Public record
Software health reportschema 0.27.0 · metrics 1.13.0 · 2026-07-23 10:40 UTC

mgd34msu / goodvibes-sdk

TypeScript SDK for building GoodVibes operator, peer, web, mobile, and daemon-connected apps with typed contracts, auth, realtime events, and transport layers.

TypeScriptMIT★ 0 stars⑂ 0 forkssince Apr 2026View on GitHub ↗

mgd34msu/goodvibes-sdk holds a health index of 56 out of 100, placing it in the Moderate band. It scores highest on Vitality (80/100) and lowest on Sustainability & Governance (34/100). It was last updated 5 days ago. A single contributor accounts for most of its recent work.

56
overall / 100
Moderate

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

56
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

Michael DavisPersonal account
1 follower22 public repossince Apr 2016

This repository is owned by a personal account. A single-owner project carries more continuity risk than an organization-backed one.

Package ecosystems

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

80Good · 22% of overall
How it's scored
36/36Push recency — last push 5 days ago
9.7/36Commit cadence — 14/52 weeks with commits
18/18Commit volume — 908 commits in the last year
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year908
human_commit_share1
days_since_last_push5
active_weeks_last_year14
How it's scored
27/27Ships releases — 100 releases published
36/36Release recency — latest release 5 days ago
27/27Release cadence — a release every ~0.5 days
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Inputs used
releases_count100
latest_release_tagv1.11.4
releases_from_tagsno
days_since_latest_release5
mean_days_between_releases0.5

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

40At risk · 18% of overall
How it's scored
0/60Stars — 0 stars
0/25Forks — 0 forks
0/15Watchers — 0 watchers
Inputs used
forks0
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (MIT)
0/18CONTRIBUTING guide
0/13.5Code of conduct
0/7.2Issue template
6.3/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingno
has_issue_templateno
has_code_of_conductno
has_pull_request_templateyes
How it's scored
62.6/80Monthly downloads — 49,410 downloads/month across npm
0/20Registry dependents — not reported by this ecosystem
Inputs used
packages@pellux/goodvibes-sdk, @pellux/goodvibes-errors, @pellux/goodvibes-peer-sdk, @pellux/goodvibes-contracts, @pellux/goodvibes-toolchain, @pellux/goodvibes-daemon-sdk, @pellux/goodvibes-operator-sdk, @pellux/goodvibes-terminal-shell
dependents
ecosystemsnpm
total_downloads
monthly_downloads49,410
Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

34At risk · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
0/22.5Commit distribution — top contributor authored 100% of commits
1.4/13.5Contributor breadth — 1 contributors
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Inputs used
bus_factor1
contributors_sampled1
top_contributor_share1
How it's scored
0/46.8Issue resolution — no issues or no data
0/38.3PR acceptance — 0/29 decided PRs merged
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Inputs used
merged_prs0
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs29
Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.
How it's scored
10/30Ownership backing — personal (user) account
0/20Verified domain — not applicable to user accounts
2.2/25Owner reach — 1 followers of mgd34msu
21.9/25Track record — 22 public repos, account ~10 yr old
Inputs used
followers1
owner_typeUser
is_verified
owner_loginmgd34msu
public_repos22
account_age_days3,753
Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.
How it's scored
25/25Published & resolvable — 8 package(s) on npm
35/35Publish recency — latest publish 5 days ago
20/20Version history — 221 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packages@pellux/goodvibes-sdk, @pellux/goodvibes-errors, @pellux/goodvibes-peer-sdk, @pellux/goodvibes-contracts, @pellux/goodvibes-toolchain, @pellux/goodvibes-daemon-sdk, @pellux/goodvibes-operator-sdk, @pellux/goodvibes-terminal-shell
ecosystemsnpm
any_deprecatedno
min_days_since_publish5

Engineering Quality

Are baseline engineering and documentation practices in place?

72Good · 20% of overall
How it's scored
24/24CI workflows — 7 workflow(s)
24/24Tests present
0/16Linter config
0/9.6Pre-commit hooks
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — no data
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configno
has_precommit_configno
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.

Documentation

90Excellent
How it's scored
30/30README
25/25Documentation directory
15/15Documentation / homepage site — https://goodvibes.sh
10/10Repository description
0/10Topics
10/10Wiki
Inputs used
topics
has_wikiyes
homepagehttps://goodvibes.sh
has_readmeyes
has_docs_diryes
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

51Moderate · 16% of overall
How it's scored
6.8/7.5Binary-Artifacts — binaries present in source code
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — no data
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
5/5Fuzzing — project is fuzzed
2.5/2.5License — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — no data
5/5Pinned-Dependencies — all dependencies are pinned
0/5SAST — no SAST tool detected
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
7.5/7.5Token-Permissions — GitHub workflow tokens follow principle of least privilege
0/7.5Vulnerabilities — 14 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate5.1
Excluded from scoring (no data or not applicable): ci_tests, packaging. Remaining weights renormalized.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

50Moderate · 0% of overall
How it's scored
0/45Agent instructions — no CLAUDE.md / AGENTS.md / editor rules
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 96 of 100 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share0.96
agent_instruction_files
agent_instruction_max_bytes
How it's scored
0/18One-command bootstrap
22/22Automated tests
0/11Lint / format config
11/11Static type checking — examples/tsconfig.json, packages/contracts/tsconfig.json, packages/daemon-sdk/tsconfig.json, packages/errors/tsconfig.json, packages/operator-sdk/tsconfig.json, packages/peer-sdk/tsconfig.json, packages/sdk/tsconfig.json, packages/terminal-shell/tsconfig.json, packages/toolchain/tsconfig.json, packages/transport-core/tsconfig.json, packages/transport-http/tsconfig.json, packages/transport-realtime/tsconfig.json, test/workers-wrangler/tsconfig.json, test/workers/tsconfig.json, tsconfig.json
0/10Reproducible environment
0/10Demonstrated agent practice — no agent-authored commits among the last 100
0/8Automated maintenance — no automated dependency updates observed
10/10OpenSSF Scorecard: Pinned-Dependencies — all dependencies are pinned
Inputs used
has_nixno
has_testsyes
lockfiles
has_dockerfileno
typed_languageyes
bootstrap_files
has_devcontainerno
has_linter_configno
typecheck_configsexamples/tsconfig.json, packages/contracts/tsconfig.json, packages/daemon-sdk/tsconfig.json, packages/errors/tsconfig.json, packages/operator-sdk/tsconfig.json, packages/peer-sdk/tsconfig.json, packages/sdk/tsconfig.json, packages/terminal-shell/tsconfig.json, packages/toolchain/tsconfig.json, packages/transport-core/tsconfig.json, packages/transport-http/tsconfig.json, packages/transport-realtime/tsconfig.json, test/workers-wrangler/tsconfig.json, test/workers/tsconfig.json, tsconfig.json
agent_commit_share0
toolchain_manifests
dependency_bot_commit_share0
How it's scored
45/45Type-checkable code — TypeScript (statically typed)
54.9/55Manageable file sizes — 4/2,419 source files over 60KB
Inputs used
primary_languageTypeScript
largest_source_bytes128,443
source_files_sampled2,419
oversized_source_files4
How it's scored
0/40API schema (OpenAPI/GraphQL/proto)
0/20MCP server
40/40Runnable examples — examples
Inputs used
example_dirsexamples
has_mcp_signalno
api_schema_files

Key facts

0GitHub stars
1contributors
908commits, last 12 months
5days since last push
100releases
1bus factor
0open issues
npmpackage ecosystems

Data collection warnings

  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository
  • deps.dev does not index npm:@pellux/goodvibes-sdk@1.11.4; advisories assessed against the repository dependency graph instead

More detail

OpenSSF Scorecard 5.1 / 10
5.1aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-23 10:40 UTC

9Binary-Artifactsbinaries present in source code
0Branch-Protectionbranch protection not enabled on development/release branches
n/aCI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
10Fuzzingproject is fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
n/aPackagingpackaging workflow not detected
10Pinned-Dependenciesall dependencies are pinned
0SASTno SAST tool detected
10Security-Policysecurity policy file detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
10Token-PermissionsGitHub workflow tokens follow principle of least privilege
0Vulnerabilities14 existing vulnerabilities detected
Direct dependencies 31
RegistryPackageVersion constraintManifest
npmzod^4.3.6packages/contracts/package.json
npm@pellux/goodvibes-contractsworkspace:*packages/daemon-sdk/package.json
npm@pellux/goodvibes-errorsworkspace:*packages/daemon-sdk/package.json
npm@pellux/goodvibes-transport-coreworkspace:*packages/daemon-sdk/package.json
npm@pellux/goodvibes-contractsworkspace:*packages/operator-sdk/package.json
npm@pellux/goodvibes-errorsworkspace:*packages/operator-sdk/package.json
npm@pellux/goodvibes-transport-httpworkspace:*packages/operator-sdk/package.json
npmzod^4.3.6packages/operator-sdk/package.json
npm@pellux/goodvibes-contractsworkspace:*packages/peer-sdk/package.json
npm@pellux/goodvibes-errorsworkspace:*packages/peer-sdk/package.json
npm@pellux/goodvibes-transport-httpworkspace:*packages/peer-sdk/package.json
npm@pellux/goodvibes-contractsworkspace:*packages/sdk/package.json
npm@pellux/goodvibes-daemon-sdkworkspace:*packages/sdk/package.json
npm@pellux/goodvibes-errorsworkspace:*packages/sdk/package.json
npm@pellux/goodvibes-operator-sdkworkspace:*packages/sdk/package.json
npm@pellux/goodvibes-peer-sdkworkspace:*packages/sdk/package.json
npm@pellux/goodvibes-toolchainworkspace:*packages/sdk/package.json
npm@pellux/goodvibes-transport-coreworkspace:*packages/sdk/package.json
npm@pellux/goodvibes-transport-httpworkspace:*packages/sdk/package.json
npm@pellux/goodvibes-transport-realtimeworkspace:*packages/sdk/package.json
npm@pellux/goodvibes-contractsworkspace:*packages/terminal-shell/package.json
npm@pellux/goodvibes-sdkworkspace:*packages/terminal-shell/package.json
npm@pellux/goodvibes-errorsworkspace:*packages/transport-core/package.json
npm@pellux/goodvibes-contractsworkspace:*packages/transport-http/package.json
npm@pellux/goodvibes-errorsworkspace:*packages/transport-http/package.json
npm@pellux/goodvibes-transport-coreworkspace:*packages/transport-http/package.json
npmzod^4.3.6packages/transport-http/package.json
npm@pellux/goodvibes-contractsworkspace:*packages/transport-realtime/package.json
npm@pellux/goodvibes-errorsworkspace:*packages/transport-realtime/package.json
npm@pellux/goodvibes-transport-coreworkspace:*packages/transport-realtime/package.json
npm@pellux/goodvibes-transport-httpworkspace:*packages/transport-realtime/package.json
All dependencies not collected

The resolved dependency set could not be collected for this report: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 20315,
      "has_wiki": true,
      "homepage": "https://goodvibes.sh",
      "languages": {
        "Shell": 5832,
        "Python": 22998,
        "JavaScript": 33681,
        "TypeScript": 23432366
      },
      "pushed_at": "2026-07-18T01:03:49Z",
      "created_at": "2026-04-13T21:58:23Z",
      "owner_type": "User",
      "updated_at": "2026-07-18T00:51:07Z",
      "description": "TypeScript SDK for building GoodVibes operator, peer, web, mobile, and daemon-connected apps with typed contracts, auth, realtime events, and transport layers.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": "https://www.linkedin.com/in/mike-davis",
      "name": "Michael Davis",
      "type": "User",
      "login": "mgd34msu",
      "company": null,
      "location": "Dallas, TX",
      "followers": 1,
      "avatar_url": "https://avatars.githubusercontent.com/u/18431027?v=4",
      "created_at": "2016-04-12T23:44:21Z",
      "is_verified": null,
      "public_repos": 22,
      "account_age_days": 3753
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v1.11.4",
          "kind": "patch",
          "published_at": "2026-07-18T01:06:32Z"
        },
        {
          "tag": "v1.11.3",
          "kind": "patch",
          "published_at": "2026-07-17T20:44:38Z"
        },
        {
          "tag": "v1.11.2",
          "kind": "patch",
          "published_at": "2026-07-17T06:04:55Z"
        },
        {
          "tag": "v1.11.1",
          "kind": "patch",
          "published_at": "2026-07-17T05:18:18Z"
        },
        {
          "tag": "v1.11.0",
          "kind": "minor",
          "published_at": "2026-07-17T04:40:48Z"
        },
        {
          "tag": "v1.10.1",
          "kind": "patch",
          "published_at": "2026-07-16T23:10:22Z"
        },
        {
          "tag": "v1.10.0",
          "kind": "minor",
          "published_at": "2026-07-16T11:48:01Z"
        },
        {
          "tag": "voice-runtimes-v1",
          "kind": "other",
          "published_at": "2026-07-16T05:13:46Z"
        },
        {
          "tag": "v1.9.0",
          "kind": "minor",
          "published_at": "2026-07-14T20:06:27Z"
        },
        {
          "tag": "v1.8.0",
          "kind": "minor",
          "published_at": "2026-07-13T22:50:05Z"
        },
        {
          "tag": "v1.7.1",
          "kind": "patch",
          "published_at": "2026-07-11T18:53:56Z"
        },
        {
          "tag": "v1.7.0",
          "kind": "minor",
          "published_at": "2026-07-11T17:34:25Z"
        },
        {
          "tag": "v1.6.1",
          "kind": "patch",
          "published_at": "2026-07-09T06:18:07Z"
        },
        {
          "tag": "v1.6.0",
          "kind": "minor",
          "published_at": "2026-07-09T05:45:25Z"
        },
        {
          "tag": "v1.5.0",
          "kind": "minor",
          "published_at": "2026-07-08T13:21:15Z"
        },
        {
          "tag": "v1.4.1",
          "kind": "patch",
          "published_at": "2026-07-08T03:01:33Z"
        },
        {
          "tag": "v1.4.0",
          "kind": "minor",
          "published_at": "2026-07-07T20:00:22Z"
        },
        {
          "tag": "v1.3.3",
          "kind": "patch",
          "published_at": "2026-07-07T06:11:53Z"
        },
        {
          "tag": "v1.3.2",
          "kind": "patch",
          "published_at": "2026-07-07T05:40:43Z"
        },
        {
          "tag": "v1.3.1",
          "kind": "patch",
          "published_at": "2026-07-07T04:28:13Z"
        },
        {
          "tag": "v1.3.0",
          "kind": "minor",
          "published_at": "2026-07-07T03:53:31Z"
        },
        {
          "tag": "v1.2.0",
          "kind": "minor",
          "published_at": "2026-07-06T22:57:58Z"
        },
        {
          "tag": "v1.1.0",
          "kind": "minor",
          "published_at": "2026-07-06T20:43:58Z"
        },
        {
          "tag": "v1.0.0",
          "kind": "major",
          "published_at": "2026-07-06T16:03:31Z"
        },
        {
          "tag": "v0.38.0",
          "kind": "minor",
          "published_at": "2026-07-04T18:19:35Z"
        },
        {
          "tag": "v0.37.2",
          "kind": "patch",
          "published_at": "2026-07-04T02:49:24Z"
        },
        {
          "tag": "v0.37.1",
          "kind": "patch",
          "published_at": "2026-07-04T02:00:58Z"
        },
        {
          "tag": "v0.37.0",
          "kind": "minor",
          "published_at": "2026-07-04T00:39:19Z"
        },
        {
          "tag": "v0.36.0",
          "kind": "minor",
          "published_at": "2026-07-03T22:52:36Z"
        },
        {
          "tag": "v0.35.0",
          "kind": "minor",
          "published_at": "2026-06-30T07:10:29Z"
        },
        {
          "tag": "v0.34.2",
          "kind": "patch",
          "published_at": "2026-06-29T17:03:25Z"
        },
        {
          "tag": "v0.34.1",
          "kind": "patch",
          "published_at": "2026-06-29T14:49:29Z"
        },
        {
          "tag": "v0.34.0",
          "kind": "minor",
          "published_at": "2026-06-20T20:38:37Z"
        },
        {
          "tag": "v0.33.38",
          "kind": "patch",
          "published_at": "2026-06-13T00:28:54Z"
        },
        {
          "tag": "v0.33.37",
          "kind": "patch",
          "published_at": "2026-06-05T17:29:49Z"
        },
        {
          "tag": "v0.33.36",
          "kind": "patch",
          "published_at": "2026-06-04T08:47:04Z"
        },
        {
          "tag": "v0.33.35",
          "kind": "patch",
          "published_at": "2026-05-21T05:29:20Z"
        },
        {
          "tag": "v0.33.34",
          "kind": "patch",
          "published_at": "2026-05-21T05:00:44Z"
        },
        {
          "tag": "v0.33.33",
          "kind": "patch",
          "published_at": "2026-05-21T04:41:55Z"
        },
        {
          "tag": "v0.33.32",
          "kind": "patch",
          "published_at": "2026-05-21T04:17:51Z"
        },
        {
          "tag": "v0.33.31",
          "kind": "patch",
          "published_at": "2026-05-21T03:33:30Z"
        },
        {
          "tag": "v0.33.30",
          "kind": "patch",
          "published_at": "2026-05-12T04:42:12Z"
        },
        {
          "tag": "v0.33.29",
          "kind": "patch",
          "published_at": "2026-05-12T04:20:04Z"
        },
        {
          "tag": "v0.33.28",
          "kind": "patch",
          "published_at": "2026-05-12T04:05:02Z"
        },
        {
          "tag": "v0.33.27",
          "kind": "patch",
          "published_at": "2026-05-12T01:49:05Z"
        },
        {
          "tag": "v0.33.26",
          "kind": "patch",
          "published_at": "2026-05-11T03:35:57Z"
        },
        {
          "tag": "v0.33.25",
          "kind": "patch",
          "published_at": "2026-05-10T22:48:17Z"
        },
        {
          "tag": "v0.33.24",
          "kind": "patch",
          "published_at": "2026-05-10T14:38:05Z"
        },
        {
          "tag": "v0.33.23",
          "kind": "patch",
          "published_at": "2026-05-10T01:27:29Z"
        },
        {
          "tag": "v0.33.22",
          "kind": "patch",
          "published_at": "2026-05-09T21:31:35Z"
        },
        {
          "tag": "v0.33.21",
          "kind": "patch",
          "published_at": "2026-05-09T19:53:32Z"
        },
        {
          "tag": "v0.33.20",
          "kind": "patch",
          "published_at": "2026-05-09T15:53:29Z"
        },
        {
          "tag": "v0.33.19",
          "kind": "patch",
          "published_at": "2026-05-09T03:27:44Z"
        },
        {
          "tag": "v0.33.18",
          "kind": "patch",
          "published_at": "2026-05-08T22:48:26Z"
        },
        {
          "tag": "v0.33.17",
          "kind": "patch",
          "published_at": "2026-05-08T04:25:00Z"
        },
        {
          "tag": "v0.33.16",
          "kind": "patch",
          "published_at": "2026-05-08T01:55:34Z"
        },
        {
          "tag": "v0.33.15",
          "kind": "patch",
          "published_at": "2026-05-08T01:08:07Z"
        },
        {
          "tag": "v0.33.14",
          "kind": "patch",
          "published_at": "2026-05-08T00:09:59Z"
        },
        {
          "tag": "v0.33.13",
          "kind": "patch",
          "published_at": "2026-05-07T23:37:25Z"
        },
        {
          "tag": "v0.33.12",
          "kind": "patch",
          "published_at": "2026-05-07T22:33:14Z"
        },
        {
          "tag": "v0.33.11",
          "kind": "patch",
          "published_at": "2026-05-07T21:19:54Z"
        },
        {
          "tag": "v0.33.10",
          "kind": "patch",
          "published_at": "2026-05-07T19:51:44Z"
        },
        {
          "tag": "v0.33.9",
          "kind": "patch",
          "published_at": "2026-05-07T18:28:09Z"
        },
        {
          "tag": "v0.33.8",
          "kind": "patch",
          "published_at": "2026-05-07T17:33:45Z"
        },
        {
          "tag": "v0.33.7",
          "kind": "patch",
          "published_at": "2026-05-07T14:32:13Z"
        },
        {
          "tag": "v0.33.6",
          "kind": "patch",
          "published_at": "2026-05-07T14:22:26Z"
        },
        {
          "tag": "v0.33.5",
          "kind": "patch",
          "published_at": "2026-05-07T06:00:26Z"
        },
        {
          "tag": "v0.33.4",
          "kind": "patch",
          "published_at": "2026-05-05T12:11:47Z"
        },
        {
          "tag": "v0.33.3",
          "kind": "patch",
          "published_at": "2026-05-05T11:39:50Z"
        },
        {
          "tag": "v0.33.2",
          "kind": "patch",
          "published_at": "2026-05-05T10:48:58Z"
        },
        {
          "tag": "v0.33.1",
          "kind": "patch",
          "published_at": "2026-05-05T08:12:02Z"
        },
        {
          "tag": "v0.30.3",
          "kind": "patch",
          "published_at": "2026-05-03T11:33:12Z"
        },
        {
          "tag": "v0.30.2",
          "kind": "patch",
          "published_at": "2026-05-03T10:33:27Z"
        },
        {
          "tag": "v0.30.1",
          "kind": "patch",
          "published_at": "2026-05-03T09:57:48Z"
        },
        {
          "tag": "v0.30.0",
          "kind": "minor",
          "published_at": "2026-05-03T09:17:08Z"
        },
        {
          "tag": "v0.28.22",
          "kind": "patch",
          "published_at": "2026-05-02T18:08:49Z"
        },
        {
          "tag": "v0.28.21",
          "kind": "patch",
          "published_at": "2026-05-02T16:35:33Z"
        },
        {
          "tag": "v0.28.20",
          "kind": "patch",
          "published_at": "2026-05-02T09:48:31Z"
        },
        {
          "tag": "v0.28.19",
          "kind": "patch",
          "published_at": "2026-05-02T08:41:35Z"
        },
        {
          "tag": "v0.28.18",
          "kind": "patch",
          "published_at": "2026-05-02T06:25:08Z"
        },
        {
          "tag": "v0.28.17",
          "kind": "patch",
          "published_at": "2026-05-02T05:20:26Z"
        },
        {
          "tag": "v0.28.16",
          "kind": "patch",
          "published_at": "2026-05-02T02:56:07Z"
        },
        {
          "tag": "v0.28.15",
          "kind": "patch",
          "published_at": "2026-05-02T02:02:48Z"
        },
        {
          "tag": "v0.28.14",
          "kind": "patch",
          "published_at": "2026-05-02T00:55:03Z"
        },
        {
          "tag": "v0.28.13",
          "kind": "patch",
          "published_at": "2026-05-01T23:26:38Z"
        },
        {
          "tag": "v0.28.12",
          "kind": "patch",
          "published_at": "2026-05-01T21:54:40Z"
        },
        {
          "tag": "v0.28.11",
          "kind": "patch",
          "published_at": "2026-05-01T20:25:48Z"
        },
        {
          "tag": "v0.28.10",
          "kind": "patch",
          "published_at": "2026-05-01T18:59:14Z"
        },
        {
          "tag": "v0.28.9",
          "kind": "patch",
          "published_at": "2026-05-01T17:57:16Z"
        },
        {
          "tag": "v0.28.8",
          "kind": "patch",
          "published_at": "2026-05-01T16:58:50Z"
        },
        {
          "tag": "v0.28.7",
          "kind": "patch",
          "published_at": "2026-05-01T16:08:42Z"
        },
        {
          "tag": "v0.28.6",
          "kind": "patch",
          "published_at": "2026-05-01T14:46:06Z"
        },
        {
          "tag": "v0.28.5",
          "kind": "patch",
          "published_at": "2026-05-01T11:17:38Z"
        },
        {
          "tag": "v0.28.4",
          "kind": "patch",
          "published_at": "2026-05-01T10:19:52Z"
        },
        {
          "tag": "v0.28.3",
          "kind": "patch",
          "published_at": "2026-05-01T09:17:57Z"
        },
        {
          "tag": "v0.28.2",
          "kind": "patch",
          "published_at": "2026-05-01T08:28:59Z"
        },
        {
          "tag": "v0.28.1",
          "kind": "patch",
          "published_at": "2026-05-01T07:33:03Z"
        },
        {
          "tag": "v0.28.0",
          "kind": "minor",
          "published_at": "2026-05-01T05:10:44Z"
        },
        {
          "tag": "v0.27.12",
          "kind": "patch",
          "published_at": "2026-05-01T02:02:44Z"
        },
        {
          "tag": "v0.27.11",
          "kind": "patch",
          "published_at": "2026-05-01T01:08:29Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "4dc6f9fa71b815ac90ae734ad1a9ec91bb932994",
          "body": "Secrets-store key-mismatch hardening: exclusive keyfile generation,\npre-write key revalidation (with missing-keyfile restore), and key\nfingerprints in store envelopes for precise mismatch reporting.",
          "is_bot": false,
          "headline": "release: 1.11.4",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-18T00:50:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cb606a285181fcab05121edcaf822f49de95b92e",
          "body": "Keyfile generation is now exclusive (wx; a process losing the creation race\nadopts the winner's key instead of caching a private one). Every store write\nrevalidates the cached key against the keyfile first — a mismatch refuses the\nwrite with fingerprints on both sides, and a missing keyfile is resto\n[…]\n as 'written\nwith key X, current is Y' instead of a bare GCM auth failure days later.\nAdditive and backward compatible: stores without keyId decrypt exactly as\nbefore; the format version is unchanged.",
          "is_bot": false,
          "headline": "fix: close the secrets-store key-mismatch class",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-18T00:48:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fb6430d2683e5ca5b5e02ab66dba2624b57c5773",
          "body": "Fixes: missing hooks.json no longer error-logs on startup; error summaries\nkeep [REDACTED*] tokens (no more '/home/ /...' paths); publish-package\nresolves tarball paths to absolute before npm sees them.\n\nAdded: COMPACTION_HANDOFF_HEADER export (platform/core) so transcript\nrenderers can fold compaction-continuation messages.",
          "is_bot": false,
          "headline": "release: 1.11.3",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-17T20:30:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "97a349a182f0ee983a3bfd78c0c4fde38a99345f",
          "body": "…ies, export compaction handoff header\n\n- HookDispatcher.loadFromFile skips cleanly (debug log) when the hooks file\n  does not exist — absent hooks.json is the normal state and was producing a\n  WARN + ERROR pair on every startup.\n- stripJson no longer eats [REDACTED*] placeholders, which turned\n  /\n[…]\non' in logs.\n- COMPACTION_HANDOFF_HEADER is exported so transcript renderers can recognize\n  a compaction-continuation message and fold it instead of rendering the full\n  re-injected instruction wall.",
          "is_bot": false,
          "headline": "fix: quiet missing hooks.json, keep [REDACTED] tokens in error summar…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-17T20:18:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5cb19717fe9bd0c3a8d60551d927f3004a94bf49",
          "body": "…bare relative a/b path as a GitHub spec",
          "is_bot": false,
          "headline": "docs: the tarball publish example needs the ./ prefix — npm parses a …",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-17T06:35:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "59860b32673a79ac79a43ee77390e374c94df083",
          "body": null,
          "is_bot": false,
          "headline": "release: 1.11.2",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-17T05:51:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d6d5e23a3e91c91aedcc1d5ec553ced821133a76",
          "body": null,
          "is_bot": false,
          "headline": "release: 1.11.1",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-17T05:04:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "77a2e574cef7e155169c6913a7679cf97d5001ae",
          "body": "…flows request\n\nGitHub validates reusable-workflow permission grants at startup: a callee job\nrequesting more than the caller job grants rejects the entire workflow with\nstartup_failure and an empty jobs list (this killed the v1.11.0 release run\nbefore any job started). Grant actions:read + checks:read on the\nrelease-verify caller and pin the superset contract with a shape test that\nwalks every local reusable call.",
          "is_bot": false,
          "headline": "ci: caller jobs must grant the permissions their called reusable work…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-17T04:24:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9f929867c546709b5dce927fb002b9228f955a63",
          "body": "… mtime freshness checks agree",
          "is_bot": false,
          "headline": "ci: restored dist artifacts are fresh by construction — stamp them so…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-17T01:59:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9e7d659262833e78c402dc03e95857462b9a3696",
          "body": "…— GitHub evaluates it",
          "is_bot": false,
          "headline": "ci: composite action description must not carry a literal expression …",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-17T01:49:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "64167c4fe7a37f369f8ee1c48529dd8f7028ae45",
          "body": null,
          "is_bot": false,
          "headline": "release: 1.11.0",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-17T01:47:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "064883a21965b3aee9a4b5f3b43f97d9cbdd1193",
          "body": "…nputs\n\nTwo contract defects surfaced by consumer adoption, fixed at source:\n\n- reusable-binary-matrix smoked every leg through the shared\n  smoke.binaryDefault, which cannot serve heterogeneous matrix legs (each leg\n  only builds its own suffixed artifact). The targets JSON gains a per-leg\n  'binar\n[…]\ntep's matrix.target.binary wiring + empty-binary\nguard, and that both normalization steps exist and both sinks consume the\nnormalized output instead of the raw inputs. Header contracts + docs updated.",
          "is_bot": false,
          "headline": "reusable workflows: per-leg smoke binary + whitespace-tolerant glob i…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-17T01:38:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4ae71f029a85fc1bdcb7e14d584ebea00a6c4b97",
          "body": "…fallback\n\nThe TUI's releases prefer docs/releases/<version>.md prose over the CHANGELOG\nexcerpt; the reusable workflow only supported the excerpt, silently dropping\nthat behavior. reusable-gh-release.yml gains an optional notes-file input\n({version} expands to the un-prefixed tag): when set and the\n[…]\nct + docs updated; a shape\ntest pins the input's default-empty optionality, the file-branch-before-\nexcerpt precedence, the {version} expansion, and that body_path still feeds\nfrom the resolving step.",
          "is_bot": false,
          "headline": "gh-release: optional notes-file release-body override with changelog …",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-17T01:12:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "20093d4175d1a68d1f749c27cfc061d9ee06f577",
          "body": "…under the job cap\n\nTwo structural hardenings behind dismissals that were only inventory-safe:\n\n- Fallback run-id resolution is now workflow-filtered instead of\n  first-parseable. Neither check-run nor check-suite REST payloads carry a\n  workflow-file field, so each candidate run id is confirmed aga\n[…]\nr the\nother, even listed first); a sole candidate confirmed to belong to a different\nworkflow is rejected as UNRESOLVED; a shape test pins --deadline-ms presence in\nboth mode steps and deadline < cap.",
          "is_bot": false,
          "headline": "per-job-green: workflow-filtered fallback run-id + explicit deadline …",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-17T00:35:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "31518f224f899b8f74607ea91dedab08c87e0580",
          "body": "A transient 503 while enumerating a green run's jobs failed the whole verify\nimmediately — the fallback only wrapped the runs listing. Now EVERY GitHub\nAPI call (runs listing, per-run jobs, check-suites, check-runs) goes through\none bounded retry loop: default 8 attempts with 7s sleeps (the tool's\nd\n[…]\ninto\nthe endpoint-naming failure; runs-listing 503-then-200 recovers without the\nfallback; a thrown transport error retries; default posture pinned (8\nattempts, 5-10s band) and configurability pinned.",
          "is_bot": false,
          "headline": "per-job-green: bounded transient-error retries on every API call",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-17T00:18:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bcef9da7e217acee950864ae2352d27b393d03db",
          "body": "…run_id early\n\nThe check-suites fallback returned ok with runId null; the bin wrote\nrun_id= (empty) and publish-npm fed that to download-artifact, which then\nstopped targeting the CI run — breaking the CI-build restore precisely when\nthe fallback fires.\n\n- The fallback now resolves the Actions run i\n[…]\nts: fallback run-id resolution from check-run fixtures, the unresolved\ncase, details_url parsing, and a workflow-shape test pinning the guard's\nexistence and its ordering before the CI-build download.",
          "is_bot": false,
          "headline": "per-job-green: fallback resolves the run id; publish guards an empty …",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-17T00:15:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "272d54abe89c7ec198d58a2e7c2a3648f63d0d43",
          "body": "…otstrap fix)\n\nThe SDK's release-verify bunx-ed @pellux/goodvibes-toolchain from the npm\nregistry with no checkout and no install. The package does not exist on the\nregistry until this very release publishes it, so the first release would\n404 in release-verify, skip publish-npm, and deadlock — and e\n[…]\nalesce across the two mode step ids; an unknown mode fails fast.\n\nWorkflow-shape tests pin both modes (workspace never bunx-es, registry never\nchecks out) and that the SDK's own caller uses workspace.",
          "is_bot": false,
          "headline": "release-verify: self-host the toolchain for the SDK's own release (bo…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-17T00:13:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "77d76e81af3dff9278c9a26a184f69502a922c29",
          "body": "enumerateWorkspacePackages now returns 11 public workspace packages; update\nthe sdk-dev-tool assertion to expect goodvibes-toolchain in the set.",
          "is_bot": false,
          "headline": "test: sdk-dev enumerates the 11th public package (goodvibes-toolchain)",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-16T23:57:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1200323ca8b4bbe6a2de2874c9105e3e609f146e",
          "body": "…G Unreleased\n\nRewrite docs/release-and-publishing.md for the new flow: local release =\nrelease-cut + tag, CI owns validation, the by-reference release (release-verify\n+ artifact-integrity handoff). Document the @pellux/goodvibes-toolchain package,\nthe toolchain.config.json contract, and the reusable workflows. Add the\nCHANGELOG Unreleased section for the CI/CD redesign.",
          "is_bot": false,
          "headline": "docs: by-reference release flow + toolchain.config contract; CHANGELO…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-16T23:49:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "213bcd5843ac5bed80f531b74620e87228ff6474",
          "body": "Slice 2 — reusable workflows (workflow_call) hosted here and consumed\ncross-repo: reusable-release-verify (per-job-green by reference, emits run\nid + head sha), reusable-npm-publish (provenance + propagation poll),\nreusable-gh-release (changelog excerpt + SHA256SUMS), reusable-binary-matrix\n(build-b\n[…]\nlow-shape test suite (21 tests) parses the YAML and asserts job\ngraphs, needs edges, no continue-on-error on gating jobs, timeout caps,\nartifact producer/consumer pairing, and the by-reference wiring.",
          "is_bot": false,
          "headline": "ci/cd: reusable workflows + build-once CI + by-reference release",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-16T23:47:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "34f56108d1be7aacca4149d201d269816c0e11f2",
          "body": "New 11th workspace package absorbing the parallel-copy script families\n(sdk-pin-gate, build-binaries, release-cut, coverage-gate,\nverification-ledger, post-build-smoke, package-install-check,\npublish-package, per-job-green, changelog-gate, sha256sums) as clean,\nparameterized policy modules with inje\n[…]\nshared packageDirs, tsconfig references,\nversion-consistency list, root workspace devDependency, and the test\nrunner's discovery. 74 fixture-driven unit tests (no network, temp-dir git\nfixtures only).",
          "is_bot": false,
          "headline": "toolchain: add @pellux/goodvibes-toolchain — shared CI/CD tools package",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-16T23:39:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ddd3354e0b0696aace13d5a84392ba2203f95a0a",
          "body": null,
          "is_bot": false,
          "headline": "release: 1.10.1",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-16T22:38:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1d72c9f36533c496b94953757763ed4223ac7bd4",
          "body": "…cised or skipped, never failed by the host",
          "is_bot": false,
          "headline": "tests: the live logind proof verifies its staging precondition — exer…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-16T11:24:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "837e65bdb54a58f1d223b28c61f51d03b975ca10",
          "body": "…tes landed",
          "is_bot": false,
          "headline": "ci: validate lane needs 20 minutes after the governance and voice sui…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-16T11:00:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "77d7c2b15079170856355359bccb3e1d409164c6",
          "body": "…me/buzzkill)",
          "is_bot": false,
          "headline": "tests: repo-relative paths in source-shape pins (CI runner has no /ho…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-16T10:38:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "70178b9264187d1ba06620a0d1c5902a7a088a79",
          "body": null,
          "is_bot": false,
          "headline": "release: 1.10.0",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-16T10:19:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5357f09e2ae6500cd809ed1bfa23779a9e669827",
          "body": "voice.local.install is plain request/response, so during a ~209MB provision a\nsurface could only render busy->receipt. The fix rides what already exists: the\ninstall is single-flight (a second concurrent caller joins the in-flight run),\nso the ACTIVE run's per-component progress — component, phase\n(\n[…]\nogress window.\n- CHANGELOG notes the polling shape and (for surface authors) that labeling\n  the STT bundle-unavailable state 'not yet published' is an accurate reading —\n  the wire enum is unchanged.",
          "is_bot": false,
          "headline": "voice.local.status carries live install progress while an install runs",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-16T07:39:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4d5e247bbec03413dcc9931eb6c492d26f8b08ed",
          "body": "…clients to its real slice; export singleFlight\n\nPhantom-export fix: the memory-governance layer had NO public export path —\nthe SDK's own daemon composition constructs the governor internally, but\nfork-composing consumers (agent, TUI) could not. A new\n./platform/runtime/memory subpath (types + impo\n[…]\neys (test/types, resolved through the package name).\n\nsingleFlight (the voice-install single-flight combinator) is now exported from\nthe platform/utils public surface so consumers stop duplicating it.",
          "is_bot": false,
          "headline": "Publish the memory-governance composition surface; narrow foundation-…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-16T07:21:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "efc1b380edcc7f1be7a848c30faacff013177800",
          "body": "…een-rounds gate\n\nstopWhenPaused was structurally inert for space-scoped self-improvement runs:\nbackgroundStopRequested was consulted only on the whole-store branch, and every\nhome-graph sync-pump round is space-scoped — so at the high tier (pauseAll,\nbefore critical's admission refusal) the pump ra\n[…]\n while a foreground run without stopWhenPaused is\nunaffected; the allowlist-gate regex now pins stopWhenPaused on the PUMP call\nshape, the between-rounds gate, and both threaded shouldStop call sites.",
          "is_bot": false,
          "headline": "Make the sync pump's governor pause real: per-gap stop consult + betw…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-16T06:09:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1b14e3a25a68f9b36202664c053418e7704ec892",
          "body": "…he budget\n\nThe hard limit fired at hardLimitPct x budget, and the default budget caps at\n4096MB — so a healthy daemon with a large but STABLE working set above ~4.9GB\non a big-RAM host (mmap'd sqlite pages + a large heap graph: not registered\ncaches, not reclaimable by flush) was graceful-exited in\n[…]\nn); the 5MB/s slow leak still exits at the ceiling\nwith a hard-limit receipt; a cgroup-limited daemon anchors to ITS limit; the\ngovernor test harness now injects a host-independent ceiling everywhere.",
          "is_bot": false,
          "headline": "Anchor the absolute-RSS backstop to the effective kill ceiling, not t…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-16T06:02:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fd4805c02f202a3466bd72b7ea9e87d551b2fced",
          "body": "…in (1.2x headroom)",
          "is_bot": false,
          "headline": "Bump store-snapshots bundle budget for the async tripwire snapshot tw…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-16T05:34:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "63faaf7592aca8f0f297659eba0cfe5cffec60c8",
          "body": "…oad-mismatch STT state",
          "is_bot": false,
          "headline": "Sync foundation client types + public API report with the voice sidel…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-16T05:29:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dae06b6a078913f7ebedc1f191efe37ea6d84440",
          "body": "…r gate)",
          "is_bot": false,
          "headline": "Reword burst-wave test comments to plain language (internal-identifie…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-16T05:25:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "873f6e4b19075437ee0ad8e63b32cee83860c22d",
          "body": "…bundle\n\nBind honesty (finding 13): the web-surface startup announcement now derives its\nscope wording from the binding RESOLVER, not the raw stored value. A case/space\nvariant ('  Local ') keeps the 'this machine only' note the raw check dropped,\nand an unrecognized value ('LAN') is announced as un\n[…]\nly, versioned filenames, move-in-lockstep,\nreproducible). Other platforms stay honestly unstamped. Verified end-to-end with a\nlive download->verify->extract->transcribe smoke against the hosted asset.",
          "is_bot": false,
          "headline": "Bind-honesty announcement + launchd provenance; host the whisper STT …",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-16T05:23:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2c260e80f58cd2bb12e13756d78028882367c1d5",
          "body": "…ve STT stamp, reproducible bundle, immutable model pin\n\n- The whisper sideload update path now verifies the on-disk archive against the current pin BEFORE extraction: a stale/mismatched archive is never extracted, and the install stamp never records a new version over an unverified binary. A presen\n[…]\ntead of the mutable main ref (verified same sha256), so an upstream re-export cannot brick fresh STT provisioning.\n- Regenerated operator contract, OpenAPI, and reference docs for the added STT state.",
          "is_bot": false,
          "headline": "Voice provisioning provenance: verify sideload before extract, preser…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-16T05:12:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "567d5febe5066c2cb48a184378dcd517c3be1b4d",
          "body": "…ync tripwire snapshots\n\n- resolveEffectiveSystemRamMb resolves the process's own cgroup from /proc/self/cgroup and walks the ancestor chain (minimum limit), so a systemd MemoryMax= slice limit is found rather than only the root; root-path reads stay as fallback.\n- New memory.hardLimitPct (default 1\n[…]\nStoreFileAsync/snapshotAllAsync) so a stalled disk cannot block the event loop and defeat the 10s shutdown ceiling; the receipt is written and flushed before the shutdown hook runs (pinned by a test).",
          "is_bot": false,
          "headline": "Memory governor: own-cgroup RAM resolution, absolute-RSS backstop, as…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-16T05:02:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8d4a707f2dff086c1db4b2b03e4ba8273dd09174",
          "body": "Two edge cases in the governed background scheduler:\n\n- gapIds arriving while a run is IN FLIGHT were merged into pendingInput\n  and then wiped by the completion handler, and a zero-gap completion\n  parked the scope for the full backoff over that fresh evidence. The\n  queued input is now CONSUMED at\n[…]\n\nre-queued and runs after a zero-gap completion (scope not parked); a\nsecond burst wave inside the sweep's window fires NO second sweep, and a\ngapId-carrying overflow trigger clears the sweep backoff.",
          "is_bot": false,
          "headline": "Scheduler: re-queue mid-run gap evidence; sweep honors its own backoff",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-16T00:48:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8367d55e322618cfe6fe595a45f947d2a536cf07",
          "body": "…mp pause\n\nThe critical-tier admission gate now covers every knowledge-shaped HTTP\nsurface, not one of three:\n\n- agentKnowledgeService (the /api/goodvibes-agent/knowledge alias\n  serving full runJob/ingest routes) is constructed WITH\n  admitExpensiveWork in both compositions - runtime services and t\n[…]\nunds through the pressure window.\n\nPinning tests: refusal on all six gated verbs, tail defers on pause and\non refusal and runs when admitted, plus shape pins on the two\ncompositions and the pump call.",
          "is_bot": false,
          "headline": "Admission-gate coverage: agent-alias knowledge, home-graph ingest, pu…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-16T00:45:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7896742119bca2236d7872ea304c8ce9229d7156",
          "body": "…ght installs\n\nThe WS 'call' frame's second dispatch arm - a frame carrying methodId\nrouted to invokeGatewayMethodCall's registered-handler branch - ran with\nno cap, no refusal, and no visibility (probed: 5,000 concurrent handler\ninvocations while wsCallStats reported 0). The handler branch now shar\n[…]\n mirror the reviewer's probe: a 5,000-frame methodId burst\npeaks at 256 concurrent handlers with visible stats and 503 refusals,\ndrains to zero; single-flight join/fresh-run/failure-release semantics.",
          "is_bot": false,
          "headline": "Cap the WS methodId arm under the same in-flight contract; single-fli…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-16T00:40:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d6015e6ca959783f78f1130d60dac49412188000",
          "body": "…ng discovery\n\nThe staged pane process becomes agent-shaped only after bash's\n`exec -a claude` completes; racing discovery against that exec chain\nproduced flaky \"must be discovered\" failures on a healthy host. The live\nleg now verifies via /proc that the staged process's cmdline matches the\nREAL di\n[…]\ns own uniquely-named session is ever created, targeted, or killed.\n\nVerified: 5 consecutive foreground runs, all EXERCISED (discovery,\npane resolution, three-send steer, marker read back), 0 failures.",
          "is_bot": false,
          "headline": "Live tmux steer proof: verify the staging precondition before asserti…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-16T00:15:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2ae180f3c20be94f7cf335c3b360acd22b98052f",
          "body": "…verb schemas",
          "is_bot": false,
          "headline": "Regenerate contract, OpenAPI, and docs artifacts for the managed-STT …",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-16T00:10:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e70b5a638cd50b481ffe638049c97bdb23d180ec",
          "body": "whisper.cpp publishes no official prebuilt binary, so goodvibes builds it:\nscripts/build-whisper-bundle.ts reproduces the bundle (pinned source tag\n1.8.2, static ggml, portable codegen, stripped whisper-cli), and the\nlinux-x64 artifact it produced is pinned in the manifest (1121557 bytes,\nsha256 809\n[…]\n.local.status/install schemas now carry the STT managed state\n(supported/state/binaryPresent/modelPresent + reason); contract types\nupdated. CHANGELOG rewritten for the round's fixes in user language.",
          "is_bot": false,
          "headline": "Managed STT: goodvibes-built whisper.cpp, pinned + provisioned like TTS",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-16T00:04:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "20a47fd343232a997fb71996248616b21a206212",
          "body": "…real web binding resolver\n\nresolveHostBinding no longer has an undefined fall-through: hostMode is\nnormalized (trim/lowercase) so case/padding variants of real modes\nresolve deliberately, and any unrecognized value ('LAN', '', a typo)\ntakes the SAFE local posture (127.0.0.1) with an explicit\nrecogn\n[…]\nrface URL, and the\ntailscale-serve verb all anchor to it instead of each reading the raw\nstored values (Number(raw ?? 3423) let 0 stay 0 and non-numeric stay\nNaN). Tests pin the exact fixture strings.",
          "is_bot": false,
          "headline": "Bind-honesty resolvers: explicit unrecognized-hostMode posture and a …",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-15T23:52:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cc72e39a68bbf3f06c8fcc927b7a0764c4e543fa",
          "body": "…aker, owned config keys\n\n- Engine version bumps APPLY: an install stamp records the installed\n  engine/voice versions; a re-install whose pinned version differs (or\n  whose archive was freshly re-downloaded) re-extracts and replaces the\n  old binary instead of silently keeping it because a file exi\n[…]\nives the managed\n  paths (the duplicated constant that silently broke alternate archive\n  layouts is gone), and the provisioner accepts engine/voice manifest\n  overrides as a test/staged-rollout seam.",
          "is_bot": false,
          "headline": "Voice provisioning correctness: versioned atomic installs, honest bre…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-15T23:49:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "440513a6ba0e4788f3c68e99fe65552ce0136ee8",
          "body": "…ypass\n\nGovernor (was visibility theater; now every piece acts):\n- Cache adapters are REAL: the knowledge stores register a genuine\n  retained-entry count plus a trim that prunes the job-run history (Map\n  AND sqlite rows); the session broker registers its retained record\n  count plus a trim that ru\n[…]\nnt-loop\n  yields (was an O(N^2/500) offset re-scan with no yields).\n- Production defaults (5s floor, 1h backoff) are asserted exactly via\n  injected clock/schedule seams - no test overrides them down.",
          "is_bot": false,
          "headline": "Make the memory governor real and close every self-improve hot-loop b…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-15T23:40:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ebe1f63b979999a95fe71983c9e94efdfae7c936",
          "body": "The prior round's relay caps were unreachable on a LAN-only daemon (the\nrelay path is triple-gated off), and its 401-error release was a no-op\n(the transport pins the same object via ctx.error). This commit bounds\nthe retainers that are actually reachable, with retention probes proving\nbefore/after.\n[…]\ng at dispatch-resolve, the\nreconstructed Request carries an abort signal, streaming responses are\nrefused with a structured 501 tunnel frame, and response bodies are\nbounded at 32MB with a 502 beyond.",
          "is_bot": false,
          "headline": "Bound the true retained-context sites on the ordinary daemon path",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-15T23:15:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8f937579f9e2b1a5bec34a3680037ec61a439587",
          "body": "Relay context leak (the OOM killer): bound the operator-token\ncontrol-plane relay path. The daemon-side relay registration now caps\nretained secure-channel pipes (LRU-evicts the coldest) and refuses\nin-flight tunneled requests past a ceiling with an honest 503 instead of\naccumulating request context\n[…]\nuilt binary\nexists. New voice.local.status and voice.local.install verbs.\n\nCHANGELOG updated; contract/openapi/docs/api artifacts regenerated;\nline-cap ceilings re-justified for the deliberate growth.",
          "is_bot": false,
          "headline": "Harden daemon memory, control-plane relay, and local voice",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-15T04:38:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ef7533340927d5fa1df5e4acf1f9a4ceec110ac2",
          "body": null,
          "is_bot": false,
          "headline": "release: regenerate contract artifacts for 1.9.0",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T19:42:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5a8b30aa579726176da48e2fa2f106a3d14878fe",
          "body": null,
          "is_bot": false,
          "headline": "release: 1.9.0",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T19:29:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "693a6d57874b2410e5ba533374d7ebe1c05152a9",
          "body": "The six ae-unresolved-link warnings in the API report are gone: member\nreferences qualify their container (DaemonServer.start, RuntimeEventBus.emit)\nand links to module-private helpers name them in code font instead of a\npackage-level link the extractor cannot resolve.\n\nThe two remaining extractor w\n[…]\niberately:\nthe bundled-compiler version note (API Extractor ships TS 5.9.x; no release\nbundles TS 6 yet) and a third-party gaxios declaration that predates the\nnewer typeof-fetch shape. Neither gates.",
          "is_bot": false,
          "headline": "docs: every API-report doc link resolves",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T19:15:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9c389dc4023352916175a5dc480178ea65896e15",
          "body": "The conflicted-file list on a merge failure is structured data — a\nconflict-resolution session seeds from it — but the extractor scraped the\nfailure message, whose shape varies with the git/simple-git output pairing.\nOn one shape (the library's parsed merge-summary rendering, seen on the CI\nrunner's\n[…]\ny rendering —\nand always yields bare repo-relative paths. It is exported and pinned by\nfixture-driven regression tests that feed both raw shapes verbatim, with no\ndependence on the host's git version.",
          "is_bot": false,
          "headline": "git: merge-conflict file lists are bare paths on every git version",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T19:06:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3a5ea26d1ca0ade82082be9f0abf46bb5dbe7ae1",
          "body": "… system-bus connections\n\nThe Linux power seam watched logind's PrepareForSleep signal with a read-only\ndbus-monitor subscription that nothing ever reaped: an exiting or crashed\nprocess left the watcher parented to init, and repeated constructions (mostly\ntest runs) accumulated orphaned watchers unt\n[…]\nsteer\nleg proves the observed-agent steer channel end to end (own uniquely-named\nsession only; three-send recipe; capture-pane readback), recorded with the\npower acceptance in a dated decision record.",
          "is_bot": false,
          "headline": "power: the sleep-edge watcher can no longer outlive its owner or leak…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T18:47:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fd0e6b2970202625ac8ba4d4a78d5fc802126742",
          "body": "The dedicated daemon-composition subpath for the observed foreign-agent\nsource shipped without a bundle budget, which fails the budget gate (every\nexport entry must carry one). Measured and anchored per the recorded\nmethodology.",
          "is_bot": false,
          "headline": "bundle budget: the observed-agent composition subpath gets its entry",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T13:51:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1c94e8e22b3d5741dd7cd525ffda3ac7f2c34805",
          "body": "…he acceptance checklist\n\nThe acceptance checklist existed only in the internal agent-report shape the\nfix-phase controller consumes; no operator-facing wire endpoint carried it, so\na surface could not render what was actually verified despite the review\nrecord being built for exactly that.\n\nwrfc-ch\n[…]\n\nitems intact and the controller verdict overriding a passed:true reviewer\nclaim; a pre-review chain serves no review field; the shape round-trips JSON\nserialization exactly as a consumer receives it.",
          "is_bot": false,
          "headline": "fleet: the latest review rides the chain node — verdict, score, and t…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T13:46:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d0a1b96c6f201221f56b72eeaf5c6f68fb1a12da",
          "body": "…omposition subpath\n\nForks that compose their own runtime (the TUI daemon) need to instantiate the\nobserved foreign-agent source, but the class was reachable only from an\ninternal relative path — the type barrel deliberately keeps the value out to\navoid dragging host-detection code into render surfaces. Add a dedicated\nplatform/runtime/fleet/observed subpath so daemon composers get the value\nwithout polluting the type-only barrel.",
          "is_bot": false,
          "headline": "sdk exports: expose the observed-agent source on a dedicated daemon-c…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T13:08:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e0a5595d7c2797721410a8ab9a9b81370dc5f8e5",
          "body": "… refreshed\n\nmemory.consolidation.receipts is a whole-report read named for what it serves\n(retained consolidation run receipts + pending proposals), like doctor/stats/\nreview-queue — recorded in the reporting-and-diagnostics category so the\nverb-vocabulary gate passes it deliberately rather than by accident.",
          "is_bot": false,
          "headline": "contracts: the receipts verb tail joins the reporting exemption; dist…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T12:46:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dca9827e470fcaa455fb8d6c7d1c48c547e3fcb2",
          "body": "… entry moves out of 1.8.0\n\nEvery feature landed since the 1.8.0 release now has a plain-language entry\nunder Unreleased: the planned fix-phase task graph, the fleet.maxSize rename\n(with its migration note), sleep ownership and keep-awake, local voice\nengines, per-tool cancel and editable queued mes\n[…]\nand this audit round of\nfixes.\n\nThe observed-foreign-agents entry sat inside the released [1.8.0] section —\nclaiming a feature that release does not contain — and moved to Unreleased\nwhere it belongs.",
          "is_bot": false,
          "headline": "changelog: the unreleased cycle gets its section; the observed-agents…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T12:40:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ebcef11e9944c8e8608d0f67c84c79e21a543430",
          "body": "…+ proposals get a wire verb; attach notices record\n\nJudgment outcomes had zero consumers: a contradiction or cross-scope-duplicate\nproposal was computed, listed in the run receipt ring, and reached nothing —\nthe referenced records reviewState stayed untouched and no surface could list\nwhat was prop\n[…]\nipt sink to the announce-once store (hoisted above\nthe scheduler construction), recording one line per run that actually merged,\ndecayed, archived, or proposed anything — no consumer re-wiring needed.",
          "is_bot": false,
          "headline": "memory consolidation: proposals reach the review machinery; receipts …",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T12:38:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b5926539311acc7741ad157e4aea6c78e3003be4",
          "body": "The serious leak: PowerManager.stop() had zero callers and no exit path\nreleased holds — the systemd-inhibit children (block-mode, sleep infinity)\norphaned on process exit with keep-awake or a work hold active, blocking host\nsleep indefinitely with no owner. Fixed at every layer:\n\n- Exit/signal clea\n[…]\n reaper\nkills exactly the dead-owner stamped orphan (live owners and foreign\ninhibitors untouched); start() invokes the seam reaper; a config flip\nlive-applies both directions and stop() unsubscribes.",
          "is_bot": false,
          "headline": "power: holds can never outlive their owner; keep-awake applies live",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T12:26:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3b44f0b02e910be902cc2bd0215cfb74a4f0fb9e",
          "body": "…overy snapshots, watch config files in composition\n\nThree write-model residues fixed at the composition root:\n\nThe startup append-only sweep passed only workingDirectory + surfaceRoot at\nits ONE wired call site, so the registered activity-log and telemetry-ledger\nentries were skipped on every produ\n[…]\nRuntimeServices inherit it), and the underlying file watchers are\nunref-d so the watch can never pin an idle process open. Consumers that\nhand-rolled their own live-apply can drop it after re-linking.",
          "is_bot": false,
          "headline": "retention + live config: sweep the roots that never ran, register rec…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T12:20:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "419519dc38be59d42862d8a365ae8bfab1c96f63",
          "body": "…hes the announce-once queue\n\nThe migration test asserted the disk rewrite but never that the rename receipt\nwas queued for a surface to render — the user-facing half of the invisible-\nmigration contract was untested. It now asserts the announce-once file carries\nthe migration id in the announced ma\n[…]\n new key, moved value). A second test\ncovers the silent catch-and-warn fallback: a throwing receipt sink is caught,\nand the migration itself (value moved, legacy key gone, file rewritten) still\nlands.",
          "is_bot": false,
          "headline": "config migration test: the fleet.maxSize rename receipt provably reac…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T12:13:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "76ebff5178cc1de945bd75c3e34e5be4ba7a4b45",
          "body": "… catches the class\n\nA sweep found the same internal plan-item label sitting in comments across the\norchestration engine, the WRFC planned-fix path, the fleet graph route, the\nfoundation-io script, and four test files. Every occurrence is rewritten in\nplain language describing the behavior (the fix-\n[…]\nversions are\nthe doctrine sanctioned provenance — so semver strings (bare, parenthesized,\nv-prefixed) are covered by explicit stay-legal tests, alongside seeded-\nviolation red tests for the new shape.",
          "is_bot": false,
          "headline": "plain language: strip plan-item labels from shipped comments; scanner…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T12:11:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c7afd90de2637ad8ae98ee74d8de7d2d772745cf",
          "body": "…H review paths\n\nThe compound-subtask review computed its pass verdict without the\nacceptance-checklist term: a subtask reviewer recording verified:false items\nalongside a passing score passed with no fix cycle. And on every path, an\nabsent/empty checklist normalized to [] — indistinguishable from a\n[…]\nr the score; a genuine all-verified checklist passes.\nExisting fixtures that passed on prose-only or checklist-less reviews were\nupdated to structured reviews — that class no longer passes, by design.",
          "is_bot": false,
          "headline": "review gate: the acceptance checklist blocks deterministically on BOT…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T12:07:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c829957f04cf3df6db30b02e65e1bb7939e2af91",
          "body": "… certificates\n\nThe LAN certificate helper minted a self-signed CA plus a leaf certificate via\nopenssl, which violates the standing posture ruling: no self-provisioned CA,\never; certificate issuance is never the daemon business. The module is deleted\noutright with its exports (relay barrel + the dae\n[…]\n with tailscale certificates (read-only\ndetection + one explicit user-initiated enable); without tailscale, LAN access\nstays plain http rather than a locally-minted trust root. API report\nregenerated.",
          "is_bot": false,
          "headline": "relay: delete the certificate-minting helper — the daemon never mints…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T11:55:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "89690d074cf1961874120029b3bda911dfa3ed08",
          "body": "…data.memory.recordIds\n\nThe per-turn knowledge-injection accounting (TurnInjectionRecord.injectedIds +\nparallel injectedSources, agents/turn-knowledge-injection.ts) existed with no\nwire producer: nothing carried the memory-sourced ids onto the turn payloads\nsurfaces consume, so the provenance chip s\n[…]\nst turns, code-index exclusion, the surface-documented defensive\nread path round-tripping the emitted payload, and the real\nhandleFinalResponseOutcome emit site stamping the real runtime-bus envelope.",
          "is_bot": false,
          "headline": "turn events: memory-injection provenance rides TURN_COMPLETED as meta…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T09:56:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c4adfca51ab796d76da739d3b4e190ca532c259b",
          "body": "…he drift class\n\nA consumer found fleet.maxSize missing from the published ConfigKey string-\nliteral union (its tests carried documented casts around it). Root cause: the\nschema DOMAIN modules define the authoritative key set (aggregated into\nCONFIG_SCHEMA through an as-cast), while the union and th\n[…]\ng on a miss in\neither direction, with seeded red-tests proving the checker catches both a\nremoved key and a phantom member, and a sanity floor so an aggregation\nbreakage cannot produce a vacuous pass.",
          "is_bot": false,
          "headline": "config: complete the ConfigKey union + typed-accessor mapping, gate t…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T09:12:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a03bf218573cd715494fcb65e867594a11d3f543",
          "body": "A consumer composing its own runtime found dist-built modules missing from the\npackage exports map (the recorded phantom-export defect class), forcing deep\npaths and a local fork-mirror. Sweep method: every top-level platform module\nthe SDK's own composition roots (cli.ts, runtime/services.ts, daemo\n[…]\nce) resolve through the\npackage NAME against the committed manifest, not just compilation. Bundle\nbudgets added for the three new entries and ./platform/state re-anchored per\nthe recorded methodology.",
          "is_bot": false,
          "headline": "exports: close three phantom-export gaps a consumer re-link surfaced",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T08:37:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fc3bbf5eb907d39f4787ca022f76260c21705693",
          "body": "… bundle budgets\n\nThe always-on ObservedAgentSource made the generic RuntimeServices factory scan\nthe host process table, which broke daemon-boot tests that assume an empty\nfleet (they now saw real host coding-agent processes — non-deterministic).\nMirror the autoStartCodeIndex precedent: gate detect\n[…]\nhe feature itself. Re-anchor the fleet\nbundle budget (452 -> 663 B, methodology max(ceil(actual*1.2), actual+50)) and\nthe services.ts/registry.ts line ceilings for the wiring; add the CHANGELOG\nentry.",
          "is_bot": false,
          "headline": "fleet: make observed-agent detection an opt-in seam; re-anchor line +…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T08:00:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f415bf13ee9c474b2486b54b8d7c8fadd0c04a61",
          "body": "…m where a channel exists\n\nExternally-launched Claude Code / Codex sessions the daemon did not spawn or\nhost are now discovered by read-only process-table detection (same discipline\nas the tailscale detector: the process table and tmux pane list are read, the\nforeign processes are never exec-d or pr\n[…]\ntion, foundation-io typed I/O,\ntransport-parity manifest, and the regenerated contract/openapi/webui-facade/\nhomeassistant/docs/api artifacts. Detection is always-on and degrades to a\nquiet empty set.",
          "is_bot": false,
          "headline": "fleet: observe externally-launched coding agents read-only, steer the…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T07:36:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a5c63e3b8efaf6f66acd4f5d35700dbff39fb54d",
          "body": "types.ts and scheduler.ts described the engine's departure from\nWrfcController by citing startFix at a hard-coded line number — a symbol\nthe planned-workstream rework deleted, and line citations rot anyway.\nBoth comments now describe the current reality by module and function\nname: startPlannedFix plans a task graph from reviewer findings via\nreview-task-source.ts and executes it as a workstream in this engine.",
          "is_bot": false,
          "headline": "orchestration docs: drop dead startFix references from module comments",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T07:04:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dc4023ea8570edd2ed0a136cb7161e5cef27253a",
          "body": "The orchestration entry grew intentionally this round (review-task\nparser/planner, graph dynamics, elastic pool, fix-workstream runner).\nMeasured 834 B gzip at f22cfa27; budget follows the documented headroom\nmath to 1001 B.",
          "is_bot": false,
          "headline": "bundle budget: re-anchor ./platform/orchestration after export expansion",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T06:58:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f22cfa275fe27e415d59648f56556a111d373a20",
          "body": "GET /api/fleet/workstreams/{workstreamId}/graph returns the graph over\nthe contract: nodes with state, cluster, files, retry count and stalled\ntell; edges with their reasons; pool state (ready, running, capacity,\nat-cap); typed IO end to end (catalog descriptor, gateway route,\nfoundation client type\n[…]\n\naddition and requeue, structured cycle refusal, orphan surfacing,\nelastic spawn and visible at-cap state, retirement, the one-ceiling\ncounting seam, and the end-to-end fleet.maxSize rename migration.",
          "is_bot": false,
          "headline": "surface: fleet.graph.get exposes the fix workstream's task graph",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T06:47:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "152d927c52328a7771f2c3f9a9f09acb2717de76",
          "body": "…gent ceiling\n\n'Maximum fleet size' is the single cap on agents this daemon is\nresponsible for: native spawned agents, ACP-hosted agents, and elastic\nfix-task agents all count against the same ceiling — no per-path\nsibling caps.\n\n- Invisible migration: an existing orchestration.maxActiveAgents value\n[…]\nount.\n- The config manager's load-time migration passes extract to\n  manager-migration-passes.ts; the runtime wires the live fleet probe\n  and the fix-workstream runner into the engine and controller.",
          "is_bot": false,
          "headline": "config: orchestration.maxActiveAgents is now fleet.maxSize, the one a…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T06:46:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8b02b4d4119631ad54481ff1d5b1fbda6a0e62ca",
          "body": "The single-fixer prompt path is gone from the review cycle. When a\nreview fails, the controller now plans a fix workstream from the\nreviewer's typed findings and runs it through the orchestration engine:\nfresh per-task agents in isolated worktrees, the existing sequential\nintegration lane, and edges\n[…]\n result,\n  it does not re-fix review findings.\n- Tests migrate to the planned path via an injectable stub runner\n  (merged / failed / pending) and pin the new invariants, including\n  fixer-class-gone.",
          "is_bot": false,
          "headline": "workflow fix phase: the planned workstream replaces the single fixer",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T06:45:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6500cc0e1a8dc47c422547ef4b0ee2c17137c4df",
          "body": "…ne graph\n\nThe planner-decomposition engine gains the muscles the planned fix path\nneeds — as extensions of the existing workstream graph, never a sibling\nscheduler:\n\n- review-task-source: a reviewer's findings, unsatisfied constraint\n  findings, and unverified acceptance-checklist entries parse int\n[…]\not APIs.\n- fix-workstream-runner: event-driven runner that resolves merged (with\n  task titles and files) or failed with a structured reason (cycle,\n  orphaned, tasks-failed, nothing-to-fix, timeout).",
          "is_bot": false,
          "headline": "orchestration: review findings become a second task source into the o…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T06:44:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0b2003c4892ff283fd1627238617a9fb0fd24c5e",
          "body": "Local speech-to-text and text-to-speech as real configurable engines\nbehind the EXISTING voice seams (provider registry, VoiceService,\nspoken-turn controller, audio-sink contract):\n\n- Research-blessed defaults (citations in docs/voice-local.md, verified\n  2026-07-14, not from memory): whisper.cpp fo\n[…]\nro cloud dependency and zero usage records; the LIVE host\nround-trip through the provider (auto-skips honestly where engines are\nabsent); metered attribution pricing with provenance; local no-billing.",
          "is_bot": false,
          "headline": "voice: local STT/TTS engines — the free peer beside the premium route",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T05:37:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4215385c6de25c8b164b1de21b20edb6c92e86bc",
          "body": "The platform had zero power-management integration (verified: no\ninhibitor calls anywhere, bare setTimeout scheduling). New platform/power\nmodule:\n\n- Automatic work inhibition: real work holds an idle+sleep inhibitor —\n  running turns, active agents, and queued/running scheduled jobs, bound\n  off th\n[…]\nest lid-switch split; sleep checkpoint + wake catch-up ordering; LIVE\nlogind proof on this host — an unprivileged idle inhibitor appears in\nsystemd-inhibit --list while held and is gone after release.",
          "is_bot": false,
          "headline": "power: sleep ownership — work inhibition, sleep-edge honesty, keep-awake",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T05:23:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cac5a7c518dc5eddd3c6cb05436f1beb4656e090",
          "body": "…dcasts\n\nFull-suite conformance for the four new session verbs:\n\n- Every write:sessions mutator must advertise the broadcast channel it\n  genuinely drives. sessions.toolCalls.cancel advertises runtime.tools (a\n  cancelled call settles as tool events on the runtime bus);\n  sessions.queuedMessages.edi\n[…]\nhe capability\n  reconcile stays green without muting.\n- DirectTransport parity: mapped 'http-only' alongside\n  permissionMode/contextUsage — the same daemon-live-runtime shape, same\n  deliberate skip.",
          "is_bot": false,
          "headline": "live-turn verbs: honest event channels, REST route parity, queue broa…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T05:00:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2972cab4babf11114cac5d6b8f9d57431cd0840e",
          "body": "Work done through the platform that pushes a branch (or opens a PR) in a\nCI repo now creates its own watch — no ceremony:\n\n- New ci-watch/auto-watch: CiWatchAutoMinter taps the shared\n  tool-execution observer seam (a successful exec whose commands include\n  `git push` / `gh pr create`, compound lin\n[…]\nises the\n  existing \"fix this?\" offer; the delivered terminal verdict retires the\n  watch (existing CiWatchService behavior, now proven end-to-end); the\n  scripted ci.watches.create path is untouched.",
          "is_bot": false,
          "headline": "ci-watch: watches mint themselves at the push seam and retire on verdict",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T04:47:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "17d61b2c2ba8e9490549771d4fe8b7d924caab18",
          "body": "The consolidation engine (state/memory-consolidation.ts) was complete but\nhad no production wiring in this runtime: the only driver lived in the\nagent surface behind an agent-local toggle, so the pass effectively never\nran. The daemon — the memory store's single writer — now drives it:\n\n- New Memory\n[…]\nry wake. Wired at RuntimeServices\n  construction beside the store-snapshot scheduler.\n\nConsumer note: the agent repo's local idle-scheduler wiring is superseded\nand retires in its next consumer round.",
          "is_bot": false,
          "headline": "memory: consolidation actually runs — daemon-driven idle + slow schedule",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T04:38:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "01ac5a62e97aff33968946b6ec48721e1648107d",
          "body": "…t diff\n\nThree small interaction wins:\n\n- Per-tool cancel: executeToolCalls opens a per-call AbortSignal through\n  the existing cooperative Tool.execute opts.signal machinery\n  (ToolCallAbortRegistry in the new core/orchestrator-live-turn module).\n  Orchestrator.cancelToolCall(callId) kills ONE runn\n[…]\neted\n  on its side when it adopts (next consumer round).\n\nContract artifacts regenerated (403 -> 407 methods); the four new verbs\nship typed foundation IO entries (untyped count stays at baseline 97).",
          "is_bot": false,
          "headline": "interaction: per-tool cancel, editable queued messages, structural gi…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T04:30:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7ca239e54cc4917a2d5504267fa26e376c50cee9",
          "body": "…ion test\n\nFull-suite fixes for two issues the isolated runs did not surface:\n\n- The default-strip migration rewrote any file containing a default-valued\n  key, including a sparse hand-authored file whose lone key happens to equal\n  its default (display.theme's default is 'vaporwave'). The read-time\n[…]\nnts against the\n  shared module singleton, which other test files pollute when the suite runs\n  files concurrently. The ActivityLogger class is now exported and the test\n  drives an isolated instance.",
          "is_bot": false,
          "headline": "config + logger: gate the strip migration to dumps; isolate the rotat…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T03:56:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "500a6307ba0492de834e68e2ecae2dac6ef9ec68",
          "body": "An append-only file that no one prunes grows without bound (the observed\n22.8 MB activity.md). A new append-only-registry is now the single owner:\nevery append-only store the platform writes (session/agent journals, the\nshared activity log, the local telemetry ledger) registers with an owner\nand a r\n[…]\nsertAppendOnlyStoreRegistered) throws on an unregistered\nid — the same discipline as the feature-gate-id and model-source checks —\nand a membership test enumerates the known stores and fails on drift.",
          "is_bot": false,
          "headline": "retention: one start-time janitor owning every append-only store",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T03:42:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f43e6544de394dc6644a93da4d9832b820b9e784",
          "body": "A settings file changed by another process or by hand needed a restart\nto take effect. ConfigManager.watchConfigFiles() now polls the global,\nproject, and shared-tier files (watchFile, robust to in-place writes and\natomic save-via-rename — the failure mode the custom-provider fs.watch\nnote calls out\n[…]\n\n(its value is unchanged on reload). The watch bookkeeping and reload-diff\nlive in a new config-file-watcher module to keep manager.ts under the\nline cap; the persistence helpers moved to settings-io.",
          "is_bot": false,
          "headline": "config: watch settings files, apply external edits live",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T03:33:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "337b4a0567620b6a91107ebccad958413bd41f88",
          "body": "save() serialized the whole merged config, so every default was baked\nonto disk (freezing it against later default changes) and a set()\nrewrote the entire file, clobbering hand edits made between load and\nset. Now:\n\n- set() persists a single key by read-merge-write into the raw on-disk\n  shape (gene\n[…]\nefaults-known\n  leaves only; unknown keys and differing values kept), and drops a\n  one-line receipt through the announce-once queue exactly once per file.\n  An already-minimal file is left untouched.",
          "is_bot": false,
          "headline": "config: persist only user-set keys, strip previously-frozen defaults",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T03:23:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "240a1628ec8ac246ab25e00d6b55f602cffbede2",
          "body": "The single shared recovery.jsonl let two concurrent sessions clobber\neach other's crash snapshot — the exact collision the consuming surface\nworked around with a .preserved dance. Recovery is now per session:\nrecovery-<sessionId>.jsonl under a scoped recovery/ directory, so\nconcurrent sessions snaps\n[…]\nAnnouncementStore.record shape), then clears the snapshot.\nWith no shared file to guard, the consumer's collision workaround dies;\na source test asserts no .preserved path suffix survives in SDK code.",
          "is_bot": false,
          "headline": "recovery: per-session crash snapshots, silent receipted restore",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T03:13:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "52c011f79cdfde7617ed2fe6243d588ddc84880d",
          "body": "The activity.md debug log appended forever (a real 22.8 MB file was\nobserved). The shared ActivityLogger now rotates the live file to\nactivity.md.1 once it reaches a size cap (10 MB default, configurable),\nkeeping a single backup. The size is tracked with an in-memory byte\ncounter seeded once from the existing file at configure(), so the hot\nwrite path never stats per entry.",
          "is_bot": false,
          "headline": "shared logger: rotate activity.md at a size cap, keep one backup",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T03:08:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "64c67eaf6f195b4b149a4c2c7d16c3df08dd42bc",
          "body": "The SharedSessionKind lockstep guard caught exactly what it exists to catch:\nthe new 'acp' kind was added to the type, broker validator, and wire schema\nbut not the daemon-sdk route validators. SHARED_SESSION_KINDS (and the\nresponse kind union) now carry 'acp', and the lockstep test's own declaration\nsite is updated with it.",
          "is_bot": false,
          "headline": "daemon-sdk: the session-kind lockstep gains 'acp'",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T02:43:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "068e0b97b7d9d3dc7e26711e421177f36b244bfe",
          "body": "…t rows\n\nThe hosting side of the Agent Client Protocol (the agent side already shipped\nin platform/acp): Claude Code, Codex CLI, and opencode run as daemon sessions\nand appear as first-class fleet rows with the existing steer/stop/attention\naffordances.\n\n1. AcpHostService (platform/acp/host.ts): spa\n[…]\ne, no adapter installed) failed with the structured\ninitialize-stage error in bounded time — proving the honest-degradation path\nwith the real binary and motivating the discovery-table decision above.",
          "is_bot": false,
          "headline": "acp: third-party coding agents run as hosted daemon sessions and flee…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T02:33:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d07b49e829f63a89869d2139ed49537fa8858c5b",
          "body": "The S2b parity gate requires every fleet.* contract method to state its\nDirectTransport story; fleet.conflicts.list/.resolve are http-only exactly\nlike the sibling fleet verbs — the TUI reads conflicts off its direct engine\nreference, and the wire verbs exist for remote consumers.",
          "is_bot": false,
          "headline": "test: declare the fleet.conflicts.* DirectTransport disposition",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T02:09:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2212b18f1ee7121984b8cc03af1ee6ceba7298d4",
          "body": "…ktrees act on data\n\nThe fleet package's SDK half, six seams in one coordinated round (shared\ncontract regeneration):\n\n1. ONE waiting-on-human class. ProcessAttentionReason (and the mirrored fleet\nevent/wire enums) gain 'pick' and 'conflict' alongside 'approval'/'input': a\nREADY best-of-N group (eve\n[…]\ny state against a real git repo; approve-and-launch refusal and\none-act launch. Line caps held by extracting the seeded-session starters into\nroutes/seeded-sessions.ts (startCiFixSession re-exported).",
          "is_bot": false,
          "headline": "fleet: waiting-on-human is one state class; picks, conflicts, and wor…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T01:58:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d9fada0831bb40a24781aa9900f6da2e1036905f",
          "body": "The pairing public facade grew 64 B gzip with describeOriginPosture and the\nLAN plain-http notice line; the budget moves to the measured size plus the\nstandard 1.2x headroom.",
          "is_bot": false,
          "headline": "chore: lift the pairing bundle budget for the origin-posture exports",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T01:22:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0376d8c8a8dfc96b4262cec56a54c5b8563848a2",
          "body": "…the full PWA\n\nThe remote-access source of truth (docs/pairing.md, the SDK-side doc consumer\ndocs reference) replaces the bare \"use HTTPS in production\" note with the real\nposture: plain http on a private network is a supported way to use the full\ncockpit, with exactly two consequences stated once (\n[…]\nmended path, with a worked example (tailscale up; tailscale serve --bg\n3423 → the https MagicDNS URL) and the daemon's one-action affordance\n(tailscale.get / tailscale.serve.run) documented alongside.",
          "is_bot": false,
          "headline": "docs: the honest TLS posture — http on your LAN works, tailscale for …",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T01:09:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3830c6333656ee117c5ce2f4ee95f73aebcf7c42",
          "body": "…led not walled\n\nThree coordinated seams (one contract regeneration), under the standing ruling\nthat the daemon NEVER mints certificates — http stays and its problems get\nfixed:\n\n1. The transport's insecure-origin wall comes down for private-network origins.\nnormalizeBaseUrl no longer throws SDK_TRA\n[…]\nncluding a browser-like runtime with no process.env), the labeled\nposture on LAN/localhost/https origins, the posture riding the hand-off, and\ndetection/serve/receipt/publicBaseUrl over a fake runner.",
          "is_bot": false,
          "headline": "transport+pairing: plain http on the LAN is a supported posture, labe…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T01:08:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3bddf14336256c1610c607e10e705e9ebacd1107",
          "body": "…r the new surface\n\nThe new pairing verbs (tokens + hand-off) and the WORKFLOW_CHAIN_FAILED typed\noutcome fields flow into the generated operator reference; the pairing public\nfacade grew with PairingTokenManager + the hand-off link helpers, so its bundle\nbudget is lifted to the measured size plus the standard headroom.",
          "is_bot": false,
          "headline": "chore: regenerate operator docs and lift the pairing bundle budget fo…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T00:49:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "43d03e4ca39d64148cba642654b243212d9eeef5",
          "body": "The WRFC reviewer confirmed that work was DONE (files exist, it parses, it\ncompiles) but not that the work that was done was the work that SHOULD have been\ndone or that it is correct. It now verifies the task contract:\n\n- The reviewer task derives an explicit ACCEPTANCE CHECKLIST from the original\n \n[…]\n\n\nTests pin every policy requirement + the anti-gaming clause, the normalized\nreview record, and a perfect-score-but-unverified-checklist deliverable being\nrejected through the controller's pass gate.",
          "is_bot": false,
          "headline": "wrfc: the reviewer verifies the contract, not the activity",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T00:38:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9f7f170818b41db956e584f65a4eef59ff657356",
          "body": "…ess really started\n\nA standalone daemon that self-promoted to a supervised service wrote its unit's\nExecStart from a dist/-existence heuristic, so a COMPILED binary running outside\na source tree got ExecStart=\"<binary> run <workingDir>/src/daemon/cli.ts\" — a\ndev command line a compiled binary can't\n[…]\nary launch yields the binary\nalone; a source/dev run is flagged not-compiled and never self-promotes (no unit\nwritten, no handover); the existing compiled-promotion and enabled=false paths\nstill hold.",
          "is_bot": false,
          "headline": "daemon: a self-promoted service unit's ExecStart matches how the proc…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T00:33:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f3cc7b5757b26e916fe1aeb8d1bc5e42688852e7",
          "body": "… configurable\n\nAn agent that spends its whole turn budget surfaced only as the prose string\n\"Exceeded maximum turn limit (N)\" inside a generic chain-failed error, forcing\nconsumers to regex prose to tell budget exhaustion from an infrastructure\nfailure. Now:\n\n- The terminal chain outcome carries a \n[…]\n shape, and an end-to-end controller max-turns failure\ncarrying the typed kind + limit + source + settled signal. Reclaimed offsetting\nlines in the touched files to stay under their line-cap ceilings.",
          "is_bot": false,
          "headline": "agents: turn-budget exhaustion is a typed outcome, and the ceiling is…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T00:26:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "28b3b99e7eb3c2135c127126753eb5cb42a4b300",
          "body": "…rtbeat\n\nBun.serve's default 10s idleTimeout tore a quiet SSE stream down ~5s before its\nfirst ~15s heartbeat could arrive. Two coordinated fixes share one source of\ntruth (sse-timing.ts) so the interval and the timeout can never drift into\nanother 10s-vs-15s mismatch:\n\n- The daemon serve path sets \n[…]\nervalMs across the realistic\nrange, prove the immediate-on-open heartbeat and continued keep-alives on a\nquiet stream, and confirm Last-Event-ID replay still delivers missed events\nacross a reconnect.",
          "is_bot": false,
          "headline": "sse: a quiet stream outlives the idle timeout, and self-heals its hea…",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T00:09:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e255d3c862add6ebed1cc5b3a739afa6fb7fa51f",
          "body": "Two pairing seams land together (their generated contract/API artifacts share\none regeneration and cannot be split cleanly).\n\n1. Every pairing mints its own named, individually-revocable operator token.\nA new PairingTokenManager mints a per-device token with a user-visible,\neditable name; only a SHA\n[…]\nand daemon control-plane auth; typed\nIO ships for all eight verbs so the coverage ratchet holds; rename/migrate/\nrevokeShared/complete added to the pairing core-verb exemptions; contracts\nregenerated.",
          "is_bot": false,
          "headline": "pairing: per-device revocable tokens + a one-pass hand-off offer set",
          "author_name": "Mike Davis",
          "author_login": "mgd34msu",
          "committed_at": "2026-07-14T00:01:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        }
      ],
      "releases_count": 100,
      "commits_last_year": 908,
      "latest_release_at": "2026-07-18T01:06:32Z",
      "latest_release_tag": "v1.11.4",
      "releases_from_tags": false,
      "days_since_last_push": 5,
      "active_weeks_last_year": 14,
      "days_since_latest_release": 5,
      "mean_days_between_releases": 0.5
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 71,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "@pellux/goodvibes-sdk",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "goodvibes",
            "sdk",
            "browser",
            "react-native",
            "control-plane"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@pellux/goodvibes-sdk",
          "is_deprecated": false,
          "latest_version": "1.11.4",
          "repository_url": "https://github.com/mgd34msu/goodvibes-sdk",
          "versions_count": 221,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 8289,
          "first_published_at": "2026-04-14T19:05:42.339000Z",
          "latest_published_at": "2026-07-18T01:05:27.591000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        },
        {
          "name": "@pellux/goodvibes-errors",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "goodvibes",
            "sdk",
            "errors",
            "telemetry",
            "transport"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@pellux/goodvibes-errors",
          "is_deprecated": false,
          "latest_version": "1.11.4",
          "repository_url": "https://github.com/mgd34msu/goodvibes-sdk",
          "versions_count": 76,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 9229,
          "first_published_at": "2026-04-14T19:05:14.037000Z",
          "latest_published_at": "2026-07-18T01:04:58.390000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        },
        {
          "name": "@pellux/goodvibes-peer-sdk",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "goodvibes",
            "sdk",
            "peer",
            "distributed-runtime",
            "client"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@pellux/goodvibes-peer-sdk",
          "is_deprecated": false,
          "latest_version": "1.11.4",
          "repository_url": "https://github.com/mgd34msu/goodvibes-sdk",
          "versions_count": 76,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 6812,
          "first_published_at": "2026-04-14T19:05:38.831000Z",
          "latest_published_at": "2026-07-18T01:05:18.506000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        },
        {
          "name": "@pellux/goodvibes-contracts",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "goodvibes",
            "sdk",
            "contracts",
            "operator",
            "peer"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@pellux/goodvibes-contracts",
          "is_deprecated": false,
          "latest_version": "1.11.4",
          "repository_url": "https://github.com/mgd34msu/goodvibes-sdk",
          "versions_count": 76,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 8322,
          "first_published_at": "2026-04-14T19:05:10.634000Z",
          "latest_published_at": "2026-07-18T01:04:55.205000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        },
        {
          "name": "@pellux/goodvibes-toolchain",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "goodvibes",
            "toolchain",
            "ci",
            "release",
            "publish"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@pellux/goodvibes-toolchain",
          "is_deprecated": false,
          "latest_version": "1.11.4",
          "repository_url": "https://github.com/mgd34msu/goodvibes-sdk",
          "versions_count": 5,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 897,
          "first_published_at": "2026-07-17T04:35:41.984000Z",
          "latest_published_at": "2026-07-18T01:05:33.760000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        },
        {
          "name": "@pellux/goodvibes-daemon-sdk",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "goodvibes",
            "sdk",
            "daemon",
            "server",
            "control-plane"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@pellux/goodvibes-daemon-sdk",
          "is_deprecated": false,
          "latest_version": "1.11.4",
          "repository_url": "https://github.com/mgd34msu/goodvibes-sdk",
          "versions_count": 76,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 6704,
          "first_published_at": "2026-04-14T19:05:18.369000Z",
          "latest_published_at": "2026-07-18T01:05:02.323000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        },
        {
          "name": "@pellux/goodvibes-operator-sdk",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "goodvibes",
            "sdk",
            "operator",
            "control-plane",
            "client"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@pellux/goodvibes-operator-sdk",
          "is_deprecated": false,
          "latest_version": "1.11.4",
          "repository_url": "https://github.com/mgd34msu/goodvibes-sdk",
          "versions_count": 76,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 7231,
          "first_published_at": "2026-04-14T19:05:35.580000Z",
          "latest_published_at": "2026-07-18T01:05:15.497000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        },
        {
          "name": "@pellux/goodvibes-terminal-shell",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "goodvibes",
            "sdk",
            "terminal",
            "daemon",
            "gateway"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@pellux/goodvibes-terminal-shell",
          "is_deprecated": false,
          "latest_version": "1.11.4",
          "repository_url": "https://github.com/mgd34msu/goodvibes-sdk",
          "versions_count": 11,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 1926,
          "first_published_at": "2026-07-11T17:29:13.996000Z",
          "latest_published_at": "2026-07-18T01:05:30.685000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0,
        "collected_at": null
      },
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "examples/tsconfig.json",
        "packages/contracts/tsconfig.json",
        "packages/daemon-sdk/tsconfig.json",
        "packages/errors/tsconfig.json",
        "packages/operator-sdk/tsconfig.json",
        "packages/peer-sdk/tsconfig.json",
        "packages/sdk/tsconfig.json",
        "packages/terminal-shell/tsconfig.json",
        "packages/toolchain/tsconfig.json",
        "packages/transport-core/tsconfig.json",
        "packages/transport-http/tsconfig.json",
        "packages/transport-realtime/tsconfig.json",
        "test/workers-wrangler/tsconfig.json",
        "test/workers/tsconfig.json",
        "tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 128443,
      "source_files_sampled": 2419,
      "oversized_source_files": 4,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "examples/package.json",
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "zod",
          "manifest": "packages/contracts/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.3.6"
        },
        {
          "name": "@pellux/goodvibes-contracts",
          "manifest": "packages/daemon-sdk/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@pellux/goodvibes-errors",
          "manifest": "packages/daemon-sdk/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@pellux/goodvibes-transport-core",
          "manifest": "packages/daemon-sdk/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@pellux/goodvibes-contracts",
          "manifest": "packages/operator-sdk/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@pellux/goodvibes-errors",
          "manifest": "packages/operator-sdk/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@pellux/goodvibes-transport-http",
          "manifest": "packages/operator-sdk/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "zod",
          "manifest": "packages/operator-sdk/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.3.6"
        },
        {
          "name": "@pellux/goodvibes-contracts",
          "manifest": "packages/peer-sdk/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@pellux/goodvibes-errors",
          "manifest": "packages/peer-sdk/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@pellux/goodvibes-transport-http",
          "manifest": "packages/peer-sdk/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@pellux/goodvibes-contracts",
          "manifest": "packages/sdk/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@pellux/goodvibes-daemon-sdk",
          "manifest": "packages/sdk/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@pellux/goodvibes-errors",
          "manifest": "packages/sdk/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@pellux/goodvibes-operator-sdk",
          "manifest": "packages/sdk/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@pellux/goodvibes-peer-sdk",
          "manifest": "packages/sdk/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@pellux/goodvibes-toolchain",
          "manifest": "packages/sdk/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@pellux/goodvibes-transport-core",
          "manifest": "packages/sdk/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@pellux/goodvibes-transport-http",
          "manifest": "packages/sdk/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@pellux/goodvibes-transport-realtime",
          "manifest": "packages/sdk/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@pellux/goodvibes-contracts",
          "manifest": "packages/terminal-shell/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@pellux/goodvibes-sdk",
          "manifest": "packages/terminal-shell/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@pellux/goodvibes-errors",
          "manifest": "packages/transport-core/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@pellux/goodvibes-contracts",
          "manifest": "packages/transport-http/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@pellux/goodvibes-errors",
          "manifest": "packages/transport-http/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@pellux/goodvibes-transport-core",
          "manifest": "packages/transport-http/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "zod",
          "manifest": "packages/transport-http/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.3.6"
        },
        {
          "name": "@pellux/goodvibes-contracts",
          "manifest": "packages/transport-realtime/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@pellux/goodvibes-errors",
          "manifest": "packages/transport-realtime/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@pellux/goodvibes-transport-core",
          "manifest": "packages/transport-realtime/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@pellux/goodvibes-transport-http",
          "manifest": "packages/transport-realtime/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 0,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 29
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "mgd34msu",
          "commits": 906,
          "avatar_url": "https://avatars.githubusercontent.com/u/18431027?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "release.yml",
        "reusable-binary-matrix.yml",
        "reusable-gh-release.yml",
        "reusable-npm-publish.yml",
        "reusable-release-verify.yml",
        "voice-runtimes.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 9,
            "reason": "binaries present in source code",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 10,
            "reason": "project is fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 10,
            "reason": "all dependencies are pinned",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 10,
            "reason": "GitHub workflow tokens follow principle of least privilege",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "14 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "4dc6f9fa71b815ac90ae734ad1a9ec91bb932994",
        "ran_at": "2026-07-23T10:40:21Z",
        "aggregate_score": 5.1,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-18T01:06:35Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": null,
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/mgd34msu/goodvibes-sdk",
    "host": "github.com",
    "name": "goodvibes-sdk",
    "owner": "mgd34msu"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 56,
      "inputs": {
        "security": 51,
        "vitality": 80,
        "community": 40,
        "governance": 34,
        "engineering": 72
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 80,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 74,
            "inputs": {
              "commits_last_year": 908,
              "human_commit_share": 1,
              "days_since_last_push": 5,
              "active_weeks_last_year": 14
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "14/52 weeks with commits",
                "points": 9.7,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 14
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "908 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 908
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 100,
              "latest_release_tag": "v1.11.4",
              "releases_from_tags": false,
              "days_since_latest_release": 5,
              "mean_days_between_releases": 0.5
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "100 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 100
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~0.5 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 0.5
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 40,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 57,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "good",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 78,
            "inputs": {
              "packages": [
                "@pellux/goodvibes-sdk",
                "@pellux/goodvibes-errors",
                "@pellux/goodvibes-peer-sdk",
                "@pellux/goodvibes-contracts",
                "@pellux/goodvibes-toolchain",
                "@pellux/goodvibes-daemon-sdk",
                "@pellux/goodvibes-operator-sdk",
                "@pellux/goodvibes-terminal-shell"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 49410
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "49,410 downloads/month across npm",
                "points": 62.6,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 49410,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 34,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "critical",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "merged_prs": 0,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 29
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "0/29 decided PRs merged",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 0,
                      "decided": 29
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 43,
            "inputs": {
              "followers": 1,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "mgd34msu",
              "public_repos": 22,
              "account_age_days": 3753
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "1 followers of mgd34msu",
                "points": 2.2,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 1,
                      "login": "mgd34msu"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "22 public repos, account ~10 yr old",
                "points": 21.9,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 22
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 10
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "@pellux/goodvibes-sdk",
                "@pellux/goodvibes-errors",
                "@pellux/goodvibes-peer-sdk",
                "@pellux/goodvibes-contracts",
                "@pellux/goodvibes-toolchain",
                "@pellux/goodvibes-daemon-sdk",
                "@pellux/goodvibes-operator-sdk",
                "@pellux/goodvibes-terminal-shell"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 5
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "8 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 8,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 5 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "221 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 221
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 72,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 60,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "7 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": "https://goodvibes.sh",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://goodvibes.sh",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 51,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests, Packaging. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests",
                    "packaging"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 51,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 5.1
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "binaries present in source code",
                "points": 6.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is fuzzed",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "all dependencies are pinned",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "GitHub workflow tokens follow principle of least privilege",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "14 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 50,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.96,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "96 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 96,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "at_risk",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 43,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "examples/tsconfig.json",
                "packages/contracts/tsconfig.json",
                "packages/daemon-sdk/tsconfig.json",
                "packages/errors/tsconfig.json",
                "packages/operator-sdk/tsconfig.json",
                "packages/peer-sdk/tsconfig.json",
                "packages/sdk/tsconfig.json",
                "packages/terminal-shell/tsconfig.json",
                "packages/toolchain/tsconfig.json",
                "packages/transport-core/tsconfig.json",
                "packages/transport-http/tsconfig.json",
                "packages/transport-realtime/tsconfig.json",
                "test/workers-wrangler/tsconfig.json",
                "test/workers/tsconfig.json",
                "tsconfig.json"
              ],
              "agent_commit_share": 0,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "examples/tsconfig.json, packages/contracts/tsconfig.json, packages/daemon-sdk/tsconfig.json, packages/errors/tsconfig.json, packages/operator-sdk/tsconfig.json, packages/peer-sdk/tsconfig.json, packages/sdk/tsconfig.json, packages/terminal-shell/tsconfig.json, packages/toolchain/tsconfig.json, packages/transport-core/tsconfig.json, packages/transport-http/tsconfig.json, packages/transport-realtime/tsconfig.json, test/workers-wrangler/tsconfig.json, test/workers/tsconfig.json, tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples/tsconfig.json, packages/contracts/tsconfig.json, packages/daemon-sdk/tsconfig.json, packages/errors/tsconfig.json, packages/operator-sdk/tsconfig.json, packages/peer-sdk/tsconfig.json, packages/sdk/tsconfig.json, packages/terminal-shell/tsconfig.json, packages/toolchain/tsconfig.json, packages/transport-core/tsconfig.json, packages/transport-http/tsconfig.json, packages/transport-realtime/tsconfig.json, test/workers-wrangler/tsconfig.json, test/workers/tsconfig.json, tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "all dependencies are pinned",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 128443,
              "source_files_sampled": 2419,
              "oversized_source_files": 4
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "4/2419 source files over 60KB",
                "points": 54.9,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 2419,
                      "oversized": 4
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
    "deps.dev does not index npm:@pellux/goodvibes-sdk@1.11.4; advisories assessed against the repository dependency graph instead"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-23T10:40:28.713882Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/m/mgd34msu/goodvibes-sdk.svg",
  "full_name": "mgd34msu/goodvibes-sdk",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsnpm.