Public record
Software health reportschema 0.27.0 · metrics 1.13.0 · 2026-07-28 08:36 UTC

moonD4rk / things3

AI-friendly Go library and CLI for Things 3 on macOS: full typed read API, type-safe URL scheme writes, machine-readable JSON everywhere

GoApache-2.0★ 2 stars⑂ 0 forkssince Nov 2025View on GitHub ↗

moonD4rk/things3 holds a health index of 58 out of 100, placing it in the Moderate band. It scores highest on Vitality (77/100) and lowest on Community & Adoption (24/100). It was last updated 1 day ago. A single contributor accounts for most of its recent work.

58
overall / 100
Moderate

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

58
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

RogerPersonal account
1,165 followers20 public repossince Dec 2016

This repository is owned by a personal account. A single-owner project carries more continuity risk than an organization-backed one.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publish
Gogithub.com/moond4rk/things3v0.5.5-1216 days ago

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

77Good · 22% of overall
How it's scored
36/36Push recency — last push 1 days ago
9/36Commit cadence — 13/52 weeks with commits
15.5/18Commit volume — 52 commits in the last year
7/10OpenSSF Scorecard: Maintained — 9 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 7
Inputs used
commits_last_year52
human_commit_share0.788
days_since_last_push1
active_weeks_last_year13
How it's scored
27/27Ships releases — 10 releases published
36/36Release recency — latest release 16 days ago
27/27Release cadence — a release every ~24.8 days
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Inputs used
releases_count10
latest_release_tagv0.5.5
releases_from_tagsno
days_since_latest_release16
mean_days_between_releases24.8

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

24Critical · 18% of overall
How it's scored
0/60Stars — 2 stars
0/25Forks — 0 forks
0/15Watchers — 1 watchers
Inputs used
forks0
stars2
watchers1
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (Apache-2.0)
0/18CONTRIBUTING guide
0/13.5Code of conduct
0/7.2Issue template
0/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingno
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

61Moderate · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
0/22.5Commit distribution — top contributor authored 100% of commits
1.4/13.5Contributor breadth — 1 contributors
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Inputs used
bus_factor1
contributors_sampled1
top_contributor_share1
How it's scored
46.8/46.8Issue resolution — 100% of issues closed
38.2/38.3PR acceptance — 43/43 decided PRs merged
0/15OpenSSF Scorecard: Code-Review — Found 0/28 approved changesets -- score normalized to 0
Inputs used
merged_prs43
open_issues0
closed_issues15
issue_closed_ratio1
closed_unmerged_prs0
How it's scored
10/30Ownership backing — personal (user) account
0/20Verified domain — not applicable to user accounts
22/25Owner reach — 1,165 followers of moonD4rk
21.6/25Track record — 20 public repos, account ~9 yr old
Inputs used
followers1,165
owner_typeUser
is_verified
owner_loginmoonD4rk
public_repos20
account_age_days3,526
Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.
How it's scored
25/25Published & resolvable — 1 package(s) on go
35/35Publish recency — latest publish 16 days ago
20/20Version history — 12 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packagesgithub.com/moond4rk/things3
ecosystemsgo
any_deprecatedno
min_days_since_publish16

Engineering Quality

Are baseline engineering and documentation practices in place?

70Good · 20% of overall
How it's scored
24/24CI workflows — 2 workflow(s)
24/24Tests present
16/16Linter config — .golangci.yml
0/9.6Pre-commit hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 22 out of 22 merged PRs checked by a CI test -- score normalized to 10
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configyes
has_precommit_configno

Documentation

50Moderate
How it's scored
30/30README
0/25Documentation directory
0/15Documentation / homepage site
10/10Repository description
10/10Topics — 6 topics
0/10Wiki
Inputs used
topicsgolang, gtd, macos, sqlite3, things, things3
has_wikino
homepage
has_readmeyes
has_docs_dirno
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

48At risk · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
2.2/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 22 out of 22 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/28 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
5.2/7.5Maintained — 9 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 7
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated18
scorecard_versionv5.5.0
checks_inconclusive0
scorecard_aggregate4.8

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

74Good · 0% of overall
How it's scored
45/45Agent instructions — CLAUDE.md
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 40 of 41 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share0.976
agent_instruction_filesCLAUDE.md
agent_instruction_max_bytes8,722
How it's scored
12.6/18One-command bootstrap — cmd/things3/go.mod, go.mod (toolchain convention, no task runner)
22/22Automated tests
11/11Lint / format config — .golangci.yml
11/11Static type checking — Go (statically typed)
10/10Reproducible environment — lockfile
0/10Demonstrated agent practice — no agent-authored commits among the last 52
8/8Automated maintenance — 2 of the last 52 commits are automated dependency updates
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Inputs used
has_nixno
has_testsyes
lockfilesgo.sum
has_dockerfileno
typed_languageyes
bootstrap_files
has_devcontainerno
has_linter_configyes
typecheck_configs
agent_commit_share0
toolchain_manifestscmd/things3/go.mod, go.mod
dependency_bot_commit_share0.038
How it's scored
45/45Type-checkable code — Go (statically typed)
54.5/55Manageable file sizes — 1/115 source files over 60KB
Inputs used
primary_languageGo
largest_source_bytes73,277
source_files_sampled115
oversized_source_files1
How it's scored
0/40API schema (OpenAPI/GraphQL/proto)
20/20MCP server
0/40Runnable examples
Inputs used
example_dirs
has_mcp_signalyes
api_schema_files

Key facts

2GitHub stars
1contributors
52commits, last 12 months
1days since last push
10releases
1bus factor
0open issues
Gopackage ecosystems

Data collection warnings

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

More detail

OpenSSF Scorecard 4.8 / 10
4.8aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-28 08:35 UTC

10Binary-Artifactsno binaries found in the repo
3Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests22 out of 22 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/28 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
7Maintained9 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 7
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
10Vulnerabilities0 existing vulnerabilities detected
Direct dependencies 2
RegistryPackageVersion constraintManifest
Gogithub.com/mattn/go-sqlite3v1.14.48go.mod
Gogithub.com/stretchr/testifyv1.11.1go.mod
All dependencies not collected

The resolved dependency set could not be collected for this report: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [
        "golang",
        "gtd",
        "macos",
        "sqlite3",
        "things",
        "things3"
      ],
      "is_fork": false,
      "size_kb": 541,
      "has_wiki": false,
      "homepage": null,
      "languages": {
        "Go": 725238
      },
      "pushed_at": "2026-07-26T10:48:26Z",
      "created_at": "2025-11-29T04:23:34Z",
      "owner_type": "User",
      "updated_at": "2026-07-26T10:49:12Z",
      "description": "AI-friendly Go library and CLI for Things 3 on macOS: full typed read API, type-safe URL scheme writes, machine-readable JSON everywhere",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Go",
      "significant_languages": [
        "Go"
      ]
    },
    "owner": {
      "blog": "moonD4rk.com",
      "name": "Roger",
      "type": "User",
      "login": "moonD4rk",
      "company": null,
      "location": "Singapore",
      "followers": 1165,
      "avatar_url": "https://avatars.githubusercontent.com/u/24284231?v=4",
      "created_at": "2016-12-01T02:09:40Z",
      "is_verified": null,
      "public_repos": 20,
      "account_age_days": 3526
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.5.5",
          "kind": "patch",
          "published_at": "2026-07-11T14:37:56Z"
        },
        {
          "tag": "v0.5.4",
          "kind": "patch",
          "published_at": "2026-02-23T07:53:57Z"
        },
        {
          "tag": "v0.5.3",
          "kind": "patch",
          "published_at": "2026-02-21T02:48:01Z"
        },
        {
          "tag": "v0.5.1",
          "kind": "patch",
          "published_at": "2026-02-21T02:24:30Z"
        },
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2026-02-20T10:14:17Z"
        },
        {
          "tag": "v0.4.0",
          "kind": "minor",
          "published_at": "2026-01-01T13:58:42Z"
        },
        {
          "tag": "v0.3.0",
          "kind": "minor",
          "published_at": "2025-12-28T14:33:09Z"
        },
        {
          "tag": "v0.2.1",
          "kind": "patch",
          "published_at": "2025-12-17T16:00:19Z"
        },
        {
          "tag": "v0.2.0",
          "kind": "minor",
          "published_at": "2025-12-15T12:03:53Z"
        },
        {
          "tag": "v0.1.0",
          "kind": "minor",
          "published_at": "2025-11-30T17:14:10Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "32638c75be1dc61d5aa178cb91ad7ecd166673a6",
          "body": "Bumps [actions/setup-go](https://github.com/actions/setup-go) from 6 to 7.\n- [Release notes](https://github.com/actions/setup-go/releases)\n- [Commits](https://github.com/actions/setup-go/compare/v6...v7)\n\n---\nupdated-dependencies:\n- dependency-name: actions/setup-go\n  dependency-version: '7'\n  depen\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "ci: bump actions/setup-go from 6 to 7 (#57)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-26T10:48:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "03742a1a2a5d6203353be9f495c9035a5da6a303",
          "body": "…#58)\n\nBumps the go-minor-patch group with 1 update: [github.com/mattn/go-sqlite3](https://github.com/mattn/go-sqlite3).\n\n\nUpdates `github.com/mattn/go-sqlite3` from 1.14.47 to 1.14.48\n- [Release notes](https://github.com/mattn/go-sqlite3/releases)\n- [Commits](https://github.com/mattn/go-sqlite3/com\n[…]\nsion-update:semver-patch\n  dependency-group: go-minor-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore: bump github.com/mattn/go-sqlite3 in the go-minor-patch group (…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-26T10:48:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d31024a33400c490e02c5662000dc6b9a893a462",
          "body": "Co-authored-by: moond4rk-ci[bot] <299850723+moond4rk-ci[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore: release v0.5.5 (#56)",
          "author_name": "moond4rk-ci[bot]",
          "author_login": "moond4rk-ci[bot]",
          "committed_at": "2026-07-11T14:39:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f40df5b857d3e86d8f5540817276e43e1aeb4cb6",
          "body": null,
          "is_bot": false,
          "headline": "feat: make the MCP server token-efficient (#55)",
          "author_name": "Roger",
          "author_login": "moonD4rk",
          "committed_at": "2026-07-11T14:35:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "286a7bb139c71fbe8cb7b7afb9ff2d95ebe571d1",
          "body": null,
          "is_bot": false,
          "headline": "ci: add Dependabot and upgrade all dependencies (#54)",
          "author_name": "Roger",
          "author_login": "moonD4rk",
          "committed_at": "2026-07-05T05:17:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "71c70cff6d51e31b2dea560081f34b171ea7c48c",
          "body": "* ci: push homebrew formula via moond4rk-ci app token\n\nReplace the long-lived Homebrew PAT with a short-lived moond4rk-ci app token scoped to homebrew-tap, and attribute the formula-bump commit to moond4rk-ci[bot].\n\n* ci: open the CLI release bump as an auto-merged bot PR\n\nThe CLI go.mod bump now reaches main through a moond4rk-ci PR that\nauto-merges once CI passes, instead of a direct push. Opening it with the\napp token rather than the default GITHUB_TOKEN is what lets CI run on it.",
          "is_bot": false,
          "headline": "ci: push homebrew formula via moond4rk-ci app token (#53)",
          "author_name": "Roger",
          "author_login": "moonD4rk",
          "committed_at": "2026-07-04T16:35:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "678e28d599bba42aa1dab0da1fdf06892ecc3435",
          "body": "AI assistants previously needed a separate, unverified, unresolved\nbinary. The stdio server reuses the CLI's resolve/verify pipeline so\nmodel-driven writes get the same guarantees as human ones (RFC 014).",
          "is_bot": false,
          "headline": "feat: serve Things over MCP with a things3 mcp subcommand (#52)",
          "author_name": "Roger",
          "author_login": "moonD4rk",
          "committed_at": "2026-07-03T13:46:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d9e9435bc0b1448b8c338e2cc9d55d5e5b8c3f7e",
          "body": "* feat: rebuild CLI ground-up with unified flags and verified writes\n\nThe list-based CLI matched neither the app's mental model nor agent\nconsumption. Views become commands, writes verify against the DB, and\nmachine output is a self-describing paginated envelope (RFC 012/013).",
          "is_bot": false,
          "headline": "feat: CLI ground-up rebuild with unified flags and verified writes (#51)",
          "author_name": "Roger",
          "author_login": "moonD4rk",
          "committed_at": "2026-07-02T16:40:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6a60d68be466c6528f77ce4d5e96a4f3cf5c3b04",
          "body": "* fix: resolve audit findings across database, scheme, builders, and CLI\n\nCross-verified fixes for 25 confirmed defects: timezone model, filter\nlogic (HasProject, LIKE escaping, NULL visible), copy-on-write query\nbuilders, URL scheme build idempotency and validation, and CLI fixes\nwith first test co\n[…]\n and strengthen ParseWhen error test\n\nAddress Copilot review: the doc now matches the retry-on-next-Build\nbehavior, and the empty-input test case no longer relies on a\nvacuous ErrorContains assertion.",
          "is_bot": false,
          "headline": "fix: resolve confirmed audit findings across all layers (#50)",
          "author_name": "Roger",
          "author_login": "moonD4rk",
          "committed_at": "2026-07-02T06:36:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "47294176fb3433f209c1c45f2f3018e85cbc95b9",
          "body": "* feat: add todo/project detail commands and fix list views\n\n- Add `todo` command with UUID prefix, --title, --search modes\n- Add `project` command with detail view showing incomplete todos\n- Fix `list today` to use three-query composition (regular + yellow dot + overdue)\n- Fix `list upcoming` to use Start().Someday() instead of Anytime()\n- Fix `list someday` to exclude tasks with scheduled dates\n- Add detail text output for single todo/project views\n- Add RFC 010 documenting CLI design",
          "is_bot": false,
          "headline": "feat: add todo/project detail commands and fix list views (#48)",
          "author_name": "Roger",
          "author_login": "moonD4rk",
          "committed_at": "2026-03-10T14:57:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8176268a5c9289fd1bcb3ec005eae86205666baa",
          "body": "* feat: Redesign domain model architecture and query structure\n\n- Introduce a new domain model layer to enhance data management between the SQLite database and the public API.\n- Improve type safety and consistency by establishing separate domain types for various entities (Todo, Project, Area, Tag, \n[…]\nincomplete, 10 anytime)\n\n* fix: resolve golangci-lint modernize/newexpr and gosec warnings\n\n- Replace ptr() helper with new(expr) syntax (Go 1.26)\n- Add gosec nolint for t.TempDir() path in thingstest",
          "is_bot": false,
          "headline": "feat: Redesign domain model architecture and query structure (#46)",
          "author_name": "Roger",
          "author_login": "moonD4rk",
          "committed_at": "2026-03-08T16:27:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d87a89e04447c52fc28ed20901eda2dab2b6a233",
          "body": "* refactor: update go version to 1.26.0 for all modules\n\n- Update Go version to 1.26.0 to utilize newer language features and optimizations\n- Ensure compatibility with the latest libraries and tools\n- Update dependencies to reflect changes in Go modules for the project\n\n* refactor: update golangci-l\n[…]\nor quicker feedback\n- Enhance coverage report management by only uploading reports from Ubuntu platform\n- Refactor CI workflow to improve readability and maintenance through consistent setup and steps",
          "is_bot": false,
          "headline": "refactor: update go version to 1.26.0 for all modules (#47)",
          "author_name": "Roger",
          "author_login": "moonD4rk",
          "committed_at": "2026-03-03T02:56:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "98708c0651a82a399519d4d798280b8054762f3c",
          "body": null,
          "is_bot": true,
          "headline": "chore: release v0.5.4",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-02-23T07:53:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "33e007998023e59b40dfc6bdaf27afbd01516161",
          "body": "Restructure test infrastructure:\n- Replace db_test.go and utils_test.go with client_test.go\n- Add thingstest package for reusable test fixture database\n- Update test database and typos config\n\nStrengthen weak test assertions:\n- Replace NoError-only checks with content validation and count assertions\n[…]\n Len-only checks to ElementsMatch with precise UUID sets\n- Add cross-validation for complementary filters (Before + OnOrAfter == Exists)\n- Fix require -> assert in loops for complete failure reporting",
          "is_bot": false,
          "headline": "test: restructure test infrastructure and strengthen assertions (#44)",
          "author_name": "Roger",
          "author_login": "moonD4rk",
          "committed_at": "2026-02-22T16:02:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "917126c8be629579e9c40bca30fee4e67c5dc51d",
          "body": null,
          "is_bot": true,
          "headline": "chore: release v0.5.3",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-02-21T02:47:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "749648d6f3bb90c064624e967cdd07bfc23bff05",
          "body": "- Specify installation directory for improved organization\n- Include user instructions for Things 3 database access\n- Update test command to ensure compatibility with `things3` version\n- Update commit author and email for automation with `github-actions[bot]`",
          "is_bot": false,
          "headline": "fix: update .goreleaser.yml formula file location (#42)",
          "author_name": "Roger",
          "author_login": "moonD4rk",
          "committed_at": "2026-02-21T02:45:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "981a7a0a9d2410f3f8c76e692efa9be96768c443",
          "body": null,
          "is_bot": true,
          "headline": "chore: release v0.5.2",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-02-21T02:43:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f131fa6381a9d22707d5ef1498d459efe1e1ba46",
          "body": null,
          "is_bot": true,
          "headline": "chore: release v0.5.1",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-02-21T02:23:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "52337d40ce7496fcef4183f7cc3c00dcfc6d59b2",
          "body": "* chore: add homebrew tap formula release\n\n- Add new environment variable for GitHub token to workflow configuration\n- Update GoReleaser version and skip `validate` step in build process\n- Specify details for new brew formula and set up commit author information\n- Include installation, testing, and \n[…]\nrove user experience by providing more detailed installation instructions\n- Streamline setup process by removing outdated and ambiguous steps\n- Enhance clarity by adding specific notes for macOS users",
          "is_bot": false,
          "headline": "chore: add homebrew tap formula release (#41)",
          "author_name": "Roger",
          "author_login": "moonD4rk",
          "committed_at": "2026-02-21T02:08:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "92744849b7dd96a79fd50471b33f8f090b2b41a2",
          "body": "- Implement a CLI functionality for querying tasks from the terminal for better user interaction\n- Update RFC status for various RFCs to reflect their progress and implementation\n- Streamline add and update operations with a builder pattern for cleaner code\n- Enhance user access and type safety in the URL Scheme API for a better user experience",
          "is_bot": false,
          "headline": "fix: add version and build info for things3 cli (#40)",
          "author_name": "Roger",
          "author_login": "moonD4rk",
          "committed_at": "2026-02-20T11:22:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8b90e38ebb933b126c9c42431dc42ec6c36b1cdb",
          "body": "GoReleaser validates that the current tag points to HEAD, but in the\ntwo-tag release flow, the library tag (v0.5.0) is on commit A while\nHEAD advances to commit B after the CLI go.mod update. Adding\n--skip=validate bypasses this check since GORELEASER_CURRENT_TAG\nalready provides the correct version.\n\nAlso make the commit step idempotent so the workflow can be safely\nre-triggered without failing on \"nothing to commit\".",
          "is_bot": false,
          "headline": "fix: add --skip=validate for two-tag release workflow (#39)",
          "author_name": "Roger",
          "author_login": "moonD4rk",
          "committed_at": "2026-02-20T10:12:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "10204f43c1716fc7d4b78209e612f66d3fdb8f02",
          "body": null,
          "is_bot": true,
          "headline": "chore: release v0.5.0",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-02-20T10:03:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bafb6b17258211dfdc9cfd1d034818ef6241ff71",
          "body": "- Remove unnecessary test functions in output_test.go\n- Enhance testing coverage for task formatting and handling in writeTasks functions\n- Update dependency version of `github.com/mattn/go-sqlite3` for improved functionality and bug fixes\n- Configure git settings and update CLI module for GitHub Actions and Go module system integration",
          "is_bot": false,
          "headline": "refactor: remove output_test.go file (#38)",
          "author_name": "Roger",
          "author_login": "moonD4rk",
          "committed_at": "2026-02-20T09:56:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "78825d01d73e8acfdf3c3de061042a1c0890579f",
          "body": "…me layers (#37)\n\n- Fix P0 bug: buildChecklistItemsSQL used colModificationDate for both created\n  and modified columns, now correctly uses colCreationDate for creation date\n- Fix thread safety: change db.queryCount from int to atomic.Int64\n- Update doc.go examples to use current NewClient() API ins\n[…]\nconsistency with other builders\n- Add UnmarshalJSON/UnmarshalYAML for TaskType and Status enums\n- Add CLI output tests and enum round-trip tests\n- Extract string constants to fix goconst linter issues",
          "is_bot": false,
          "headline": "fix: address code quality issues across database, types, and URL sche…",
          "author_name": "Roger",
          "author_login": "moonD4rk",
          "committed_at": "2026-02-20T02:29:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c1e6257bf5a9bd8d2e7d149fe027554f491f5f50",
          "body": "Revert the following commits created by release workflow testing:\n- 39cbc5b chore: release v0.5.0\n- 10936c3 chore: release v0.5.0-rc.2\n- 5451926 fix: use local replace for go mod tidy in release workflow (#35)\n- 6deb20f chore: release v0.5.0-rc.1\n\nReset cmd/things3/go.mod back to v0.4.0 and restore release.yml\nto the state from #34.",
          "is_bot": false,
          "headline": "revert: remove release test commits (#36)",
          "author_name": "Roger",
          "author_login": "moonD4rk",
          "committed_at": "2026-02-06T13:17:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "39cbc5bc84b19e6c35a4d27035e44103f69fe5ae",
          "body": null,
          "is_bot": true,
          "headline": "chore: release v0.5.0",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-02-06T13:07:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "10936c3b96633f2c151cbdffa009045359282d71",
          "body": null,
          "is_bot": true,
          "headline": "chore: release v0.5.0-rc.2",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-02-06T13:05:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "54519267b28a96eb27e5308dcad5e49e2a23423f",
          "body": "go mod tidy runs before the tag is created, so the version doesn't\nexist on the module proxy yet. Use replace directive with local code\nfor tidy, then set the formal version for release.",
          "is_bot": false,
          "headline": "fix: use local replace for go mod tidy in release workflow (#35)",
          "author_name": "Roger",
          "author_login": "moonD4rk",
          "committed_at": "2026-02-06T13:04:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6deb20fbcb66d249b7f2440ec9ffa1db01d6b386",
          "body": null,
          "is_bot": true,
          "headline": "chore: release v0.5.0-rc.1",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-02-04T14:00:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "83f99970f8e0ebf84a7f28e0d12bb1157e8c6d09",
          "body": "- Change release workflow to manual trigger (workflow_dispatch)\n- User inputs version number, workflow handles:\n  - Update cmd/things3/go.mod dependency\n  - Commit and create tag\n  - Push to main and tag\n  - Run GoReleaser\n- Update goreleaser config to version 2\n- Fix deprecated archives.format syntax\n- Exclude \"chore: release\" commits from release notes\n\nThis ensures version consistency across:\n- Git tag\n- cmd/things3/go.mod\n- Binary version (via ldflags)\n- go install compatibility",
          "is_bot": false,
          "headline": "feat: improve release workflow with manual trigger (#34)",
          "author_name": "Roger",
          "author_login": "moonD4rk",
          "committed_at": "2026-02-04T13:58:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "895c2bd7816a3243396fa4824e3d0b32befdca5a",
          "body": "- Improve compatibility by adding version 2 to .goreleaser.yml\n- Enhance flexibility by updating archive formats to include tar.gz\n- Provide more detailed information by changing name_template to include\n  architecture information",
          "is_bot": false,
          "headline": "fix: add version 2 to goreleaser.yml (#33)",
          "author_name": "Roger",
          "author_login": "moonD4rk",
          "committed_at": "2026-02-04T13:38:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b367857d8a43e3b90673674cbc8f71d121792cc4",
          "body": "* chore: create GitHub Actions workflow for tag pushes\n\n- Automate the release process to streamline the creation of GitHub releases\n- Ensure the CLI is built with the correct version extracted from the tag\n- Include release notes and attach the built CLI in the GitHub release\n\n* refactor: update go\n[…]\nnd use v6 across the board\n- Modify go.mod file for local development and set required version for release build\n- Ensure clean release by updating goreleaser version and including necessary arguments",
          "is_bot": false,
          "headline": "chore: create GitHub Actions workflow for tag pushes (#31)",
          "author_name": "Roger",
          "author_login": "moonD4rk",
          "committed_at": "2026-02-04T13:31:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "23f2b66e332ef4490b2dd036d867be54cd76991d",
          "body": "* refactor: update CLI development process formulas\n\n- Track Things3 binary and go module files for version control\n- Include version information in the `things3` command\n- Update dependencies and versions in `go.mod` files\n- Enhance CLI development using factory function pattern with Cobra\n\n* feat:\n[…]\ngo-sqlite3 version to v1.14.33\n\n- Update go-sqlite3 version for improved compatibility\n- Remove dependency on older version to avoid issues\n- Potential fix for problems with SQLite database operations",
          "is_bot": false,
          "headline": "feat: update CLI development process formulas (#29)",
          "author_name": "Roger",
          "author_login": "moonD4rk",
          "committed_at": "2026-02-04T10:49:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "52b72c740057bcd0033509c6c61651a212b56081",
          "body": "…#28)",
          "is_bot": false,
          "headline": "feat: Refactor API design to unify client and interface abstraction (…",
          "author_name": "Roger",
          "author_login": "moonD4rk",
          "committed_at": "2026-02-02T14:27:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "14a0f2cf66b57e9594d551b00294a20128025d4c",
          "body": "* fix: refactor db_options for internal clarity\n\n- Refactor and rename `WithPrintSQL` to improve clarity and specificity\n- Add `client_options.go` file to define `clientOptions` struct and `ClientOption` functional options\n- Implement methods for client creation, task querying, and token management\n\n[…]\no use `AddTodo()` instead of `Todo()` for consistency\n- Update implementation to use `NewClient()` as single entry point for most use cases\n- Emphasize clear intent with action-expressing method names",
          "is_bot": false,
          "headline": "feat: Refactor and unify Things 3 client architecture (#26)",
          "author_name": "Roger",
          "author_login": "moonD4rk",
          "committed_at": "2026-01-02T08:01:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "49de3b568390b9266c423e3f3e97d45787fe6d6b",
          "body": "* refactor: Refactor scheduling functions to use time.Time types\n* feat: Refactor task querying to use CreatedAfter filter\n* feat: Add scheduling support with comprehensive date tests\n* fix: Handle zero time values in deadline functions",
          "is_bot": false,
          "headline": "feat: format scheduling functions to use time.Time types (#23)",
          "author_name": "Roger",
          "author_login": "moonD4rk",
          "committed_at": "2026-01-01T13:54:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "82287d6ab4c20e391964999defd1097e5666dca5",
          "body": "* feat: Improve URL handling in Things3 application integration\n\n- Refactor the script to specifically open URLs in the Things3 application.\n- Improve method execution for enhanced user experience.\n\n* feat: Enhance navigation options for foreground and background execution\n\n- Enhance the navigation \n[…]\nying comments in `executeNavigation` method.\n- Enhance understanding of foreground and background execution within the documentation.\n- Ensure consistency in terminology related to execution contexts.",
          "is_bot": false,
          "headline": "feat: Improve URL handling in Things3 application integration (#22)",
          "author_name": "Roger",
          "author_login": "moonD4rk",
          "committed_at": "2026-01-01T08:26:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "68644d98ea74e1e592450499d48983c24b37b719",
          "body": "- Introduce comprehensive reminder functionality across builders, enhancing task management.\n- Implement validation and error handling for reminder times, ensuring accurate user input.\n- Integrate reminder settings within project and to-do structures, facilitating automatic scheduling.",
          "is_bot": false,
          "headline": "feat: Implement reminder functionality for to-dos and projects (#19)",
          "author_name": "Roger",
          "author_login": "moonD4rk",
          "committed_at": "2025-12-28T14:25:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2c3ac56866e3c2d50fbb726b8fd60a23ddd775e0",
          "body": "* feat: Enhance URL Scheme with Execution Capabilities\n\n- Revise the API to enhance type safety and execution capabilities for URL scheme operations.\n- Rename and restructure key functions and files to reflect a clearer distinction between client and database interactions.\n- Introduce the Execute me\n[…]\nction for clarity\n\n- Refactor URL handling in the search functionality for better maintainability.\n- Improve code readability by utilizing the `SearchURL` method instead of constructing URLs manually.",
          "is_bot": false,
          "headline": "feat: Enhance URL Scheme with Execution Capabilities (#17)",
          "author_name": "Roger",
          "author_login": "moonD4rk",
          "committed_at": "2025-12-28T09:07:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2f036d489b75861e7bf4fdc56fc6d765f7126cad",
          "body": "- Refactor query encoding across multiple builder files to use the new `encodeQuery` function for improved consistency and clarity.\n- Ensure that URL encoding correctly represents spaces as `%20` and handles `+` characters appropriately.\n- Enhance test coverage for encoding functionalities to verify expected behavior with various input scenarios.",
          "is_bot": false,
          "headline": "fix: Add query encoding to use dedicated function (#14)",
          "author_name": "Roger",
          "author_login": "moonD4rk",
          "committed_at": "2025-12-17T15:57:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cff77dfdd0d41d103135cdeb19b4b22120b17a2f",
          "body": "- Implement enhanced task querying capabilities with new filtering methods.\n- Exclude trashed items from task retrieval, ensuring cleaner results.\n- Introduce comprehensive test coverage for new filtering functionalities.\n- Refactor existing tests for clarity and maintainability.",
          "is_bot": false,
          "headline": "fix: Enhance task filtering capabilities and query methods (#13)",
          "author_name": "Roger",
          "author_login": "moonD4rk",
          "committed_at": "2025-12-17T15:27:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "da4f3b92a48a98a7748650ec754b9e0537e4630b",
          "body": null,
          "is_bot": false,
          "headline": "chore: Enhance test coverage for Todo and project functionalities (#10)",
          "author_name": "Roger",
          "author_login": "moonD4rk",
          "committed_at": "2025-12-14T16:01:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "abef6a77970f55901a5f9d3a60ff18f31c2a1c86",
          "body": "- Enhance the documentation by adding badges and a comprehensive \"Features\" section to improve visibility and understanding of the project's capabilities.\n- Clarify and update method names in examples and documentation to reflect changes in the API for better usability.\n- Introduce new usage examples and revise existing ones to demonstrate key functionalities related to URL scheme support and database interactions.",
          "is_bot": false,
          "headline": "docs: Enhance README and documentation for API clarity (#9)",
          "author_name": "Roger",
          "author_login": "moonD4rk",
          "committed_at": "2025-12-14T14:03:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a3fab5b48254090d9971c42eb4a0568c9943e381",
          "body": "* feat: make task query and filter functionalities for clarity\n\n- Refactor task query methods to utilize a new fluent API, enhancing readability and maintainability.\n- Introduce type-safe filters for task properties, including date, status, and task type, allowing for more flexible queries.\n- Add co\n[…]\nr comprehensive coverage on database interactions, URL attributes, and JSON handling.\n- Optimize error handling and improve clarity in method signatures and naming conventions throughout the codebase.",
          "is_bot": false,
          "headline": "feat: Refactor API builders and enhance testing structure (#8)",
          "author_name": "Roger",
          "author_login": "moonD4rk",
          "committed_at": "2025-12-14T13:42:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "17c66f2acb60d576c1abe7cb2ee846423ea30224",
          "body": "- Refactor task query methods to utilize a new fluent API, enhancing readability and maintainability.\n- Introduce type-safe filters for task properties, including date, status, and task type, allowing for more flexible queries.\n- Add comprehensive test coverage for new functionalities, ensuring all filters and methods work as expected across various scenarios.\n- Enhance error handling and overall code cleanliness through renaming and removal of deprecated methods.",
          "is_bot": false,
          "headline": "feat: make task query and filter functionalities for clarity (#7)",
          "author_name": "Roger",
          "author_login": "moonD4rk",
          "committed_at": "2025-12-13T16:20:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "895b1a5f5315fb9c2e7a08edb9558914e4bdebcd",
          "body": "- Refactor task management structures to use proper time types for date fields, improving date handling and tracking in Task and ChecklistItem.\n- Introduce a comprehensive URL scheme for building and managing interactions with Todos and Projects, enhancing consistency and usability.\n- Implement new \n[…]\nch edge cases in data processing and URL generation.\n- Update multiple areas in the codebase to adopt new boolean flags and cleaner query building practices for better performance and maintainability.",
          "is_bot": false,
          "headline": "feat: Add URL scheme and enhance task structures (#6)",
          "author_name": "Roger",
          "author_login": "moonD4rk",
          "committed_at": "2025-12-13T11:54:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a343d1f772d9d68d676686b3bb0cb8e155f670d1",
          "body": "- Refactor client-related components to utilize a new database interface, enhancing clarity and consistency.\n- Update method and variable names throughout the codebase to reflect the transition from `Client` to `DB`.\n- Ensure all tests are aligned with the new database structure and utilize the updated querying mechanism.\n- Revise documentation to accurately describe the new architecture and type-safe URL handling in the library.",
          "is_bot": false,
          "headline": "refactor: Refactor client to database interface for clarity (#5)",
          "author_name": "Roger",
          "author_login": "moonD4rk",
          "committed_at": "2025-12-13T08:18:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "815eabec82c419cb8f28e303ddc5f8c3b4e9860a",
          "body": "* feat: Refactor query filtering with unified filter builder and docs\n\n- Introduce a comprehensive filterBuilder abstraction and filter package to streamline and unify SQL WHERE clause construction, supporting complex date/time and combined filters with improved clarity and maintainability.\n- Add a \n[…]\n implementation to enhance encapsulation.\n- Update naming conventions for table and filter expression constants for consistency.\n- Ensure internal implementation details are not exposed unnecessarily.",
          "is_bot": false,
          "headline": "feat: Refactor query filtering with unified filter builder and docs (#4)",
          "author_name": "Roger",
          "author_login": "moonD4rk",
          "committed_at": "2025-11-30T17:05:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ab5109c0e18abcf1fa84986c3929a498c303b59d",
          "body": "- Add a comprehensive README detailing installation, usage, API examples, and configuration options to improve developer onboarding\n- Enhance CI workflow to run tests and builds on both Ubuntu and macOS, consolidating coverage uploads to prevent duplicates\n- Refine code coverage configuration by removing unnecessary exclusions and clarifying coverage reporting guidance",
          "is_bot": false,
          "headline": "chore: Document usage and enhance CI configurations (#3)",
          "author_name": "Roger",
          "author_login": "moonD4rk",
          "committed_at": "2025-11-29T15:27:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1611f43a41fe2b91e63db2ec689de46a657253e3",
          "body": "* feat: Implement comprehensive Things 3 read-only Go client API\n\n- Implement a complete Go client library for read-only access to the Things 3 macOS app's SQLite database, including connection management, schema models, and query execution.\n- Provide a fluent, chainable query builder interface for \n[…]\nles to the testdata directories for improved testing coverage\n- Update `.gitignore` to allow tracking of SQLite test data files\n- Enhance typo detection configuration to include UUID fragment patterns",
          "is_bot": false,
          "headline": "feat: Implement comprehensive Things 3 read-only Go client API (#2)",
          "author_name": "Roger",
          "author_login": "moonD4rk",
          "committed_at": "2025-11-29T14:54:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cbc4852641f86cef2c1abd4174a33991fef09523",
          "body": "* ci: Set up Go project with CI, linting, coverage, and docs\n\n- Establish a robust Go project foundation by initializing the module and adding comprehensive configurations for linting, coverage, spelling, and CI workflows.\n- Introduce detailed documentation outlining project structure, development g\n[…]\nte CI workflow to use golangci-lint v2.6.2\n\n- Update golangci-lint version from v2.1 to v2.6.2 in the CI workflow to ensure compatibility with the latest linting rules and improve code quality checks.",
          "is_bot": false,
          "headline": "ci: Set up Go project with CI, linting, coverage, and docs (#1)",
          "author_name": "Roger",
          "author_login": "moonD4rk",
          "committed_at": "2025-11-29T04:52:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cebdce723e58b0cd0ec18717dadefdd664612bf9",
          "body": null,
          "is_bot": false,
          "headline": "Initial commit",
          "author_name": "Roger",
          "author_login": "moonD4rk",
          "committed_at": "2025-11-29T04:23:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 10,
      "commits_last_year": 52,
      "latest_release_at": "2026-07-11T14:37:56Z",
      "latest_release_tag": "v0.5.5",
      "releases_from_tags": false,
      "days_since_last_push": 1,
      "active_weeks_last_year": 13,
      "days_since_latest_release": 16,
      "mean_days_between_releases": 24.8
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 42,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/moond4rk/things3",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/moond4rk/things3",
          "is_deprecated": false,
          "latest_version": "v0.5.5",
          "repository_url": "https://github.com/moond4rk/things3",
          "versions_count": 12,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-11T14:35:35Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 16
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 2,
      "watchers": 1,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": null,
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": true,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "cmd/things3/go.mod",
        "go.mod"
      ],
      "largest_source_bytes": 73277,
      "source_files_sampled": 115,
      "oversized_source_files": 1,
      "agent_instruction_files": [
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 8722
    },
    "dependencies": {
      "manifests": [
        "go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go"
      ],
      "dependencies": [
        {
          "name": "github.com/mattn/go-sqlite3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.14.48"
        },
        {
          "name": "github.com/stretchr/testify",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.11.1"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 43,
        "open_issues": 0,
        "closed_ratio": 1,
        "closed_issues": 15,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 3,
      "top_contributors": [
        {
          "type": "User",
          "login": "moonD4rk",
          "commits": 41,
          "avatar_url": "https://avatars.githubusercontent.com/u/24284231?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "release.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [
        ".golangci.yml"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 3,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "22 out of 22 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/28 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 7,
            "reason": "9 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 7",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "32638c75be1dc61d5aa178cb91ad7ecd166673a6",
        "ran_at": "2026-07-28T08:35:57Z",
        "aggregate_score": 4.8,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-26T10:50:50Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-26T10:48:24Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/moonD4rk/things3",
    "host": "github.com",
    "name": "things3",
    "owner": "moonD4rk"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 58,
      "inputs": {
        "security": 48,
        "vitality": 77,
        "community": 24,
        "governance": 61,
        "engineering": 70
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 77,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "commits_last_year": 52,
              "human_commit_share": 0.788,
              "days_since_last_push": 1,
              "active_weeks_last_year": 13
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 1 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "13/52 weeks with commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 13
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "52 commits in the last year",
                "points": 15.5,
                "status": "partial",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 52
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "9 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 7",
                "points": 7,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 10,
              "latest_release_tag": "v0.5.5",
              "releases_from_tags": false,
              "days_since_latest_release": 16,
              "mean_days_between_releases": 24.8
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "10 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 10
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 16 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 16
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~24.8 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 24.8
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 16,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 16 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 16
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 24,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 2,
              "watchers": 1,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "2 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "1 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 61,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "excellent",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "merged_prs": 43,
              "open_issues": 0,
              "closed_issues": 15,
              "issue_closed_ratio": 1,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "100% of issues closed",
                "points": 46.8,
                "status": "met",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "43/43 decided PRs merged",
                "points": 38.2,
                "status": "met",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 43,
                      "decided": 43
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/28 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 67,
            "inputs": {
              "followers": 1165,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "moonD4rk",
              "public_repos": 20,
              "account_age_days": 3526
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "1,165 followers of moonD4rk",
                "points": 22,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 1165,
                      "login": "moonD4rk"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "20 public repos, account ~9 yr old",
                "points": 21.6,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 20
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 9
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/moond4rk/things3"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 16
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 16 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 16
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "12 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 12
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 70,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "2 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": ".golangci.yml",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yml"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "22 out of 22 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "topics": [
                "golang",
                "gtd",
                "macos",
                "sqlite3",
                "things",
                "things3"
              ],
              "has_wiki": false,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "6 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 6
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 48,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": null,
            "notes": [],
            "value": 48,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 18,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 0,
              "scorecard_aggregate": 4.8
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "22 out of 22 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/28 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "9 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 7",
                "points": 5.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 74,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.976,
              "agent_instruction_files": [
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 8722
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "40 of 41 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 40,
                      "sampled": 41
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "cmd/things3/go.mod",
                "go.mod"
              ],
              "dependency_bot_commit_share": 0.038
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "cmd/things3/go.mod, go.mod (toolchain convention, no task runner)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "toolchain_convention",
                    "params": {
                      "files": "cmd/things3/go.mod, go.mod"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": ".golangci.yml",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yml"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 52",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 52
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "2 of the last 52 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 2,
                      "sampled": 52
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 73277,
              "source_files_sampled": 115,
              "oversized_source_files": 1
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "1/115 source files over 60KB",
                "points": 54.5,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 115,
                      "oversized": 1
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "critical",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 20,
            "inputs": {
              "example_dirs": [],
              "has_mcp_signal": true,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-28T08:36:12.197778Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/m/moonD4rk/things3.svg",
  "full_name": "moonD4rk/things3",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsGo.