "kind": "minor",
          "published_at": "2026-04-23T21:33:54Z"
        },
        {
          "tag": "v0.17.1",
          "kind": "patch",
          "published_at": "2026-04-16T06:19:23Z"
        },
        {
          "tag": "v0.17.0",
          "kind": "minor",
          "published_at": "2026-04-15T11:38:18Z"
        },
        {
          "tag": "v0.16.0",
          "kind": "minor",
          "published_at": "2026-04-14T19:34:38Z"
        },
        {
          "tag": "v0.15.1",
          "kind": "patch",
          "published_at": "2026-04-07T09:28:00Z"
        },
        {
          "tag": "v0.15.0",
          "kind": "minor",
          "published_at": "2026-04-07T09:14:33Z"
        },
        {
          "tag": "v0.14.0",
          "kind": "minor",
          "published_at": "2026-04-03T10:07:33Z"
        },
        {
          "tag": "v0.13.0",
          "kind": "minor",
          "published_at": "2026-03-29T21:37:04Z"
        },
        {
          "tag": "v0.12.0",
          "kind": "minor",
          "published_at": "2026-03-28T13:48:21Z"
        },
        {
          "tag": "v0.11.0",
          "kind": "minor",
          "published_at": "2026-03-28T09:25:57Z"
        },
        {
          "tag": "v0.10.0",
          "kind": "minor",
          "published_at": "2026-03-23T15:45:02Z"
        },
        {
          "tag": "v0.9.0",
          "kind": "minor",
          "published_at": "2026-03-23T12:49:57Z"
        },
        {
          "tag": "v0.8.0",
          "kind": "minor",
          "published_at": "2026-03-23T06:56:12Z"
        },
        {
          "tag": "v0.7.0",
          "kind": "minor",
          "published_at": "2026-03-17T13:59:40Z"
        },
        {
          "tag": "v0.6.0",
          "kind": "minor",
          "published_at": "2026-03-17T10:41:38Z"
        },
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2026-03-17T08:44:09Z"
        },
        {
          "tag": "v0.4.0",
          "kind": "minor",
          "published_at": "2026-03-16T09:30:54Z"
        },
        {
          "tag": "v0.3.0",
          "kind": "minor",
          "published_at": "2026-03-12T10:01:26Z"
        },
        {
          "tag": "v0.2.0",
          "kind": "minor",
          "published_at": "2026-03-03T10:09:16Z"
        },
        {
          "tag": "v0.1.0",
          "kind": "minor",
          "published_at": "2026-02-19T18:20:14Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "4444f7986b29b07d24791a86f2cc84e123ec6a4c",
          "body": "ci(release): crates.io = libraries only + metadata-derived publish + dry-run gate",
          "is_bot": false,
          "headline": "Merge pull request #312 from meteora-pro/feat/crates-io-lib-only-publish",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-25T12:02:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b291203525e99847019f4e563e694cd0e7179f17",
          "body": "Option A for the chronically-broken crates.io release (#308):\n\n- Mark devboy-cli (app binary) + devboy-mcp publish=false — they hard-depend on\n  the internal secrets plugins (publish=false), so they can never publish to\n  crates.io. Distributed via npm + release binaries instead.\n- Replace the hardc\n[…]\ns on every PR, before the release tag.\n\nValidated: dry-run packages exactly the 17 clean libs, skips cli/mcp/plugins.\n\nCloses #308\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci(release): crates.io = libraries only, metadata-derived + dry-run gate",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-25T11:52:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f8a9ec73a0f066df21668863da20eecb3401eeb2",
          "body": "…able\n\nci(release): skip publish=false crates in crates.io publish",
          "is_bot": false,
          "headline": "Merge pull request #311 from meteora-pro/fix/crates-io-skip-unpublish…",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-25T10:18:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "63acd9ec551739bcc1e6cc5e00f0530207f7f73d",
          "body": "The secrets epic (#247) added publish=false crates (devboy-secrets-agent,\nsecrets-ui, all secrets plugins), but release-crates-io.yml's publish loop\nstill lists them and publish_if_new only tolerated \"already exists\" — so\n`cargo publish` on an unpublishable crate aborted the whole release\n(v0.32.0 p\n[…]\nied on\ndevboy-secrets-agent). Guard publish_if_new to skip crates whose\ncargo-metadata `publish` is [] (publish=false).\n\nRefs #308\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci(release): skip publish=false crates in crates.io publish",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-25T10:08:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "62326cadfa29b81f123b3b71a2c2f4d81fe1c3fd",
          "body": "docs: clarify wayland-scanner transitive + fold dep note into 0.32.0 (#309 review)",
          "is_bot": false,
          "headline": "Merge pull request #310 from meteora-pro/fix/dep-note-accuracy",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-25T07:19:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "24f36d82ec59497fe0093e882a4bf5c9ab44cfed",
          "body": "Addresses Copilot review on #309: wayland-scanner is not a direct dependency —\nit resolves transitively (via eframe) to >= 0.31.11; only ratatui and keepass\nare direct bumps. Also moves the dep-upgrade entry from [Unreleased] into the\nunpublished [0.32.0] release (where it actually ships).\n\nDocs-only.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: clarify wayland-scanner is transitive; fold dep note into 0.32.0",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-25T07:09:08Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3da2453af52e6e16d2fc3de14f5009622c2e747f",
          "body": "fix(deps): drop all RustSec ignores via ratatui/keepass/wayland-scanner upgrades",
          "is_bot": false,
          "headline": "Merge pull request #309 from meteora-pro/fix/rustsec-drop-ignores",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-25T05:45:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "498db1a03d978df7745c6839cd43f17b372d55e5",
          "body": "- ratatui 0.29 → 0.30 (removes unmaintained `paste`, RUSTSEC-2024-0436)\n- keepass 0.12 → 0.13 + wayland-scanner → 0.31.11 (both pull quick-xml >= 0.41,\n  fixing RUSTSEC-2026-0194 / -0195 DoS)\n- deny.toml [advisories].ignore is now empty\n\nFresh dependency resolve confirmed: no `paste`, quick-xml 0.41.0 only.\nNo first-party API/behavior changes; build/clippy/tests/fmt/cargo-deny green.\n\nCloses #308\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(deps): drop all RustSec ignores via dependency upgrades",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-25T05:32:40Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "39171aa96f0e9307c5840add902079bdbd2328b5",
          "body": "feat: OAuth 2.1 auth for proxy MCP upstreams (device flow + auto-refresh)",
          "is_bot": false,
          "headline": "Merge pull request #307 from meteora-pro/feat/oauth2-proxy",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-25T05:12:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "04527ee884c0def1b68cc270e9c586e011e3155e",
          "body": "The tools reference embeds the version banner; sync it after the 0.32.0 bump\n(Docs --check gate).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(docs): regenerate tools reference for v0.32.0",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-25T04:56:41Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f782dea01a99747ccc57a5dfb16d0b29493b4c79",
          "body": "Bump workspace + plugin manifests 0.31.1 → 0.32.0; cut CHANGELOG [0.32.0].\nPublish (crates.io + npm) is gated on pushing the v0.32.0 tag — not done here.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): v0.32.0 — OAuth 2.1 proxy auth",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-25T04:52:14Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a5f89a8da9717d4cf8aacdf17a8f90ecffbdbe78",
          "body": "…llback, full initialize probe\n\n- well_known_url: bracket IPv6 authority (host_str() yields unbracketed ::1,\n  building a malformed URL; require_web_url permits http loopback IPv6). +test.\n- OAuthAuth::new: drop the reqwest::Client::new() fallback that re-enabled the\n  default redirect policy on the\n[…]\n436 note (paste is pulled by ratatui, not\n  egui/eframe; compile-time proc-macro only).\n\nAddresses Copilot review threads on #307.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(oauth): address review feedback — IPv6 well-known, no-redirect fa…",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-25T04:52:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8e116eea390656a59844c5bab2d60edd2a616931",
          "body": "… (#306)\n\nThe MCP authorization spec requires the client to pass `resource=<mcp-url>`\non the authorization, token, and refresh requests so the AS binds the\nissued token's audience to the target MCP server. Thread the resource\nindicator through request_device_authorization, poll_device_token_once,\nan\n[…]\ns no introspection endpoint — so end-to-end tool calls are\nblocked on server-side token validation, tracked separately.)\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(oauth): send RFC 8707 resource indicator on device/token/refresh…",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-23T15:46:57Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2bb0f1a47f9b6b45ef0a5b0d57cff6a5100d1d09",
          "body": "…(#306)\n\nThree integration bugs found by end-to-end testing `devboy login` against\nthe real app.devboy.pro authorization server (unit/integration tests and\nstatic review missed all three — they only surface against a live server):\n\n- Config source mismatch: cmd_login loaded via Config::load() (the g\n[…]\nrough discovery → registration → device\nauthorization → poll (clean `expired_token` termination) against\napp.devboy.pro.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(oauth): make `devboy login` work against a live RFC-compliant AS …",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-23T14:43:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a1780b322058969185baf8c01fcf7c2c59445b7a",
          "body": "…ate (#306)\n\nRemaining review findings:\n\n- cmd_login's device-poll loop had no client-side deadline (`expires_in`\n  was parsed but unused); a misbehaving AS answering `authorization_pending`\n  forever hung the CLI. Bound it by the device code's lifetime.\n- request_sse pushed the pending (id, tx) reg\n[…]\nd token_endpoint — so a config\n  missing it showed green while the proxy was silently skipped. Doctor\n  now checks both.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(oauth): bound device poll, plug SSE pending leak, align doctor st…",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-23T10:45:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "daac829a18b53eb60b5d8c81382349c1978b623e",
          "body": "The single-flight gate was in-process only, but a multi-agent setup runs\nseveral `devboy` processes (one proxy per agent) against the same\nkeychain key. When the access token expired, each independently spent\nthe same rotating refresh token; the AS rotates once, so every loser got\n`invalid_grant` an\n[…]\nopts the winner's pair rather than surfacing a re-login.\n\nAdds a test simulating another process having already rotated.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(oauth): store-reconcile refresh to survive rotation races (#306)",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-23T10:45:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "cb5590d0e7e545c4938aa3fecf20db32cee3e0f8",
          "body": "…306)\n\nTwo token-response hardening fixes from the independent review:\n\n- Panic-DoS: `now + Duration::seconds(expires_in)` panicked on an\n  attacker-controlled `expires_in` (e.g. i64::MAX — a valid JSON\n  integer). In OAuthAuth::refresh that aborts the running MCP proxy on a\n  live tool call. Clamp \n[…]\ncess, refresh success); metadata parses keep\n  their detail.\n\nAdds a from_response test for the out-of-range expires_in.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(oauth): clamp expires_in + stop echoing token bodies in errors (#…",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-23T10:45:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "41b83a006ad4dd41391cc4a9279636005b0669a1",
          "body": "…ints (#306)\n\nIndependent review (Kimi K3 + a second reviewer) found the discovery\ntrust boundary was porous. Harden it:\n\n- require_web_url now parses with `url::Url` instead of string prefixes.\n  It rejects credentials in the authority (`http://localhost@evil/`),\n  non-http(s) schemes, and — for ht\n[…]\nurned `issuer` matches (§3.3).\n\nAdds tests for the bypasses, IP-range rejection, and path-aware\nwell-known construction.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(oauth): close SSRF holes in discovery + validate advertised endpo…",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-23T10:36:28Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c9234a6813f046a856f2ca7480ee5edcda39bef2",
          "body": "…h (#306)\n\nCopilot review: the request_http oauth2 behavior (pre-flight token, then\nrefresh-and-retry-once on 401) had no test at the proxy request layer —\nonly the OAuthAuth contract was covered. Add a focused test that mocks a\npersistent 401 on tools/call and asserts exactly one refresh\n(single-flight) + one retry, ending in the actionable re-login error.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(proxy): cover oauth2 refresh-and-retry on 401 in the request pat…",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-23T09:56:13Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "384faff414f3d28b7e3b14d737bdfbd44a481005",
          "body": "…d (#306)\n\nCopilot review: `devboy doctor` marked an oauth2 proxy \"logged_in\" on the\nmere presence of a stored secret, but the proxy path needs it to\ndeserialize as OAuthTokens. A corrupt/partial blob now reads as\nnot-logged-in (with the actionable `devboy login` fix) instead of a\nfalse-positive session.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(doctor): report oauth2 logged_in only when the token blob is vali…",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-23T09:56:13Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "c3fd6d62036067d88fd9fe34c8c724dc2d293c4d",
          "body": "Address Copilot review findings on the login/discovery path:\n\n- SSRF guard: validate every outbound discovery URL (resource_metadata\n  from the WWW-Authenticate challenge, and the AS issuer) via\n  require_web_url — https required, http only for loopback. A crafted\n  upstream challenge can no longer \n[…]\ntted entirely).\n\nAdds require_web_url unit tests (https/loopback ok; remote-http, file,\nftp, gopher, hostless rejected).\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(oauth): harden discovery + honor advertised scopes (#306)",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-23T09:56:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2b6ee42560e8ea846727d9b0462129e49c074c09",
          "body": "CI's stable clippy rolled to 1.97, whose stricter lints flag pre-existing\ncode (unrelated to this PR, but it blocks the shared Clippy gate under\nRUSTFLAGS=-Dwarnings):\n\n- question_mark: collapse `match opt { Some/None=>return }` and an\n  `else if let … else { return None }` chain into `?`\n  (devboy-\n[…]\nll behavior-preserving. Full-workspace `clippy --all-targets\n--all-features` under -Dwarnings is clean on stable 1.97.1.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(clippy): resolve rust-1.97 lints across workspace (#306)",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-23T06:36:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b9ea1285811731450d242d5a12fe5eff83e740f0",
          "body": "cargo-deny went red on freshly-published RUSTSEC-2026-0194/0195\n(quick-xml DoS via malicious XML, patched >= 0.41.0) — a pre-existing\necosystem issue, not introduced by this PR. quick-xml enters only via\nkeepass (parses the user's own local .kdbx password DB) and\nwayland-scanner (build-time proc-mac\n[…]\needs upstream releases.\nIgnore with a documented reachability analysis, matching the existing\nRUSTSEC-2024-0436 pattern.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(deps): ignore unreachable quick-xml XML-DoS advisories (#306)",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-23T06:22:57Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "da7c2d2e4ba082be6deed866e1770ebd176caa62",
          "body": "…(#306)\n\nBring PR #307's red hygiene jobs to green with the honest ADR-019 fix\nrather than gaming the gates:\n\n- Secrets discipline: TokenResponse/OAuthTokens token fields are now\n  secrecy::SecretString (was String). OAuthTokens round-trips through a\n  scoped secret_serde helper, so the only plainte\n[…]\n path.\n\n309 devboy-core + 266 devboy-mcp tests pass; fmt/clippy/rustdoc/\npublic-api/secrets-discipline verified locally.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(oauth): carry proxy tokens as SecretString + green hygiene gates …",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-23T06:22:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9f87ea5d036bff42d1812d5e9dafdd27a25503cf",
          "body": "Review issue #2: adds a test for the exact sequence request_http/request_sse\nrun on a 401 — access_token() (pre-flight, valid token unchanged) -> refresh\n(sent) (single-flight) -> access_token() yields the rotated token. Full\ntransport-level e2e (with initialize/session/id echoing) is deferred as it\nadds flakiness for little extra coverage over this contract test.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(oauth): cover on-401 refresh-retry contract (#306)",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-23T05:51:22Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f16aa4949c40460622ef3a8c1de3718882d3de38",
          "body": "…e (#306)\n\nReview issues #3/#4/#5:\n- cmd_login rejects non-oauth2 proxies with a clear message instead of\n  attempting a device flow against a bearer/api_key upstream.\n- request_http/request_sse map a post-refresh 401 to an actionable error\n  (\"run: devboy login <name>\") instead of a raw HTTP 401; r\n[…]\nt.\n- OAuthAuth::refresh documents the persist-before-swap failure semantics\n  (dead-refresh -> re-login, no corruption).\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(oauth): login guard + actionable 401 errors + persist-failure not…",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-23T05:49:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c7892bd06ca0f720d25f72e70c2b4275d349f4f0",
          "body": "Review issue #1: oauth2 was only injected into request_http (streamable-\nhttp). SSE proxies with auth_type=\"oauth2\" ran unauthenticated. Now the SSE\nGET stream is seeded with the access token at connect, and request_sse POSTs\ncarry a per-request Bearer with the same on-401 single-flight refresh-retry\nas request_http. Documented follow-up: stream reconnect-on-refresh (the GET\nstream header is fixed at connect).\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(proxy): wire OAuth into SSE transport too (#306)",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-23T05:47:49Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "096181995c54692c9aa5f1cbbfa4683fff24700f",
          "body": "proxy.md gains an \"OAuth 2.1 authentication (device flow)\" section (config +\n`devboy login` + doctor state); auth_type field row lists oauth2. Regenerated\ncli.md reference to include the new `login` command.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(oauth): document auth_type=oauth2 + devboy login (#306)",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-22T21:03:42Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "cb81a3892d74dc3bbc0d0cb862b34e1d1708b37d",
          "body": "doctor now accepts auth_type=\"oauth2\" (was flagged Invalid) and reports per\nproxy: Pass \"logged in; tokens auto-refresh\" when the proxy.<name>.oauth\nsecret + client_id exist, else Error \"not logged in\" with the exact fix\ncommand `devboy login <name>`. This is the stdio-side awareness signal for a\nhu\n[…]\nio-only, so http WWW-Authenticate passthrough is N/A — noted as a\nfollow-up if a remote http server mode is ever added.)\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(doctor): report OAuth login state for oauth2 proxies (#306)",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-22T20:59:21Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "860db46be2dbdf0ff8ba91daafa678b3a1d98d4e",
          "body": "…nt (#306)\n\nProxyOAuthConfig gains token_endpoint, cached by devboy login after discovery\nso the proxy refreshes headlessly without re-discovery. build_oauth_auth loads\nthe stored OAuthTokens (proxy.<name>.oauth) + client_id/token_endpoint and\nconstructs the OAuthAuth holder; build_proxy_manager wir\n[…]\n, skipping — with a clear \"run: devboy login <name>\"\n— any proxy not yet logged in. bearer/api_key/none still pass None.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(proxy): activate oauth2 at runtime — ProxyManager + token_endpoi…",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-22T20:54:47Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0d1706d94e387ed78a633558a074c52c72d45f84",
          "body": "McpProxyClient gains an optional OAuthAuth holder. For auth_type=\"oauth2\"\nthe Bearer is injected per request from the holder (pre-flight refresh),\nnot baked at connect; request_http sends in a retry loop that on a 401 runs\na single-flight refresh and retries once with the rotated token. bearer/\napi_\n[…]\nxyManager activation follows). Test asserts persistence\nvia store.exists (no expose_secret — ADR-023 guard stays green).\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(proxy): per-request OAuth Bearer + on-401 refresh-retry (#306)",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-22T20:50:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6218d1d71be03eed73ddaf1e65acabeb8b10ed96",
          "body": "…(#306)\n\nPer-upstream token holder for auth_type=\"oauth2\". access_token() refreshes\npre-flight within a 60s expiry skew; refresh(seen) is single-flight (gate +\naccess-token double-check so concurrent 401s trigger exactly one refresh)\nand persists the rotated pair to the credential store BEFORE the i\n[…]\ns a spent refresh_token. 2 tokio\ntests (rotation+persist, double-check short-circuit). Wired into the request\npath next.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(proxy): OAuthAuth holder — single-flight refresh, rotation-safe …",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-22T20:37:20Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0f43e960b802c6b02ace1322123fc8a267c5e433",
          "body": "New top-level command orchestrating the RFC 8628 device flow against a proxy\nupstream: discover AS (WWW-Authenticate probe or configured authorization_\nserver) -> register client if needed (persisted to config) -> device\nauthorization -> print user_code + verification_uri_complete -> poll the\ntoken \n[…]\n and auto-refreshes these. Compiles clean; built on the tested oauth\nprimitives (discovery/registration/device/refresh).\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(cli): devboy login <server> — OAuth 2.1 device flow (#306)",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-22T20:32:12Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e0f409cb4f42634e44d65fe8bdd45f0805fcf683",
          "body": "Persisted token set for one proxy upstream (JSON into the credential store\nunder proxy.<name>.oauth). OAuthTokens::from_response computes expires_at\nfrom expires_in relative to now, with a prev_refresh fallback; is_near_expiry\ndrives pre-flight refresh. 5 unit tests (expiry compute, refresh fallback,\nmissing-refresh error, near-expiry threshold, JSON roundtrip).\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(oauth): OAuthTokens model — access/refresh/expires_at (#306)",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-22T20:26:36Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "920619cfd498e9547bece03d2c387ab9dd4e4dcf",
          "body": "refresh() exchanges a refresh_token for a fresh token set via the RFC 6749\n§6 grant. Documents the AS rotation contract: the server returns a NEW\nrefresh_token and deactivates the old, so callers must persist-first and\nsingle-flight (enforced later in the proxy layer). invalid_grant surfaces\nas OAut\n[…]\nOauth so the caller can trigger re-login.\nAdds httpmock dev-dep; 2 integration tests (rotation success + invalid_grant).\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(oauth): refresh_token grant — RFC 6749 §6, rotation-aware (#306)",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-22T20:25:01Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "22b3cc7796cd22d6a4ab0b36b2fc64c302fc130c",
          "body": "request_device_authorization posts the RFC 8628 §3.1 form (client_id +\noptional scope) and parses the §3.2 response (device_code, user_code,\nverification_uri[_complete], expires_in, interval defaulting to 5).\npoll_device_token_once polls the token endpoint with the device_code grant\nand maps outcome\n[…]\nResponse, other error codes -> OAuthError::Oauth.\nparse_oauth_error extracts the RFC 6749 §5.2 error code. 5 unit tests.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(oauth): device authorization grant + token poll — RFC 8628 (#306)",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-22T20:20:28Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7974b05e1acea3915040e4f7223f970c33cb52ee",
          "body": "register_client posts a public device-flow client registration (grant_types\ndevice_code + refresh_token, token_endpoint_auth_method=\"none\") to the AS\nregistration_endpoint and returns the issued client_id. Callers persist it\ninto ProxyOAuthConfig.client_id so re-login reuses the same client.\nGRANT_DEVICE_CODE / GRANT_REFRESH_TOKEN constants shared with later grants.\n2 unit tests (request shape + response parse).\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(oauth): dynamic client registration — RFC 7591 (#306)",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-22T20:16:55Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6f07ada25ab46899f96e2d8fb40d911590f876bf",
          "body": "…(#306)\n\nNew devboy-core::oauth module (client half of the MCP auth spec, standard\nRFCs only). This commit: discovery.\n- parse_www_authenticate: extract resource_metadata URL (RFC 9728), quoted\n  or bare, ignoring other challenge params.\n- discover: WWW-Authenticate -> protected-resource metadata ->\n[…]\n9 unit tests (parsing + metadata deserialization).\n\nRegistration (RFC 7591), device grant (RFC 8628) and refresh follow.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(oauth): OAuth 2.1 discovery — WWW-Authenticate -> RFC 9728/8414 …",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-22T20:01:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "73d21b6882d2a7a2fa8952f273fb9f2439e99e04",
          "body": "Additive config surface for OAuth 2.1 proxy auth. ProxyMcpServerConfig\ngains an optional `oauth` block (ProxyOAuthConfig: client_id / scopes /\nauthorization_server, all optional). A minimal config sets only\nauth_type = \"oauth2\" and lets discovery (RFC 9728/8414) + dynamic\nregistration (RFC 7591) fil\n[…]\ndevboy login`.\n\nBackward compatible: bearer / api_key / none unchanged. All 16 struct\nliterals updated with oauth: None.\n\nRefs #306\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(config): add auth_type=\"oauth2\" + ProxyOAuthConfig (#306)",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-07-22T19:57:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "bd7176471447d1ab7d5d82afb6d508a89a662558",
          "body": "fix(ci): publish secrets plugins before mcp/cli on crates.io",
          "is_bot": false,
          "headline": "Merge pull request #303 from meteora-pro/fix/crates-io-publish-secrets",
          "author_name": "qumagis",
          "author_login": "qumagis",
          "committed_at": "2026-07-01T07:50:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c5730a6bf3c6a68d7d34ceddb5f4842ad6b2ee4b",
          "body": "The crates.io release failed at `Publish devboy-mcp` with \"no matching\npackage named devboy-secret-kdbx found\": devboy-mcp depends on\ndevboy-secret-kdbx, but none of the 8 secrets crates were in the publish\norder, so they were never uploaded before the crates that need them\n(devboy-mcp via kdbx, dev\n[…]\neds secrets-agent).\nUses the same publish_if_new idempotency, so it survives partial-retry of\nthe already-published 0.31.1 crates.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci): publish secrets plugins before mcp/cli on crates.io",
          "author_name": "Maxim Dymov",
          "author_login": null,
          "committed_at": "2026-06-30T18:26:39Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c4ee9bedf5a81e3018d7df585cdef46773a487f1",
          "body": "chore(release): bump workspace to 0.31.1",
          "is_bot": false,
          "headline": "Merge pull request #302 from meteora-pro/chore/release-0.31.1",
          "author_name": "qumagis",
          "author_login": "qumagis",
          "committed_at": "2026-06-30T15:58:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eee3eca94d2f5b4fff23e8ac66ab6a5623c1ee84",
          "body": "Per docs/guide/contributing/release.md Step 1:\n- [workspace.package].version 0.31.0 -> 0.31.1\n- all [workspace.dependencies] devboy-* version pins -> 0.31.1\n- sync plugin manifests (claude/codex plugin.json + marketplace.json)\n  via scripts/release/sync-plugin-version.sh\n- regenerate docs/guide/refe\n[…]\nersion, skills, readme sync,\ntools/cli reference). Tag v0.31.1 after this merges to fan out the\nnpm + crates.io release workflows.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): bump workspace to 0.31.1",
          "author_name": "Maxim Dymov",
          "author_login": null,
          "committed_at": "2026-06-30T15:55:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0324e0c52176a38babe0f6093da20a019075185f",
          "body": "…down-blocks\n\nfix(clickup): render comment markdown via comment blocks (#300)",
          "is_bot": false,
          "headline": "Merge pull request #301 from meteora-pro/fix/300-clickup-comment-mark…",
          "author_name": "qumagis",
          "author_login": "qumagis",
          "committed_at": "2026-06-30T15:49:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "159fbe85c824114bb93b35d3018a4eea98bc49ee",
          "body": "The public-api drift job ran on a floating `dtolnay/rust-toolchain@nightly`.\ncargo-public-api prints fully-qualified type paths, so a toolchain change\n(std::io::Error becoming a re-export of core::io::Error) shifted every\nbaseline that mentions io::Error, failing CI on unrelated crates.\n\nPin the job\n[…]\nthe std::io::error -> core::io::error path rename; no\nreal public API changed. Bump the pin deliberately + regenerate when needed.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci(public-api): pin nightly toolchain, regenerate baselines (#300)",
          "author_name": "Maxim Dymov",
          "author_login": null,
          "committed_at": "2026-06-30T15:36:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "75155e6d7b56a1bcb05dc72ac822cc774105f157",
          "body": "… (#300)\n\nBuilds on the existing comment_format.rs converter (markdown -> ClickUp\n`comment` rich-text runs) rather than duplicating it. Adds:\n\n- italic (`*x*` / `_x_`) and `[text](url)` links as inline run attributes\n- GFM tables -> aligned monospace `code-block` (comments have no table\n  mark); col\n[…]\nting bold rendering\n\nThe inline parser is char-based, so all additions are UTF-8 safe.\nVerified against the real ClickUp API + UI.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(clickup): extend comment markdown — italic, links, tables, tasks…",
          "author_name": "Maxim Dymov",
          "author_login": null,
          "committed_at": "2026-06-30T12:41:54Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "32724cf4e0355e40141d2123fc82daef60422d1b",
          "body": "…y-status\n\nfeat(clickup): surface display status + category in get_issue (DEV-1578)",
          "is_bot": false,
          "headline": "Merge pull request #298 from meteora-pro/feat/DEV-1578-clickup-displa…",
          "author_name": "ai-dev-2-meteora-pro",
          "author_login": "ai-dev-2-meteora-pro",
          "committed_at": "2026-06-09T14:55:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cc325febc2bd414bdd418f11741c5d5c3f6213f4",
          "body": "…ion (DEV-1578b)\n\nAddresses PR #298 merge-readiness review (test-coverage gaps). Adds\ntest_resolve_custom_field_display_degrades_gracefully asserting every\nnon-resolving branch yields display=None with the raw value preserved\n(never a wrong label / panic):\n- drop_down order index out of u32 range (t\n[…]\no matching option\n- drop_down option id with no match\n- type_config present but options empty\n- labels ids with no matching option\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(clickup): cover graceful-degradation branches in display resolut…",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-06-09T10:41:18Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "13f99c22449ba71d0b858914321341bc9a15de3a",
          "body": "Follow-on to the workspace 0.31.0 bump — regenerate the version-derived\nartifacts the CI drift checks enforce:\n- plugins/{claude,codex}/.../plugin.json + .claude-plugin/marketplace.json\n  (via scripts/release/sync-plugin-version.sh)\n- docs/guide/reference/tools.md header (\"DevBoy Tools v0.31.0 …\")\n  (via `devboy tools docs`)\n\nFixes the red \"Plugin manifests drift check\" and \"Docs\" CI jobs. Only the\nversion string changed.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): sync plugin manifests + tools reference to 0.31.0",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-06-09T10:34:26Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6a6dff8aeaab2ea973594a897bbb54c04e859a7e",
          "body": "DEV-1578 / DEV-1578b add public API (Issue.status/status_category,\nCustomFieldValue.display, ClickUp type_config resolution types) — a\nsemver-minor change. Bump [workspace.package].version and all internal\ndevboy-* dependency pins 0.30.1 → 0.31.0 so a crates.io publish resolves\nthe registry version consistently. (Publish itself stays gated: DEV-1579.)\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): bump workspace to 0.31.0",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-06-09T10:29:59Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "1ca6a4ca34b523acf9c31aab8a800161cb2de18b",
          "body": "Address PR #298 review (Copilot): resolve the drop_down order index with\n`u32::try_from(..).ok()?` instead of `as u32`, so an out-of-range value\nfails cleanly to `display = None` (raw value preserved) rather than\ntruncating to a wrong option label.\n\nAdd an httpmock end-to-end test (test_get_issues_r\n[…]\nved label in the\nserialized agent-facing JSON. Validates the serde wiring against the real\npayload, not just the in-memory mapper.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(clickup): guard dropdown index + e2e wire-shape test (DEV-1578b)",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-06-09T10:29:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "588bb03a3dc4d5f77b8bdc0a4cc0548fc551a149",
          "body": "Reflow only — `cargo fmt --all` (stable, matching the Format CI job)\ntouched nothing outside the new DEV-1578b code in client.rs. Fixes the\nred Format check on PR #298.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "style(clickup): rustfmt the DEV-1578b resolver + tests (DEV-1578b)",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-06-09T09:01:17Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "df828a87fcda5aa675984d7e5ddcf2f8ddfb0fd4",
          "body": "…ditions (DEV-1578)\n\nDEV-1578 added Issue.status / Issue.status_category, DEV-1578b added\nCustomFieldValue.display and the ClickUp drop_down/labels resolution types\n(ClickUpFieldTypeConfig / ClickUpFieldOptionInline, re-exported via\n`pub use types::*`). Regenerate the cargo-public-api baselines (pin\n[…]\ns:: + crate root)\n- devboy-clickup: 2 new public types + ClickUpCustomField.type_config\n\nAll 12 other first-wave crates: no drift.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(public-api): regenerate baselines for Issue/CustomFieldValue ad…",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-06-09T08:21:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8fa4f408c0bb15d4ffb28e741c12805cdf30c6fb",
          "body": "…abels (DEV-1578b)\n\n`map_task` surfaced custom fields with ClickUp's opaque raw value — a\ndrop_down came back as its order index (`0`), a labels multi-select as an\narray of option ids — so an agent reading the field saw `0`, not `dev`.\nClickUp already embeds `type_config.options` (id/orderindex/name\n[…]\n display None\n\nPart of epic DEV-1577; surfaces the Shipped Version / Dev Env Host dropdowns\nas readable values instead of indices.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(clickup): resolve drop_down/labels custom-field values to human l…",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-06-09T08:12:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e8402287e803e43c71452754bb0ce5f29068cb9a",
          "body": "ClickUp's rich workflow statuses (e.g. \"in progress\", \"review\", \"ready\nto release\", \"complete\") drive the team's \"what's deployed where\" board,\nbut get_issue/get_issues only exposed the binary `state` (open/closed),\ncollapsing the promotion stage. This is the read-path foundation for\nADR-114 (deploy\n[…]\n test_map_task; add test_map_task_surfaces_display_status\n  (clickup) + test_encode_issues_standard_includes_display_status (toon)\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(clickup): surface display status + category in get_issue (DEV-1578)",
          "author_name": "Andrey Maznyak",
          "author_login": "andreymaznyak",
          "committed_at": "2026-06-06T06:42:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "bf0a19468466aeaef511b0f21bc9be1dbf3d3a2a",
          "body": "fix(clickup): render comments via structured comment[] rich-text (#294)",
          "is_bot": false,
          "headline": "Merge pull request #295 from meteora-pro/fix/clickup-comment-rich-text",
          "author_name": "qumagis",
          "author_login": "qumagis",
          "committed_at": "2026-06-02T21:45:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d3c64573d489bfd1f30dd4ea886b267cebb16b8b",
          "body": "…line (#294)\n\nCI resolves bitflags 2.12.1 (the repo doesn't commit Cargo.lock, so CI\nalways builds against latest deps). bitflags 2.12 adds an `all_named()`\nmethod to the macro-generated flags API, so `Capabilities::all_named()`\nnow appears in devboy-storage's public surface and the public-api drift\n[…]\nurely the two\n`all_named()` lines, no other changes. Unblocks unrelated PRs (this one\nonly touches the ClickUp comment converter).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(storage): add bitflags-generated all_named() to public-api base…",
          "author_name": "Maxim Dymov",
          "author_login": "qumagis",
          "committed_at": "2026-06-02T21:29:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5fbf92a964180d3c97bf6143c82d627350830825",
          "body": "Making `comment_format` public (for the markdown→comment[] converter) and\nadding `CreateCommentRequest::comment` extends the crate's public surface.\nRegenerate the cargo-public-api baseline so the drift check passes. The\ndiff is purely additive: the new `comment_format` module types\n(CommentBlock, CommentAttributes, CodeBlockAttr, ListAttr),\nmarkdown_to_comment_blocks, and the new request field — no removals.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(clickup): regenerate public-api baseline for comment_format (#294)",
          "author_name": "Maxim Dymov",
          "author_login": "qumagis",
          "committed_at": "2026-06-02T21:17:05Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9691ecb80980d0e1b2a0d9b151819fc2a480ed64",
          "body": "…#294)\n\nAddress PR review: the trailing-newline trim only popped a single plain\n`\"\\n\"` block, so a body ending in multiple newlines (e.g. \"a\\n\\n\") left a\ndangling blank-line separator. Loop until no trailing plain newline\nremains, while preserving block-attribute separators (code-block / list)\nwhich are structurally significant. Add regression tests.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(clickup): trim all trailing plain newlines in comment converter (…",
          "author_name": "Maxim Dymov",
          "author_login": "qumagis",
          "committed_at": "2026-06-02T21:17:05Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "52bb490b30355b69addd19469be34d3987b77a10",
          "body": "…er (#294)\n\nThe inline parser treated **bold** content as opaque, so **`code`** kept\nits literal backticks and rendered as a bold run containing backtick\ncharacters. Parse the bold span's inner content recursively and OR the\nbold mark onto each resulting run, so an overlapping span carries both\n`bol\n[…]\nple\n(stdin markdown → comment[] JSON), used to repair existing comments via\nPUT /comment/{id} with the exact same rendering logic.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(clickup): handle nested bold+code inline marks in comment convert…",
          "author_name": "Maxim Dymov",
          "author_login": "qumagis",
          "committed_at": "2026-06-02T21:17:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e5ca2e330aa7a06c92091280829dcda9bc8d4928",
          "body": "ClickUp's Comments API does not render markdown. `comment_text` is run\nthrough a lossy auto-formatter that turns every backtick span into an\nisolated inline-code chip, so a comment with many code tokens renders as\ndisconnected gray boxes with the prose shattered around them. The\n`markdown_content` f\n[…]\n,\nfenced block renders as a code block, list items keep their inline marks,\nand there is no duplicated raw-text tail.\n\nCloses #294\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(clickup): render comments via structured comment[] rich-text (#294)",
          "author_name": "Maxim Dymov",
          "author_login": "qumagis",
          "committed_at": "2026-06-02T21:17:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f93edfff2d9e63087e2fe3bdcfd4beb97032c383",
          "body": "v0.30.0 publish run failed at devboy-executor because the new\ndevboy-telegram crate (#262) had never been published to crates.io —\nthe release workflow's Layer 2 list didn't include it, and the\ncrate's manifest was missing crates.io metadata (keywords/categories/\nreadme/homepage and workspace-resolv\n[…]\n\nDocs:\n  - tools.md regenerated for the new version header\n\nVersions: 0.30.0 → 0.30.1 across [workspace.package].version,\n[workspace.dependencies] (27 internal crates), and the three plugin\nmanifests.",
          "is_bot": false,
          "headline": "chore(release): bump workspace to 0.30.1 + fix telegram publish",
          "author_name": "Maxim Dymov",
          "author_login": "qumagis",
          "committed_at": "2026-05-27T18:29:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "083403d7ecb2eac296d372e6e2f8a0fce8dfa717",
          "body": "Minor release — telegram messenger provider added (#262, gh#86).\n\nVersions bumped: [workspace.package].version, [workspace.dependencies]\n(27 internal crates incl. new devboy-telegram), plus three plugin\nmanifests (.claude-plugin/marketplace, plugins/{claude,codex}/.../plugin.json).",
          "is_bot": false,
          "headline": "chore(release): bump workspace to 0.30.0",
          "author_name": "Maxim Dymov",
          "author_login": "qumagis",
          "committed_at": "2026-05-27T17:53:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "404dce121e85dfd73db34cee68f37e067bfc5c32",
          "body": "…er-provider\n\nfeat: add telegram messenger provider (#86)",
          "is_bot": false,
          "headline": "Merge pull request #262 from meteora-pro/feat/86-add-telegram-messeng…",
          "author_name": "qumagis",
          "author_login": "qumagis",
          "committed_at": "2026-05-27T17:49:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6e97438da7b3c74e3976d24958765868b94fc935",
          "body": "…hub.com/meteora-pro/devboy-tools into feat/86-add-telegram-messenger-provider",
          "is_bot": false,
          "headline": "Merge branch 'feat/86-add-telegram-messenger-provider' of https://git…",
          "author_name": "mikhailova-klavdia",
          "author_login": "mikhailova-klavdia",
          "committed_at": "2026-05-26T19:45:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4f7568ef46d5e6720b655525fe45832f7d0e4a35",
          "body": "…to feat/86-add-telegram-messenger-provider",
          "is_bot": false,
          "headline": "Merge branch 'main' of https://github.com/meteora-pro/devboy-tools in…",
          "author_name": "mikhailova-klavdia",
          "author_login": "mikhailova-klavdia",
          "committed_at": "2026-05-26T19:45:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9883a8db83148aae020125e977611463d2dd9fa0",
          "body": "crates.io rejected devboy-token-catalog 0.29.2 publish with:\n  > The following category slugs are not currently supported on\n  > crates.io: configuration\n\nThe slug for configuration-related crates is `config`, not\n`configuration`. Verified against\nhttps://crates.io/api/v1/categories — `config` is va\n[…]\n\nUnblocks the 0.29.2 release pipeline (Layer 1 step 4 of 4). Other\ncrates (devboy-core, devboy-secret-patterns, devboy-vault-crypto)\nalready shipped, so this is a cherry-pick fix on the trailing leaf.",
          "is_bot": false,
          "headline": "fix(token-catalog): use valid crates.io category slug `config`",
          "author_name": "Maxim Dymov",
          "author_login": "qumagis",
          "committed_at": "2026-05-26T18:39:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "13b79ba6c5899120d21f7e46d4a699792adfad09",
          "body": "`release.yml` step `Verify reference docs match the tagged binary` runs\n`devboy tools docs --check` which compares the committed snapshot to\nthe binary-generated one. After bumping workspace to 0.29.2 the header\n\"DevBoy Tools v{version}\" went out of sync and the check failed,\nblocking the GitHub release + npm publish pipeline.\n\nOnly the version line changed; all tool schemas are identical to the\n0.29.1 generation.",
          "is_bot": false,
          "headline": "docs(tools): regenerate reference for 0.29.2 header",
          "author_name": "Maxim Dymov",
          "author_login": "qumagis",
          "committed_at": "2026-05-26T17:52:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ee004191d7f9d1d6adcd0cc22f7dadf376be4cde",
          "body": "v0.29.1 publish run failed at devboy-storage because devboy-storage now\ndepends on devboy-secret-patterns (epic #247 secrets framework) which\nhad never been published to crates.io — the release workflow's Layer 1\nonly knew about devboy-core. Layer 1 succeeded (devboy-core 0.29.1\nshipped), Layer 2 bl\n[…]\npace.package].version,\n[workspace.dependencies] (15 lib crates + 10 internal secret/plugin\ncrates), and the three plugin manifests (.claude-plugin/marketplace,\nplugins/{claude,codex}/.../plugin.json).",
          "is_bot": false,
          "headline": "chore(release): bump workspace to 0.29.2 + extend release pipeline",
          "author_name": "Maxim Dymov",
          "author_login": "qumagis",
          "committed_at": "2026-05-26T17:43:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9a8c28f98e8ce1d3913d1a3c865b00b9b7decb2f",
          "body": "Patch release picking up:\n  - gh#287 (PR #289): wire ClickUp assignees through POST/PUT /task — the\n    `update_issue` / `create_issue` paths in the ClickUp adapter were\n    accepting an `assignees` arg and silently dropping it before sending\n    to ClickUp.\n  - gh#288 (PR #290): support setting Cli\n[…]\nmps:\n  - [workspace.package].version: 0.29.0 → 0.29.1\n  - [workspace.dependencies] internal devboy-* crates: 0.29.0 → 0.29.1\n  - .claude-plugin/marketplace.json, plugins/{claude,codex}/.../plugin.json",
          "is_bot": false,
          "headline": "chore(release): bump workspace to 0.29.1",
          "author_name": "Maxim Dymov",
          "author_login": "qumagis",
          "committed_at": "2026-05-26T17:24:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6db36ec7747a1f6c3a0a2d44965d1273c86d3107",
          "body": "feat(clickup): support setting custom statuses via update_issue (#288)",
          "is_bot": false,
          "headline": "Merge pull request #290 from meteora-pro/feat/288-clickup-custom-status",
          "author_name": "qumagis",
          "author_login": "qumagis",
          "committed_at": "2026-05-26T15:32:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aecd47a008a8afc95e097777d99f8a9b1b3cb1db",
          "body": "…t-pagination-schema\n\nfix(executor): restore get_meeting_transcript pagination/filter schema (#291)",
          "is_bot": false,
          "headline": "Merge pull request #292 from meteora-pro/fix/gh-291-restore-transcrip…",
          "author_name": "qumagis",
          "author_login": "qumagis",
          "committed_at": "2026-05-26T15:10:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5bf86b2c4ebf363d599c65049d68bbfd8d3ce64a",
          "body": "…om-status\n\n# Conflicts:\n#\tcrates/plugins/api/clickup/src/client.rs",
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'origin/main' into feat/288-clickup-cust…",
          "author_name": "Maxim Dymov",
          "author_login": "qumagis",
          "committed_at": "2026-05-26T15:09:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "abc8e4f61a9faeaef9c5c895d66364bcbd961589",
          "body": "fix(clickup): wire assignees through PUT/POST /task (#287)",
          "is_bot": false,
          "headline": "Merge pull request #289 from meteora-pro/fix/287-clickup-assignees-no-op",
          "author_name": "qumagis",
          "author_login": "qumagis",
          "committed_at": "2026-05-26T15:02:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2d4f1ff8e26d14414ce6bb4a5f34c0d193de6ae9",
          "body": "… grouped]\n\nCopilot review feedback on PR #292: format was declared as free-form string\neven though dispatcher only accepts 'flat' / 'grouped'. Switch to\n`PropertySchema::string_enum` so MCP client-side validators reject invalid\nvalues up-front and the generated docs render the allowed set explicitly.",
          "is_bot": false,
          "headline": "fix(executor): constrain get_meeting_transcript.format to enum [flat,…",
          "author_name": "Maxim Dymov",
          "author_login": "qumagis",
          "committed_at": "2026-05-26T09:01:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8bad7e3c2809e61465f90270ec0a57ef5be08e68",
          "body": "…gh#291)",
          "is_bot": false,
          "headline": "docs(tools): regenerate after get_meeting_transcript schema restore (…",
          "author_name": "Maxim Dymov",
          "author_login": "qumagis",
          "committed_at": "2026-05-26T08:59:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "918cf049e633410fdd29012a4de9563f90d43403",
          "body": "…a (gh#291)\n\nThe `get_meeting_transcript` tool definition currently advertises only\nthe `meeting_id` property to MCP clients, but the consumer backend\n(devboy-api-rs `TranscriptArgs`) parses 5 additional optional fields —\n`offset`, `limit`, `speaker_filter`, `search_text`, `format`. Without\nthese in\n[…]\nconsumer code change needed beyond bumping the dependency.\n\nTests:\n- New `test_get_meeting_transcript_exposes_pagination_and_filters`\n  regression guard\n- All existing tool-schema tests pass (241/241)",
          "is_bot": false,
          "headline": "fix(executor): restore get_meeting_transcript pagination/filter schem…",
          "author_name": "Maxim Dymov",
          "author_login": "qumagis",
          "committed_at": "2026-05-26T08:50:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8a14a77f50ecf16cf4612e38bbb88c6609236c16",
          "body": "CI failures on PR #290 v2 (commit eec44ac):\n\n- Docs job: docs/guide/reference/tools.md generator picks up the new\n  `status` field on update_issue + update_epic schemas. Regenerated\n  via `cargo run -p devboy-cli -- tools docs --output ...`. Also\n  trimmed the trailing period on the state field's de\n[…]\ndevboy-clickup unchanged (the new\n  validate_status_name and fetch_list_statuses helpers are private,\n  no public surface change).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: refresh tools.md + devboy-core baseline for status field (#288)",
          "author_name": "Mikhail KItaev",
          "author_login": null,
          "committed_at": "2026-05-26T07:51:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d6d1218657804ed86b184b7faad3e0f68f46a778",
          "body": "…pTeams*\n\nBakes the four new pub structs introduced in this PR into the\ncargo-public-api baseline:\n\n- AssigneeDiff (PUT /task assignees envelope)\n- ClickUpTeamsResponse / ClickUpTeam / ClickUpTeamMember\n  (GET /team response shape used by resolve_assignee_ids)\n\nPlus the new `assignees: Option<Assign\n[…]\naskRequest.\n\nPattern matches existing types (CreateTaskRequest, ClickUpUser, …)\nwhich are all pub-exported via `pub use types::*`.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(clickup): refresh public-api baseline for AssigneeDiff + ClickU…",
          "author_name": "Mikhail KItaev",
          "author_login": null,
          "committed_at": "2026-05-26T07:48:09Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "eec44acd52d2cd69cb16a8088964da5775140948",
          "body": "Review feedback on #290:\n\n1. execute_update_epic was hardcoding UpdateIssueInput.status to None\n   while execute_update_issue threaded params.status. Epics are stored\n   as ClickUp tasks too, so the same custom-status workflow applies.\n   Added a status field to UpdateEpicParams, threaded it through\n[…]\n     11th status not leaked\n\nWorkspace clippy / fmt / test all green; 102 clickup tests (94 +\nexisting 5 status + 2 new + 1 epic).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(clickup): address PR #290 review (epic status + error hints + DRY)",
          "author_name": "Mikhail KItaev",
          "author_login": null,
          "committed_at": "2026-05-26T03:43:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "31f9cf49c0c9f39f4b02bd5cee45daacd502f46f",
          "body": "…287)\n\nAddress review feedback on PR #289:\n\n- resolve_assignee_ids: spell out the three resolution paths (numeric\n  ID pass-through with no verification, /team lookup with case-\n  insensitive email/username match, fail-loud on unresolvable). Notes\n  why numeric IDs skip the workspace fetch and the A\n[…]\nctical\n  impact is small because assignee changes are rare and idempotent.\n\nBehavior unchanged; 8 / 8 assignees tests still green.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(clickup): clarify assignee resolution semantics + race window (#…",
          "author_name": "Mikhail KItaev",
          "author_login": null,
          "committed_at": "2026-05-26T03:38:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d72b6c10ad704e351cffa1291d7ebe129f9b31e9",
          "body": "…rver instance",
          "is_bot": false,
          "headline": "test(telegram): refactor search_messages tests to use a single MockSe…",
          "author_name": "mikhailova-klavdia",
          "author_login": "mikhailova-klavdia",
          "committed_at": "2026-05-25T22:06:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a5128e3a2ea6bacaa0b2d42797c1073ddb28d60d",
          "body": "…update handling",
          "is_bot": false,
          "headline": "refactor(telegram): simplify filter logic and improve readability in …",
          "author_name": "mikhailova-klavdia",
          "author_login": "mikhailova-klavdia",
          "committed_at": "2026-05-25T21:48:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "521e6c733fc7dec35d51de2cb0250d62e50d1c97",
          "body": "…te handling",
          "is_bot": false,
          "headline": "feat(telegram): enhance TelegramClient with state management and upda…",
          "author_name": "mikhailova-klavdia",
          "author_login": "mikhailova-klavdia",
          "committed_at": "2026-05-25T21:48:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9619675728b2c4ef0e5b9a5dce2a7074930966e7",
          "body": null,
          "is_bot": false,
          "headline": "feat(telegram): add Telegram provider tests and configuration handling",
          "author_name": "mikhailova-klavdia",
          "author_login": "mikhailova-klavdia",
          "committed_at": "2026-05-25T21:39:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f9a3dd40f02d875fdd72788bc1722519f9acf518",
          "body": "The unified update_issue MCP tool exposed only a generic\nstate: enum(\"open\", \"closed\") field. ClickUp custom statuses like\n\"in progress\", \"review\", or any list-defined status were unreachable\nthrough the MCP layer — callers had to open the ClickUp UI to move a\ntask forward in its workflow. This bloc\n[…]\n mapping are scoped to follow-up PRs.\n\nWorkspace clippy clean, fmt clean, 99 / 99 clickup tests + full\nworkspace test suite green.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(clickup): support setting custom statuses via update_issue (#288)",
          "author_name": "Mikhail KItaev",
          "author_login": null,
          "committed_at": "2026-05-25T13:06:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c79180acf44c0f728a054aaa67c8170b6e43c731",
          "body": "ClickUp's PUT /task/:id silently ignored the assignees field because the\nunderlying UpdateTaskRequest struct didn't declare it. POST /task also\nhardcoded assignees: None. Result: any assignees passed via the unified\nupdate_issue / create_issue MCP tool were dropped on the floor with a\n200 OK — silen\n[…]\nomits the field\n   - unknown email fails before PUT\n   - POST sends flat array\n\n102/102 clickup tests green (94 existing + 8 new).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(clickup): wire assignees through PUT/POST /task (#287)",
          "author_name": "Mikhail KItaev",
          "author_login": null,
          "committed_at": "2026-05-25T12:57:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "db74a11a70fef393feb0b64870c5d34da4bc803b",
          "body": null,
          "is_bot": false,
          "headline": "doc(telegram): update provider count and add Telegram to messenger tools",
          "author_name": "mikhailova-klavdia",
          "author_login": "mikhailova-klavdia",
          "committed_at": "2026-05-21T10:51:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ec91ac083cd6ae70e5fc38c2c6bea96bb8239c0b",
          "body": "… tracing dependency",
          "is_bot": false,
          "headline": "feat(telegram): add Telegram provider configuration and remove unused…",
          "author_name": "mikhailova-klavdia",
          "author_login": "mikhailova-klavdia",
          "committed_at": "2026-05-21T10:42:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "62c884fb85d121096d5801dd6ecc9d5e93fa056f",
          "body": "…to feat/86-add-telegram-messenger-provider",
          "is_bot": false,
          "headline": "Merge branch 'main' of https://github.com/meteora-pro/devboy-tools in…",
          "author_name": "mikhailova-klavdia",
          "author_login": "mikhailova-klavdia",
          "committed_at": "2026-05-21T09:47:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "48d2765527f615d8caa62bdbb1f7537f154dbc49",
          "body": null,
          "is_bot": false,
          "headline": "feat(telegram): add Telegram provider to workspace and CLI",
          "author_name": "mikhailova-klavdia",
          "author_login": "mikhailova-klavdia",
          "committed_at": "2026-05-21T09:45:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b51e6bffc1b535c8bddb9cb37aa423757c1e74eb",
          "body": "…dispatch\n\nfix(confluence): KB dispatch + self-hosted Server payloads + with_instance_url",
          "is_bot": false,
          "headline": "Merge pull request #286 from meteora-pro/fix/confluence-proxy-and-kb-…",
          "author_name": "qumagis",
          "author_login": "qumagis",
          "committed_at": "2026-05-20T17:56:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9cc414ba52affc46720583addaef35c52f38b81e",
          "body": "…pi baseline\n\nThree review comments and the public-api CI gate:\n\n1. **`send_json` body allocation** (review on `client.rs:297`). Switched\n   from `response.text()` + `serde_json::from_str` to `response.bytes()`\n   + `serde_json::from_slice`, so the happy path skips the extra UTF-8\n   validation pass\n[…]\nnst\na real self-hosted Confluence Server — 100 spaces, all URLs on the\nreal instance host (same as before, because `_links.base` echoes the\nreal host in non-proxy deployments).\n\nRefs: gh#285, PR #286.",
          "is_bot": false,
          "headline": "fix(confluence): address PR #286 Copilot review + regenerate public-a…",
          "author_name": "Maxim Dymov",
          "author_login": "qumagis",
          "committed_at": "2026-05-20T17:44:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5cd315cb06cc1243709eb9a3d2da16480f4d37e3",
          "body": "Mirrors `JiraClient::with_instance_url`. Splits two roles previously\nserved by `base_url`:\n\n- **`base_url`** — API target. Stays the proxy host in proxy mode so\n  every request transits the proxy.\n- **`instance_url`** — host used to render browse links\n  (`_links.webui`, `/pages/<id>`). Stays the re\n[…]\nt_providers` reading\n`proxy_mcp_servers` to derive a Confluence HTTP proxy) is out of\nscope here — the schema has no Confluence HTTP-proxy section yet.\nTracked as a follow-up in gh#285.\n\nRefs: gh#285.",
          "is_bot": false,
          "headline": "feat(confluence): with_instance_url + browse-link host separation",
          "author_name": "Maxim Dymov",
          "author_login": "qumagis",
          "committed_at": "2026-05-20T17:24:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "872094eb3bac795d4bfa20426504300e14efc7c7",
          "body": "…teger ids\n\nThree coupled bugs that combined to surface as a misleading\n\"No knowledge base provider supports '<tool>'\" against self-hosted\nConfluence Server / Data Center:\n\n1. **dispatch_builtin_tool** (KB/messenger/meeting arms) used\n   `Err(e) => continue` unconditionally, swallowing real errors f\n[…]\ner id.\n- `send_json_decode_failure_surfaces_status_and_body_preview` — 200\n  OK + HTML body must produce a diagnostic error message.\n\nRefs: gh#285 (Confluence proxy / KB dispatch / self-hosted reads).",
          "is_bot": false,
          "headline": "fix(confluence,mcp): KB dispatch hides real errors + accept Server in…",
          "author_name": "Maxim Dymov",
          "author_login": "qumagis",
          "committed_at": "2026-05-20T17:20:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9d736f202873ee3ae30a8b5d20d04f9d7d731f7a",
          "body": "feat(secrets): implement secret framework — ADR-020/021/023 (epic #247, full history)",
          "is_bot": false,
          "headline": "Merge pull request #265 from meteora-pro/epic/247-secret-framework-impl",
          "author_name": "ai-dev-2-meteora-pro",
          "author_login": "ai-dev-2-meteora-pro",
          "committed_at": "2026-05-18T22:03:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2d4cad3a4e9ff45895569b13cc6b1e854e48a7be",
          "body": "CI's `Unused deps (cargo-machete)` flagged `tokio` in\ncrates/devboy-secrets-ui-bin/Cargo.toml — the only reference in\nthe bin's source is now a doc comment (\"…switch to\ntokio::spawn_blocking\" on the attachment-save path), not a real\nuse. The HTTP-Vault block_on() path that needed tokio was\nremoved i\n[…]\ned; the failure\nwas the Swatinem/rust-cache@v2 post-step uploading the cache.\nTransient infrastructural; the next push retries it.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(ci): drop unused tokio dep from devboy-secrets-ui-bin (DEV-247)",
          "author_name": "Slava Kazarinov",
          "author_login": "slavik-kazarinov",
          "committed_at": "2026-05-18T10:10:17Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8f50096ab3c195ad54c93ea53e8fc123920ee2d7",
          "body": "Five reviewable items from the inline review on PR #265.\nAll have regression tests; only R5 doesn't add a test (the\nfix is a single RegexBuilder swap with no observable behaviour\ndifference on legitimate inputs).\n\nR1 MED — verify_fresh_unlock TOCTOU/stale-state\n  crates/devboy-secrets-agent/src/serv\n[…]\nev-dependency with the async_closure\n  feature.\n\nBuild green, fmt clean, clippy -D warnings clean, all 1800+\nworkspace tests pass.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(secrets): address 5 PR-265 review findings (R1-R6) (DEV-247)",
          "author_name": "Slava Kazarinov",
          "author_login": "slavik-kazarinov",
          "committed_at": "2026-05-18T09:11:18Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3be04a43825be01b7245297e10af4506f22daf22",
          "body": "…DEV-247)\n\nCI's Windows test runner caught a Unix-only assumption in\n`derive_working_copy_path_drops_into_source_dir_with_timestamp`\n— the assertion did a string prefix match against\n`/tmp/x.devboy-working-`, which fails on Windows where the\n`PathBuf::with_file_name` call returns `/tmp\\x.devboy-work\n[…]\nand\n`p.file_name()` so the test passes regardless of how the OS\nchooses to spell the separator. Underlying behaviour is\nunchanged.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(secrets-kdbx): cross-platform path test for working-copy helper (…",
          "author_name": "Slava Kazarinov",
          "author_login": "slavik-kazarinov",
          "committed_at": "2026-05-17T22:17:47Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "22490feecd8f40fa320f321986515cee6d8d1fb4",
          "body": "…ne (DEV-247)\n\nPR #265 CI's `Public API drift (cargo-public-api)` flagged\ndevboy-gitlab: my earlier squash inadvertently dropped main's\n`AuthScheme` refactor (PAT vs OAuth header detection, #263).\n\nResolution:\n* Reset `crates/plugins/api/gitlab/src/client.rs` to the main\n  version (restores `AuthSch\n[…]\ntlab/.public-api/baseline.txt`\n— only legitimate addition is `pub mod devboy_gitlab::liveness`\n(the epic's liveness probe module).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci): restore main's AuthScheme in gitlab, regen public-api baseli…",
          "author_name": "Slava Kazarinov",
          "author_login": "slavik-kazarinov",
          "committed_at": "2026-05-17T22:04:39Z",
          "body_truncated": true,
          "is_coding_agent": true
        }
      ],
      "releases_count": 39,
      "commits_last_year": 1798,
      "latest_release_at": "2026-07-25T12:01:23Z",
      "latest_release_tag": "v0.32.0",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 22,
      "days_since_latest_release": 0,
      "mean_days_between_releases": 9.1
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 62,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "devboy-cli",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [
            "ai-agents",
            "cli",
            "devboy",
            "developer-tools",
            "mcp",
            "command-line-utilities",
            "development-tools"
          ],
          "ecosystem": "crates",
          "matches_repo": true,
          "registry_url": "https://crates.io/crates/devboy-cli",
          "is_deprecated": false,
          "latest_version": "0.28.1",
          "repository_url": "https://github.com/meteora-pro/devboy-tools",
          "versions_count": 3,
          "total_downloads": 55,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 18,
          "first_published_at": "2026-05-09T23:14:17.755383Z",
          "latest_published_at": "2026-05-17T19:34:36.553031Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 68
        },
        {
          "name": "devboy-mcp",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [
            "ai-agents",
            "claude",
            "devboy",
            "json-rpc",
            "mcp",
            "api-bindings",
            "development-tools"
          ],
          "ecosystem": "crates",
          "matches_repo": true,
          "registry_url": "https://crates.io/crates/devboy-mcp",
          "is_deprecated": false,
          "latest_version": "0.28.1",
          "repository_url": "https://github.com/meteora-pro/devboy-tools",
          "versions_count": 3,
          "total_downloads": 95,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 32,
          "first_published_at": "2026-05-09T22:54:14.779703Z",
          "latest_published_at": "2026-05-17T19:33:31.467335Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 68
        },
        {
          "name": "devboy-core",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [
            "ai-agents",
            "devboy",
            "developer-tools",
            "mcp",
            "providers",
            "api-bindings",
            "development-tools"
          ],
          "ecosystem": "crates",
          "matches_repo": true,
          "registry_url": "https://crates.io/crates/devboy-core",
          "is_deprecated": false,
          "latest_version": "0.32.0",
          "repository_url": "https://github.com/meteora-pro/devboy-tools",
          "versions_count": 11,
          "total_downloads": 7064,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 2355,
          "first_published_at": "2026-05-09T21:33:35.173319Z",
          "latest_published_at": "2026-07-25T09:41:09.017534Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 0
        },
        {
          "name": "@devboy-tools/cli",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [
            "mcp",
            "model-context-protocol",
            "devboy",
            "code-review",
            "ai-agent",
            "gitlab",
            "github",
            "clickup",
            "jira"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@devboy-tools/cli",
          "is_deprecated": false,
          "latest_version": "0.32.0",
          "repository_url": "https://github.com/meteora-pro/devboy-tools",
          "versions_count": 39,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 2,
          "monthly_downloads": 435,
          "first_published_at": "2026-02-19T18:20:44.705000Z",
          "latest_published_at": "2026-07-25T12:02:20.476000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 0
        },
        {
          "name": "devboy-assets",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [
            "ai-agents",
            "assets",
            "cache",
            "devboy",
            "filesystem",
            "development-tools",
            "caching",
            "filesystem"
          ],
          "ecosystem": "crates",
          "matches_repo": true,
          "registry_url": "https://crates.io/crates/devboy-assets",
          "is_deprecated": false,
          "latest_version": "0.32.0",
          "repository_url": "https://github.com/meteora-pro/devboy-tools",
          "versions_count": 9,
          "total_downloads": 6525,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 2175,
          "first_published_at": "2026-05-09T21:34:25.421466Z",
          "latest_published_at": "2026-07-25T09:42:50.457971Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 0
        },
        {
          "name": "devboy-skills",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [
            "ai-agents",
            "claude",
            "devboy",
            "manifest",
            "skills",
            "development-tools",
            "parser-implementations"
          ],
          "ecosystem": "crates",
          "matches_repo": true,
          "registry_url": "https://crates.io/crates/devboy-skills",
          "is_deprecated": false,
          "latest_version": "0.32.0",
          "repository_url": "https://github.com/meteora-pro/devboy-tools",
          "versions_count": 4,
          "total_downloads": 98,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 33,
          "first_published_at": "2026-05-09T23:04:11.524448Z",
          "latest_published_at": "2026-07-25T12:12:43.795419Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 0
        },
        {
          "name": "devboy-storage",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [
            "credentials",
            "devboy",
            "keychain",
            "secrets",
            "storage",
            "authentication",
            "development-tools",
            "os"
          ],
          "ecosystem": "crates",
          "matches_repo": true,
          "registry_url": "https://crates.io/crates/devboy-storage",
          "is_deprecated": false,
          "latest_version": "0.32.0",
          "repository_url": "https://github.com/meteora-pro/devboy-tools",
          "versions_count": 9,
          "total_downloads": 199,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 66,
          "first_published_at": "2026-05-09T21:33:57.151193Z",
          "latest_published_at": "2026-07-25T09:42:28.108262Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 0
        }
      ]
    },
    "popularity": {
      "forks": 4,
      "stars": 13,
      "watchers": 0,
      "fork_history": {
        "days": [
          {
            "date": "2026-02-16",
            "count": 1
          },
          {
            "date": "2026-03-11",
            "count": 1
          },
          {
            "date": "2026-03-27",
            "count": 1
          },
          {
            "date": "2026-06-08",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 4,
        "total_forks": 4
      },
      "star_history": null,
      "open_issues_and_prs": 51
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples",
        "notebooks"
      ],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": true,
      "bootstrap_files": [
        "docs/research/paper1-repro/Makefile"
      ],
      "api_schema_files": [],
      "has_devcontainer": true,
      "typecheck_configs": [
        "docs/tsconfig.json"
      ],
      "toolchain_manifests": [
        "Cargo.toml",
        "crates/devboy-assets/Cargo.toml",
        "crates/devboy-cli/Cargo.toml",
        "crates/devboy-core/Cargo.toml",
        "crates/devboy-executor/Cargo.toml",
        "crates/devboy-mcp/Cargo.toml",
        "crates/devboy-secret-patterns/Cargo.toml",
        "crates/devboy-secrets-agent/Cargo.toml",
        "crates/devboy-secrets-ui-bin/Cargo.toml",
        "crates/devboy-secrets-ui/Cargo.toml",
        "crates/devboy-skills/Cargo.toml",
        "crates/devboy-storage/Cargo.toml",
        "crates/devboy-token-catalog/Cargo.toml",
        "crates/devboy-vault-crypto/Cargo.toml",
        "crates/llm-eval/Cargo.toml",
        "crates/plugins/api/clickup/Cargo.toml",
        "crates/plugins/api/confluence/Cargo.toml",
        "crates/plugins/api/fireflies/Cargo.toml",
        "crates/plugins/api/github/Cargo.toml",
        "crates/plugins/api/gitlab/Cargo.toml",
        "crates/plugins/api/jira/Cargo.toml",
        "crates/plugins/api/slack/Cargo.toml",
        "crates/plugins/api/telegram/Cargo.toml",
        "crates/plugins/format-pipeline/Cargo.toml",
        "crates/plugins/secrets/1password/Cargo.toml",
        "crates/plugins/secrets/env-store/Cargo.toml",
        "crates/plugins/secrets/kdbx/Cargo.toml",
        "crates/plugins/secrets/keychain/Cargo.toml",
        "crates/plugins/secrets/local-vault/Cargo.toml",
        "crates/plugins/secrets/vault/Cargo.toml"
      ],
      "largest_source_bytes": 381128,
      "source_files_sampled": 329,
      "oversized_source_files": 22,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "Cargo.toml",
        "docs/package.json"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "crates",
        "npm"
      ],
      "dependencies": [
        {
          "name": "devboy-core",
          "manifest": "crates/devboy-assets/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "thiserror",
          "manifest": "crates/devboy-assets/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/devboy-assets/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_json",
          "manifest": "crates/devboy-assets/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tracing",
          "manifest": "crates/devboy-assets/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "toml",
          "manifest": "crates/devboy-assets/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "dirs",
          "manifest": "crates/devboy-assets/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "sha2",
          "manifest": "crates/devboy-assets/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tempfile",
          "manifest": "crates/devboy-assets/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-core",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-executor",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-mcp",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-storage",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-secret-patterns",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-secrets-agent",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-secrets-ui",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-token-catalog",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "regex",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "ratatui",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.30"
        },
        {
          "name": "crossterm",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.28"
        },
        {
          "name": "devboy-secret-keychain",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-secret-local-vault",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-secret-1password",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-secret-kdbx",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-secret-env-store",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-github",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-gitlab",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-clickup",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-jira",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-confluence",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-fireflies",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-slack",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-telegram",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-format-pipeline",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-skills",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_yaml",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.9"
        },
        {
          "name": "tokio",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_json",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "clap",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "clap-markdown",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.1"
        },
        {
          "name": "tracing",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tracing-subscriber",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "anyhow",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "async-trait",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "futures",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "reqwest",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "dialoguer",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.11"
        },
        {
          "name": "chrono",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4"
        },
        {
          "name": "toml",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "dirs",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "flate2",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.1"
        },
        {
          "name": "tar",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4"
        },
        {
          "name": "zip",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "8.4"
        },
        {
          "name": "secrecy",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "sentry",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "sentry-tracing",
          "manifest": "crates/devboy-cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "thiserror",
          "manifest": "crates/devboy-core/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "anyhow",
          "manifest": "crates/devboy-core/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/devboy-core/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_json",
          "manifest": "crates/devboy-core/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "async-trait",
          "manifest": "crates/devboy-core/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tracing",
          "manifest": "crates/devboy-core/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "toml",
          "manifest": "crates/devboy-core/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "dirs",
          "manifest": "crates/devboy-core/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "reqwest",
          "manifest": "crates/devboy-core/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "url",
          "manifest": "crates/devboy-core/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "secrecy",
          "manifest": "crates/devboy-core/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "sentry",
          "manifest": "crates/devboy-core/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "chrono",
          "manifest": "crates/devboy-core/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4"
        },
        {
          "name": "which",
          "manifest": "crates/devboy-core/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "8.0"
        },
        {
          "name": "devboy-core",
          "manifest": "crates/devboy-executor/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-assets",
          "manifest": "crates/devboy-executor/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-gitlab",
          "manifest": "crates/devboy-executor/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-github",
          "manifest": "crates/devboy-executor/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-clickup",
          "manifest": "crates/devboy-executor/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-jira",
          "manifest": "crates/devboy-executor/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-confluence",
          "manifest": "crates/devboy-executor/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-fireflies",
          "manifest": "crates/devboy-executor/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-slack",
          "manifest": "crates/devboy-executor/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-telegram",
          "manifest": "crates/devboy-executor/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-format-pipeline",
          "manifest": "crates/devboy-executor/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tokio",
          "manifest": "crates/devboy-executor/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/devboy-executor/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_json",
          "manifest": "crates/devboy-executor/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "async-trait",
          "manifest": "crates/devboy-executor/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tracing",
          "manifest": "crates/devboy-executor/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "thiserror",
          "manifest": "crates/devboy-executor/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "base64",
          "manifest": "crates/devboy-executor/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.22"
        },
        {
          "name": "secrecy",
          "manifest": "crates/devboy-executor/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-core",
          "manifest": "crates/devboy-mcp/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-assets",
          "manifest": "crates/devboy-mcp/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-executor",
          "manifest": "crates/devboy-mcp/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-confluence",
          "manifest": "crates/devboy-mcp/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-format-pipeline",
          "manifest": "crates/devboy-mcp/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-storage",
          "manifest": "crates/devboy-mcp/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-secret-kdbx",
          "manifest": "crates/devboy-mcp/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "chrono",
          "manifest": "crates/devboy-mcp/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4"
        },
        {
          "name": "tokio",
          "manifest": "crates/devboy-mcp/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/devboy-mcp/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_json",
          "manifest": "crates/devboy-mcp/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tracing",
          "manifest": "crates/devboy-mcp/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "reqwest",
          "manifest": "crates/devboy-mcp/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "reqwest-eventsource",
          "manifest": "crates/devboy-mcp/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "futures",
          "manifest": "crates/devboy-mcp/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tokio-util",
          "manifest": "crates/devboy-mcp/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.7"
        },
        {
          "name": "async-trait",
          "manifest": "crates/devboy-mcp/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "thiserror",
          "manifest": "crates/devboy-mcp/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "secrecy",
          "manifest": "crates/devboy-mcp/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "thiserror",
          "manifest": "crates/devboy-secret-patterns/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/devboy-secret-patterns/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "toml",
          "manifest": "crates/devboy-secret-patterns/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "regex",
          "manifest": "crates/devboy-secret-patterns/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tracing",
          "manifest": "crates/devboy-secret-patterns/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-vault-crypto",
          "manifest": "crates/devboy-secrets-agent/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "thiserror",
          "manifest": "crates/devboy-secrets-agent/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/devboy-secrets-agent/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_json",
          "manifest": "crates/devboy-secrets-agent/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tokio",
          "manifest": "crates/devboy-secrets-agent/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tracing",
          "manifest": "crates/devboy-secrets-agent/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "secrecy",
          "manifest": "crates/devboy-secrets-agent/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "dirs",
          "manifest": "crates/devboy-secrets-agent/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-secrets-ui",
          "manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-storage",
          "manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-token-catalog",
          "manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-vault-crypto",
          "manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-secret-patterns",
          "manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-secret-vault",
          "manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-secret-kdbx",
          "manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "eframe",
          "manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.34"
        },
        {
          "name": "egui_kittest",
          "manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.34.2"
        },
        {
          "name": "image",
          "manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.25"
        },
        {
          "name": "anyhow",
          "manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "clap",
          "manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "secrecy",
          "manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "regex",
          "manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "reqwest",
          "manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "dirs",
          "manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "toml",
          "manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "rfd",
          "manifest": "crates/devboy-secrets-ui-bin/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.15"
        },
        {
          "name": "secrecy",
          "manifest": "crates/devboy-secrets-ui/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "chrono",
          "manifest": "crates/devboy-secrets-ui/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4"
        },
        {
          "name": "ratatui",
          "manifest": "crates/devboy-secrets-ui/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.30"
        },
        {
          "name": "crossterm",
          "manifest": "crates/devboy-secrets-ui/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.28"
        },
        {
          "name": "egui",
          "manifest": "crates/devboy-secrets-ui/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.34"
        },
        {
          "name": "thiserror",
          "manifest": "crates/devboy-skills/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/devboy-skills/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_json",
          "manifest": "crates/devboy-skills/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "async-trait",
          "manifest": "crates/devboy-skills/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "dirs",
          "manifest": "crates/devboy-skills/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "sha2",
          "manifest": "crates/devboy-skills/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_yaml",
          "manifest": "crates/devboy-skills/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.9"
        },
        {
          "name": "rust-embed",
          "manifest": "crates/devboy-skills/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "8.5"
        },
        {
          "name": "chrono",
          "manifest": "crates/devboy-skills/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4"
        },
        {
          "name": "ulid",
          "manifest": "crates/devboy-skills/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.1"
        },
        {
          "name": "devboy-core",
          "manifest": "crates/devboy-storage/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-secret-patterns",
          "manifest": "crates/devboy-storage/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "thiserror",
          "manifest": "crates/devboy-storage/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/devboy-storage/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_json",
          "manifest": "crates/devboy-storage/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "toml",
          "manifest": "crates/devboy-storage/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tracing",
          "manifest": "crates/devboy-storage/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "dirs",
          "manifest": "crates/devboy-storage/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "secrecy",
          "manifest": "crates/devboy-storage/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "async-trait",
          "manifest": "crates/devboy-storage/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "bitflags",
          "manifest": "crates/devboy-storage/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "2.6"
        },
        {
          "name": "regex",
          "manifest": "crates/devboy-storage/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "chrono",
          "manifest": "crates/devboy-storage/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4"
        },
        {
          "name": "sha2",
          "manifest": "crates/devboy-storage/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "hex",
          "manifest": "crates/devboy-storage/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4"
        },
        {
          "name": "tokio",
          "manifest": "crates/devboy-storage/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/devboy-token-catalog/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_json",
          "manifest": "crates/devboy-token-catalog/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "thiserror",
          "manifest": "crates/devboy-token-catalog/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "dirs",
          "manifest": "crates/devboy-token-catalog/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "toml",
          "manifest": "crates/devboy-token-catalog/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "reqwest",
          "manifest": "crates/devboy-token-catalog/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "sha2",
          "manifest": "crates/devboy-token-catalog/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "chrono",
          "manifest": "crates/devboy-token-catalog/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4"
        },
        {
          "name": "rust-embed",
          "manifest": "crates/devboy-token-catalog/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "8"
        },
        {
          "name": "thiserror",
          "manifest": "crates/devboy-vault-crypto/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde",
          "manifest": "crates/devboy-vault-crypto/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "secrecy",
          "manifest": "crates/devboy-vault-crypto/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "zeroize",
          "manifest": "crates/devboy-vault-crypto/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.8"
        },
        {
          "name": "toml",
          "manifest": "crates/devboy-vault-crypto/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "base64",
          "manifest": "crates/devboy-vault-crypto/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "tempfile",
          "manifest": "crates/devboy-vault-crypto/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "chacha20poly1305",
          "manifest": "crates/devboy-vault-crypto/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "getrandom",
          "manifest": "crates/devboy-vault-crypto/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "argon2",
          "manifest": "crates/devboy-vault-crypto/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "bip39",
          "manifest": "crates/devboy-vault-crypto/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "hkdf",
          "manifest": "crates/devboy-vault-crypto/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "sha2",
          "manifest": "crates/devboy-vault-crypto/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "devboy-format-pipeline",
          "manifest": "crates/llm-eval/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "anyhow",
          "manifest": "crates/llm-eval/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "serde_json",
          "manifest": "crates/llm-eval/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "reqwest",
          "manifest": "crates/llm-eval/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "secrecy",
          "manifest": "crates/llm-eval/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 6,
        "merged_prs": 123,
        "open_issues": 45,
        "closed_ratio": 0.729,
        "closed_issues": 121,
        "closed_unmerged_prs": 15
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "slavik-kazarinov",
          "commits": 1081,
          "avatar_url": "https://avatars.githubusercontent.com/u/126971369?v=4"
        },
        {
          "type": "User",
          "login": "qumagis",
          "commits": 339,
          "avatar_url": "https://avatars.githubusercontent.com/u/126944225?v=4"
        },
        {
          "type": "User",
          "login": "andreymaznyak",
          "commits": 119,
          "avatar_url": "https://avatars.githubusercontent.com/u/4545924?v=4"
        },
        {
          "type": "User",
          "login": "mikhailova-klavdia",
          "commits": 98,
          "avatar_url": "https://avatars.githubusercontent.com/u/114179767?v=4"
        },
        {
          "type": "User",
          "login": "ai-dev-2-meteora-pro",
          "commits": 91,
          "avatar_url": "https://avatars.githubusercontent.com/u/207333965?v=4"
        },
        {
          "type": "User",
          "login": "mikhkit",
          "commits": 34,
          "avatar_url": "https://avatars.githubusercontent.com/u/12929152?v=4"
        },
        {
          "type": "User",
          "login": "mkitaev",
          "commits": 24,
          "avatar_url": "https://avatars.githubusercontent.com/u/26816897?v=4"
        }
      ],
      "contributors_sampled": 7,
      "top_contributor_share": 0.605
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "deploy-docs.yml",
        "fixtures-update.yml",
        "release-crates-io.yml",
        "release.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        "biome.json"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "pnpm-lock.yaml"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "5 out of 5 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/5 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 6,
            "reason": "project has 2 contributing companies or organizations -- score normalized to 6",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 21 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "21 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "4444f7986b29b07d24791a86f2cc84e123ec6a4c",
        "ran_at": "2026-07-25T13:14:27Z",
        "aggregate_score": 3.5,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-25T12:14:05Z",
      "oldest_open_prs": [
        {
          "number": 249,
          "created_at": "2026-05-07T21:51:47Z",
          "last_comment_at": "2026-05-07T21:54:13Z",
          "last_comment_author": "codecov"
        },
        {
          "number": 293,
          "created_at": "2026-05-28T16:13:15Z",
          "last_comment_at": "2026-05-28T16:22:23Z",
          "last_comment_author": "codecov"
        },
        {
          "number": 296,
          "created_at": "2026-06-08T00:42:06Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 299,
          "created_at": "2026-06-21T23:45:57Z",
          "last_comment_at": "2026-06-30T23:15:08Z",
          "last_comment_author": "codecov"
        },
        {
          "number": 304,
          "created_at": "2026-06-30T22:37:38Z",
          "last_comment_at": "2026-07-01T00:30:19Z",
          "last_comment_author": "codecov"
        },
        {
          "number": 305,
          "created_at": "2026-07-09T00:28:52Z",
          "last_comment_at": "2026-07-09T00:33:59Z",
          "last_comment_author": "codecov"
        }
      ],
      "last_merged_pr_at": "2026-07-25T12:02:48Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 64,
          "created_at": "2026-03-26T10:28:49Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 65,
          "created_at": "2026-03-26T10:29:59Z",
          "last_comment_at": "2026-05-02T21:17:00Z",
          "last_comment_author": "andreymaznyak"
        },
        {
          "number": 68,
          "created_at": "2026-03-26T17:38:45Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 69,
          "created_at": "2026-03-26T17:39:00Z",
          "last_comment_at": "2026-05-02T21:17:42Z",
          "last_comment_author": "andreymaznyak"
        },
        {
          "number": 73,
          "created_at": "2026-03-27T15:09:22Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 87,
          "created_at": "2026-03-28T20:09:54Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 88,
          "created_at": "2026-03-28T20:10:05Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 89,
          "created_at": "2026-03-28T20:10:17Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 90,
          "created_at": "2026-03-28T20:10:34Z",
          "last_comment_at": "2026-05-02T21:17:02Z",
          "last_comment_author": "andreymaznyak"
        },
        {
          "number": 99,
          "created_at": "2026-03-30T08:41:41Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 100,
          "created_at": "2026-03-30T08:41:51Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 112,
          "created_at": "2026-04-03T08:44:06Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 120,
          "created_at": "2026-04-10T21:23:47Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 124,
          "created_at": "2026-04-10T21:24:28Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 125,
          "created_at": "2026-04-11T09:31:34Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 210,
          "created_at": "2026-04-26T21:59:23Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 211,
          "created_at": "2026-04-28T03:46:50Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 213,
          "created_at": "2026-04-30T06:17:53Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 240,
          "created_at": "2026-05-04T17:18:56Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 241,
          "created_at": "2026-05-04T17:19:23Z",
          "last_comment_at": "2026-06-21T06:09:52Z",
          "last_comment_author": "Necmttn"
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/meteora-pro/devboy-tools",
    "host": "github.com",
    "name": "devboy-tools",
    "owner": "meteora-pro"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "at_risk",
      "name": "Overall health",
      "note": "High-Risk Jurisdiction Policy applies a 50% multiplier to weighted overall health and gives it an At risk ceiling of 49.",
      "notes": [
        {
          "code": "jurisdiction_overall_adjustment",
          "params": {
            "cap": 49,
            "pct": 50
          }
        }
      ],
      "value": 31,
      "inputs": {
        "security": 18,
        "vitality": 83,
        "community": 49,
        "governance": 60,
        "engineering": 86,
        "high_risk_jurisdiction_cap": 49,
        "high_risk_jurisdiction_multiplier": 50,
        "weighted_overall_before_jurisdiction": 62,
        "overall_after_jurisdiction_multiplier": 31
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 83,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 79,
            "inputs": {
              "commits_last_year": 1798,
              "human_commit_share": 1,
              "days_since_last_push": 0,
              "active_weeks_last_year": 22
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "22/52 weeks with commits",
                "points": 15.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 22
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "1798 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 1798
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 21 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 39,
              "latest_release_tag": "v0.32.0",
              "releases_from_tags": false,
              "days_since_latest_release": 0,
              "mean_days_between_releases": 9.1
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "39 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 39
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~9.1 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 9.1
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 0,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 0 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 49,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 22,
            "inputs": {
              "forks": 4,
              "stars": 13,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "13 stars",
                "points": 17.5,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 13
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "4 forks",
                "points": 4,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "good",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 70,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 62,
            "inputs": {
              "packages": [
                "devboy-cli",
                "devboy-mcp",
                "devboy-core",
                "@devboy-tools/cli",
                "devboy-assets",
                "devboy-skills",
                "devboy-storage"
              ],
              "dependents": null,
              "ecosystems": "crates, npm",
              "total_downloads": 14036,
              "monthly_downloads": 5114
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "5,114 downloads/month across crates, npm",
                "points": 49.5,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 5114,
                      "ecosystems": "crates, npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 60,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "at_risk",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 33,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 7,
              "top_contributor_share": 0.605
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 60% of commits",
                "points": 8.9,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 60
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "7 contributors",
                "points": 9.5,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "moderate",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "merged_prs": 123,
              "open_issues": 45,
              "closed_issues": 121,
              "issue_closed_ratio": 0.729,
              "closed_unmerged_prs": 15
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "73% of issues closed",
                "points": 34.1,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 73
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "123/138 decided PRs merged",
                "points": 34.1,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 123,
                      "decided": 138
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/5 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 54,
            "inputs": {
              "followers": 4,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "meteora-pro",
              "public_repos": 9,
              "account_age_days": 2118
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "4 followers of meteora-pro",
                "points": 5,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 4,
                      "login": "meteora-pro"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "9 public repos, account ~5 yr old",
                "points": 18.9,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 9
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 5
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "devboy-cli",
                "devboy-mcp",
                "devboy-core",
                "@devboy-tools/cli",
                "devboy-assets",
                "devboy-skills",
                "devboy-storage"
              ],
              "ecosystems": "crates, npm",
              "any_deprecated": false,
              "min_days_since_publish": 0
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "7 package(s) on crates, npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 7,
                      "ecosystems": "crates, npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 0 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "39 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 39
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "excellent",
        "name": "Engineering Quality",
        "value": 86,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "5 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": "biome.json",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "biome.json"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "5 out of 5 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": "https://meteora-pro.github.io/devboy-tools/",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://meteora-pro.github.io/devboy-tools/",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "critical",
        "name": "Security",
        "value": 18,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "critical",
            "name": "Security posture",
            "note": "High-Risk Jurisdiction Policy applies a 50% multiplier to Security posture and gives it an At risk ceiling of 49.",
            "notes": [
              {
                "code": "jurisdiction_posture_adjustment",
                "params": {
                  "cap": 49,
                  "pct": 50
                }
              }
            ],
            "value": 18,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 18,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 0,
              "scorecard_aggregate": 3.5,
              "high_risk_jurisdiction_cap": 49,
              "high_risk_jurisdiction_multiplier": 50,
              "security_posture_after_multiplier": 18,
              "security_posture_before_jurisdiction": 35
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "5 out of 5 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/5 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 21 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "21 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "moderate",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 50,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": true,
              "exposures": [
                {
                  "role": "top_contributor",
                  "count": 1,
                  "country": "Russia"
                }
              ],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "Russia: top_contributor (1)",
                "points": 50,
                "status": "partial",
                "details": [
                  {
                    "code": "jurisdiction_exposure",
                    "params": {
                      "role": "top_contributor",
                      "count": 1,
                      "country": "Russia"
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 68,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.96,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "96 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 96,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 82,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "pnpm-lock.yaml"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [
                "docs/research/paper1-repro/Makefile"
              ],
              "has_devcontainer": true,
              "has_linter_config": true,
              "typecheck_configs": [
                "docs/tsconfig.json"
              ],
              "agent_commit_share": 0.61,
              "toolchain_manifests": [
                "Cargo.toml",
                "crates/devboy-assets/Cargo.toml",
                "crates/devboy-cli/Cargo.toml",
                "crates/devboy-core/Cargo.toml",
                "crates/devboy-executor/Cargo.toml",
                "crates/devboy-mcp/Cargo.toml",
                "crates/devboy-secret-patterns/Cargo.toml",
                "crates/devboy-secrets-agent/Cargo.toml",
                "crates/devboy-secrets-ui-bin/Cargo.toml",
                "crates/devboy-secrets-ui/Cargo.toml",
                "crates/devboy-skills/Cargo.toml",
                "crates/devboy-storage/Cargo.toml",
                "crates/devboy-token-catalog/Cargo.toml",
                "crates/devboy-vault-crypto/Cargo.toml",
                "crates/llm-eval/Cargo.toml",
                "crates/plugins/api/clickup/Cargo.toml",
                "crates/plugins/api/confluence/Cargo.toml",
                "crates/plugins/api/fireflies/Cargo.toml",
                "crates/plugins/api/github/Cargo.toml",
                "crates/plugins/api/gitlab/Cargo.toml",
                "crates/plugins/api/jira/Cargo.toml",
                "crates/plugins/api/slack/Cargo.toml",
                "crates/plugins/api/telegram/Cargo.toml",
                "crates/plugins/format-pipeline/Cargo.toml",
                "crates/plugins/secrets/1password/Cargo.toml",
                "crates/plugins/secrets/env-store/Cargo.toml",
                "crates/plugins/secrets/kdbx/Cargo.toml",
                "crates/plugins/secrets/keychain/Cargo.toml",
                "crates/plugins/secrets/local-vault/Cargo.toml",
                "crates/plugins/secrets/vault/Cargo.toml"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "docs/research/paper1-repro/Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "docs/research/paper1-repro/Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": "biome.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "biome.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "docs/tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "docs/tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "devcontainer, Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "devcontainer, Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "61 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 61,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 96,
            "inputs": {
              "primary_language": "Rust",
              "largest_source_bytes": 381128,
              "source_files_sampled": 329,
              "oversized_source_files": 22
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Rust (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Rust"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "22/329 source files over 60KB",
                "points": 51.3,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 329,
                      "oversized": 22
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "moderate",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "example_dirs": [
                "examples",
                "notebooks"
              ],
              "has_mcp_signal": true,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples, notebooks",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples, notebooks"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "Could not fetch crates package 'llm-eval' from its registry",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-25T13:14:45.021201Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/m/meteora-pro/devboy-tools.svg",
  "full_name": "meteora-pro/devboy-tools",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticscrates.io, npm.