Raw JSON report machine-readable
{
"data": {
"repo": {
"topics": [
"ai-agents",
"claude-code",
"context-assembly",
"golang",
"local-first",
"mcp"
],
"is_fork": false,
"size_kb": 36708,
"has_wiki": false,
"homepage": null,
"languages": {
"Go": 7261564,
"HTML": 150293,
"Shell": 180576,
"Python": 153714,
"Makefile": 6207,
"Dockerfile": 1956,
"JavaScript": 8817
},
"pushed_at": "2026-07-22T23:46:55Z",
"created_at": "2026-04-06T17:20:02Z",
"owner_type": "Organization",
"updated_at": "2026-07-22T23:46:58Z",
"description": "Local Go daemon that gives AI tools persistent shared workspace state. Context assembly, multi-provider inference routing, hash-chained ledger, MCP server.",
"is_archived": false,
"is_disabled": false,
"license_spdx": "MIT",
"default_branch": "main",
"license_spdx_raw": "MIT",
"primary_language": "Go",
"significant_languages": [
"Go"
]
},
"owner": {
"blog": null,
"name": "Myrgic Labs",
"type": "Organization",
"login": "myrgic",
"company": null,
"location": null,
"followers": 1,
"avatar_url": "https://avatars.githubusercontent.com/u/274069615?v=4",
"created_at": "2026-04-06T17:19:21Z",
"is_verified": null,
"public_repos": 18,
"account_age_days": 107
},
"license": {
"state": "standard",
"spdx_id": "MIT",
"raw_spdx": "MIT",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v0.16.20",
"kind": "patch",
"published_at": "2026-07-17T13:43:00Z"
},
{
"tag": "v0.16.19",
"kind": "patch",
"published_at": "2026-07-07T20:37:53Z"
},
{
"tag": "v0.16.18",
"kind": "patch",
"published_at": "2026-07-07T16:32:50Z"
},
{
"tag": "v0.16.17",
"kind": "patch",
"published_at": "2026-07-06T21:44:42Z"
},
{
"tag": "v0.16.16",
"kind": "patch",
"published_at": "2026-07-06T19:53:36Z"
},
{
"tag": "v0.16.15",
"kind": "patch",
"published_at": "2026-07-05T00:59:26Z"
},
{
"tag": "v0.16.14",
"kind": "patch",
"published_at": "2026-07-04T14:37:52Z"
},
{
"tag": "v0.16.13",
"kind": "patch",
"published_at": "2026-07-04T05:24:56Z"
},
{
"tag": "v0.16.12",
"kind": "patch",
"published_at": "2026-07-04T00:53:06Z"
},
{
"tag": "v0.16.11",
"kind": "patch",
"published_at": "2026-07-02T04:09:54Z"
},
{
"tag": "v0.16.10",
"kind": "patch",
"published_at": "2026-07-01T09:18:25Z"
},
{
"tag": "v0.16.9",
"kind": "patch",
"published_at": "2026-06-30T14:10:25Z"
},
{
"tag": "v0.16.8",
"kind": "patch",
"published_at": "2026-06-30T13:01:07Z"
},
{
"tag": "v0.16.7",
"kind": "patch",
"published_at": "2026-06-30T11:17:59Z"
},
{
"tag": "v0.16.6",
"kind": "patch",
"published_at": "2026-06-27T12:54:56Z"
},
{
"tag": "v0.16.5",
"kind": "patch",
"published_at": "2026-06-25T10:59:37Z"
},
{
"tag": "v0.16.4",
"kind": "patch",
"published_at": "2026-06-25T09:37:49Z"
},
{
"tag": "v0.16.3",
"kind": "patch",
"published_at": "2026-06-24T11:25:41Z"
},
{
"tag": "v0.16.0",
"kind": "minor",
"published_at": "2026-06-10T21:25:19Z"
},
{
"tag": "v0.15.1",
"kind": "patch",
"published_at": "2026-06-08T22:42:03Z"
},
{
"tag": "v0.15.0",
"kind": "minor",
"published_at": "2026-06-07T02:55:59Z"
},
{
"tag": "v0.14.2",
"kind": "patch",
"published_at": "2026-06-04T21:24:50Z"
},
{
"tag": "v0.14.1",
"kind": "patch",
"published_at": "2026-06-04T20:25:12Z"
},
{
"tag": "v0.14.0",
"kind": "minor",
"published_at": "2026-06-03T01:33:34Z"
},
{
"tag": "v0.13.0",
"kind": "minor",
"published_at": "2026-05-27T02:11:42Z"
},
{
"tag": "v0.12.0",
"kind": "minor",
"published_at": "2026-05-25T17:54:41Z"
},
{
"tag": "v0.10.0",
"kind": "minor",
"published_at": "2026-05-19T21:12:05Z"
},
{
"tag": "v0.9.0",
"kind": "minor",
"published_at": "2026-05-17T00:15:15Z"
},
{
"tag": "v0.8.0",
"kind": "minor",
"published_at": "2026-05-15T20:31:05Z"
},
{
"tag": "v0.7.0",
"kind": "minor",
"published_at": "2026-05-13T16:14:32Z"
},
{
"tag": "v0.6.0",
"kind": "minor",
"published_at": "2026-05-08T21:43:02Z"
},
{
"tag": "v0.5.0",
"kind": "minor",
"published_at": "2026-05-08T02:56:44Z"
},
{
"tag": "v0.4.2",
"kind": "patch",
"published_at": "2026-05-05T21:37:54Z"
},
{
"tag": "v0.4.1",
"kind": "patch",
"published_at": "2026-05-02T16:21:28Z"
},
{
"tag": "v0.4.0",
"kind": "minor",
"published_at": "2026-05-01T21:42:20Z"
},
{
"tag": "v0.3.0",
"kind": "minor",
"published_at": "2026-04-22T16:01:50Z"
},
{
"tag": "v0.2.0",
"kind": "minor",
"published_at": "2026-04-20T01:45:10Z"
},
{
"tag": "v0.1.0",
"kind": "minor",
"published_at": "2026-04-14T20:52:26Z"
}
],
"recent_commits": [
{
"oid": "7ebe6461c7b0d381e6b90f85dbc47b9f1943bb68",
"body": "…reconcile + ConfigExporter snapshot (#473)\n\n* refactor(providers): re-home discord provider into internal/providers/discord\n\nADR-121 Wave 4: the daemon's discordProvider registration\n(internal/providers/daemon/daemon.go) was a Health()-only stub embedding\nstubMethods, standing in for the real Recon\n[…]\nuracy (its one confirmed\nfinding) was already corrected in the PR body, and the daemon\nreconcile-loop Tokenable gap is already disclosed in the PR's \"Not in\nscope\" section as an intentional follow-up.",
"is_bot": false,
"headline": "feat(providers): ADR-121 Wave 4 — re-home discord provider with real …",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-07-22T23:46:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5c677ee4c1461680ef7dadcfd6ef31f7f0d27030",
"body": "…(#468)\n\n* feat(marginbridge): add margin-bridge GitHub signal watcher provider\n\nKernel-native replacement for the Python bridge_github.py prototype:\noutbound-only gh-api polling of a workspace's signal inboxes and\nsettlement ledger, surfaced as kernel-native wakes (ledger event +\nbus_margin_bridge)\n[…]\ng two actions resolved in the same ApplyPlan call\ncollide if they land in the same millisecond. Mixed in a per-process\nmonotonic counter as a tiebreaker.\n\nPR #468 round-3 cog-review CHANGES_REQUESTED.",
"is_bot": false,
"headline": "feat(marginbridge): add margin-bridge GitHub signal watcher provider …",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-07-22T23:06:35Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "59606d76aaab39b16a4eb5eca6cc678a85e78076",
"body": "…463)\n\nA quarantine-only ingest source — every record rejected, e.g. the\nclaude-ai-web observer's unsent composer drafts (role user-draft →\nreason draft_role) — never reaches a converged state, so the\nreconciler re-reads its unchanged ingest file every cycle. Quarantine\nwas append-only with no dedup\n[…]\nason uniformly, not just draft_role.\n\nRegression test: same record across 50 cycles and a simulated restart\n→ 1 line; distinct records still append; content-hash dedup for\nrecords without a stable_id.",
"is_bot": false,
"headline": "fix(conversations): make quarantine writes idempotent by stable_id (#…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-07-22T16:14:13Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6fcdd2a1f8740fe06c6e2a2729f44168e8c38130",
"body": "* docs(adr): ADR-121 single-binary consolidation -- fold CLI into cogos, delete legacy root package\n\n* chore(cli): delete legacy root package main per ADR-121\n\nRemoves all 232 root-level .go files (the legacy standalone CLI,\npackage main). The shipped entrypoint is cmd/cogos -> internal/engine\nand a\n[…]\nsubsystem, which predates and is orthogonal to the\nReconcilable-provider pattern and isn't part of ADR-121's Wave 4 list.\n\nVerified: go build ./..., go build -tags fts5 ./..., go vet ./... all\nexit 0.",
"is_bot": false,
"headline": "chore(cli): delete legacy root package main per ADR-121 (#464)",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-07-22T16:12:37Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e9cb104b537b5d7211e1ec5d347d9e3520a84862",
"body": "…, chunk 2) (#472)\n\n* feat(identity): ledger-backed identity grants + revoke (board task 60, chunk 2)\n\nChunk 1 (dce2d68, #471) proved kernel-issued identity grants in memory\nonly, with an explicitly-filed gap: a kernel restart silently invalidated\nevery live grant, and a full grant store had no non-\n[…]\ny succeeds\nonce the ledger recovers and the token dies),\nTestIdentityGrantMint_LedgerAppendFailureMapsTo503. Existing Revoke\ncall sites updated to the error-returning signature; all prior tests\ngreen.",
"is_bot": false,
"headline": "feat(identity): ledger-backed identity grants + revoke (board task 60…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-07-22T03:52:56Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "dce2d6889e528f217b15df54ee7b61d04404a47a",
"body": "…) (#471)\n\n* feat(identity): kernel-issued identity grants (board task 60, chunk 1)\n\nAdds POST /v1/identity/grants, POST /v1/identity/verify, GET /v1/identity/grants,\nand GET /v1/identity/grants/current -- an in-memory, surface-scoped credential\nissuance/verification surface following the serve_sess\n[…]\nfor both: alternating scope across repeated mints for\none surface holds byGrantID at exactly one live entry, and minting past the\ncap is rejected with the capacity error while bySurface stays bounded.",
"is_bot": false,
"headline": "feat(identity): kernel-issued identity grants (board task 60, chunk 1…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-07-22T00:03:22Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b530df6c1cb7b048e377ffc30e12162ca537f124",
"body": "…precated temperature (#467)",
"is_bot": false,
"headline": "fix(dispatch): route current-generation Anthropic models and strip de…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-07-17T13:34:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a4d7477761617d9ef8dd446a7878f52370c2fab2",
"body": "The SiteProvider drift check was a stub (\"ArtifactSHA empty -> update;\notherwise -> skip. Full SHA comparison is planned for v0.1.\"). It only\ndeployed targets that had never been deployed, so once a target had any\ncontent, every subsequent content change was silently skipped and never\nshipped.\n\nRepl\n[…]\n, hashes the output, compares to the live hash:\n differ or missing -> update, equal -> skip.\n\nContent-only changes now plan as update. Tests added for synced,\ncontent-drift, and missing-marker cases.",
"is_bot": false,
"headline": "fix(site): real per-app content-hash drift detection (#462)",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-07-08T22:32:36Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "32dbfc619d9d4a6f2d09a53af08b4c9cc9ab1880",
"body": "…n (#458)\n\n* fix(conversations): atomic + cross-process-locked writes to _meta.json\n\nFixes #449. writeMetaFileLocked previously did a plain os.WriteFile with\nno cross-process coordination, so a CLI-invoked \"cog reconcile\nconversations\" run and the daemon's own reconcile cycle could each\nread-modify-\n[…]\nop races MCP writes; in cmd/cogos the eval reconcile provider is a\n no-op stub. Comments now state the real guarded races: concurrent MCP\n invocations, and any future real-provider reconcile wiring.",
"is_bot": false,
"headline": "fix(conversations): atomic + cross-process-locked writes to _meta.jso…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-07-08T00:25:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "62e9d337e4be0c07f27813c714d4cf030d5d3f86",
"body": "…utation (#460)\n\n* fix(config): gate config-mutation HTTP endpoints, warn on unauthenticated non-loopback bind\n\nGET/PATCH /v1/config and POST /v1/config/rollback were reachable by any\nlocal process on the same host with no gate at all, unlike the existing\nEnableSkillExec (serve_skills.go) / EnableSe\n[…]\ne \"disabled\"/enable_config_mutation wording, matching the established\npattern for resource-read failures elsewhere in this file (resourceState).\n\nTests: TestResourceConfigMCP_GateDisabled/GateEnabled.",
"is_bot": false,
"headline": "fix(config): gate config-mutation HTTP endpoints behind EnableConfigM…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-07-07T22:28:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "24b3ce9cf8593b35c23e860d487f76b51497e66e",
"body": "Extends the existing lint CI job with a cheap mechanical check\n(scripts/check-shell-hardening.sh) requiring every tracked scripts/*.sh\nfile to declare `set -euo pipefail` (or `set -eu` for POSIX sh, which\nhas no pipefail) or carry a documented `# no-pipefail: <reason>`\nopt-out, plus a shellcheck err\n[…]\nened POSIX\nsh, documented opt-out, unhardened, non-shell-shebang skip, shellcheck\nerror-severity, mixed tree), plus an acceptance test running the real\ngate against this repo's own scripts/ directory.",
"is_bot": false,
"headline": "ci(shell): add shell-hardening gate for scripts/*.sh (ledger L15) (#459)",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-07-07T21:49:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "39d63c2c2ababb7c343344c90dbf839c95eb44eb",
"body": "Adds keyless Sigstore signing of checksums.txt to the release pipeline\nusing the GitHub OIDC identity (id-token: write, scoped to the release\njob), plus a fail-closed self-verify step before publishing. Documents\nwhat is signed, the exact consumer verify command, and the trust model\nin docs/release-signing.md.\n\nRatified v1.0 alignment item L12 (release integrity), phase 1\n(release-side signing). Kernel self-update verification of this\nsignature is out of scope here and tracked in #454.",
"is_bot": false,
"headline": "ci(release): sign checksums.txt with Sigstore/cosign (keyless) (#456)",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-07-07T21:49:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "863ce4e2919f3a83b8512730b9f5de00775cb7d9",
"body": "…ism (#457)\n\n* fix(replay): implement real sha256 hash and wire VerifyReplayDeterminism into tests\n\nhashString was a placeholder that returned its input bytes verbatim\ninstead of hashing (replay.go:402), so ComputeReplayHash was string\nidentity dressed as a hash. VerifyReplayDeterminism, its only re\n[…]\nng covers ID/Type/branch/branchSeq\nand not Timestamp/ParentID/Data -- pre-existing scope, not a regression,\nflagged per review rather than widened, since that's a design call\noutside this fix's scope.",
"is_bot": false,
"headline": "fix(replay): implement real sha256 hash and wire VerifyReplayDetermin…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-07-07T20:48:26Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f6d860322df832de7a1a5776e31637374a12f46e",
"body": "…on (#455)\n\nendpointReachable unconditionally cached a negative probe result on any\nHTTP failure, including when the failure was caused by the CALLER's own\ncontext being cancelled (e.g. an HTTP client disconnecting mid-dispatch,\nsince ctx traces back to r.Context() via DispatchToHarness). That\npoiso\n[…]\nmeout firing on a genuinely slow/hung\nendpoint) is unaffected and still caches negative.\n\nAdds two regression tests: a cancelled caller ctx must not write the\ncache; a genuine connection refusal must.",
"is_bot": false,
"headline": "fix(dispatch): guard reachability cache against caller-ctx cancellati…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-07-07T20:41:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9893d6267ba79761211e37d27e13080e8428291b",
"body": "…y + salience-strip (ADR-103) (#452)\n\n* feat(foveation): cache-aware placement, salience strip, session-scoped light-cone key\n\nUnder a plain prefix cache (llama.cpp / LM Studio / OpenAI-compat), the volatile\nfoveal doc manifest sat at the FRONT of the token stream, so its per-turn churn\nre-prefilled\n[…]\n build ./... and go test -race\n./internal/engine/... green.\n\n* chore: re-trigger review (cog-review transient error on prior head)\n\n* chore: re-trigger review (cog-review errored twice on prior heads)",
"is_bot": false,
"headline": "feat(foveation): cache-aware placement + session-scoped light-cone ke…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-07-07T20:26:23Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "04cb2f2e87902802b7e4127ad29966ad80618d60",
"body": "…104) (#453)\n\n* feat(engine): lms-model-state declarative reconciler (opt-in, off by default)\n\nAdd a Reconcilable that keeps an LM Studio backend loaded with the declared\nmodel at the declared context length, orthogonal to OpenAI-compat dispatch.\nModels the mlx-supervised dual-shape precedent, swapp\n[…]\nMSModelStateProviderConcurrentFieldAccess (SetToken/LoadConfig writes\n vs FetchLive/Health reads) so -race flags any regression.\n\n* chore: re-trigger review (cog-review transient error on prior head)",
"is_bot": false,
"headline": "feat(inference): lms-model-state declarative reconciler, opt-in (ADR-…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-07-07T20:26:17Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "32d445e0b74b4c9106848b55320f836f7e37abf7",
"body": "…ackends) (#451)\n\n* feat(inference): live /v1/models composition with admission-parity fixes\n\nLive-view GET /v1/models: enumerate every ModelLister provider (bounded,\nconcurrent, graceful-skip), emit composite \"<provider>/<model>\" ids for\nlocal/OpenAI-compat providers and bare claude ids for frontie\n[…]\next caller rebuilds\ncleanly. Mirrors the #441 Available() TTL-cache guard. Adds a regression test\n(cancelled caller -> next healthy caller still gets the full menu) and makes the\nlisterStub ctx-aware.",
"is_bot": false,
"headline": "feat(inference): live /v1/models composition (Anthropic + LM Studio b…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-07-07T16:21:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "dcba52627fb267954c94a58a40d76eafb82c1888",
"body": "… A-E) (#447)\n\n* feat(testkernel): First Instruments Module A — cadence + cell-lattice test surface\n\nAdds the boot/testkernel extensions needed to observe and control kernel\ncadence in tests: WithPollInterval (wires the previously-dead\nbootConfig.pollInterval into ReconcileDaemonConfig.PollInterval)\n[…]\nre-check -- multi-hour-to-multi-day wall-clock time the runner\nitself does not shorten. Running that sweep is the next action once this\nPR lands, not a step this implementation session could complete.",
"is_bot": false,
"headline": "feat(instruments): First Instruments Stage-2 instrumentation (Modules…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-07-07T12:54:51Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "207e329cd8bebcb75c1aa2384fa6732875721e1b",
"body": "cog_fork_session and POST /v1/sessions/{id}/fork both register the child\nsession via ApplyRegister with appendFn=nil, relying on the session.fork\nbus event written just before as the child's only durable record. But\nReplaySessionRegistry's switch had no case for \"session.fork\", so the\nchild row was \n[…]\nerve.go) and the stdio MCP path (cli_mcp.go), which previously never\nwired a ForkRegistry at all. PinnedUntil is preserved via the fork body\nround-trip so GC expiry semantics survive replay unchanged.",
"is_bot": false,
"headline": "fix(sessions): forked sessions and lineage survive kernel restart (#446)",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-07-06T22:01:41Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "735a138891576edee9406133197197d97eecb5a3",
"body": "…ecord drift (#444)\n\nSelf-update writes kernel.toml (version + current-platform checksum) write-ahead before the binary swap and rolls it back on failure, so the pinned-version record stops drifting from the running daemon (#442). Dormant no-op where no kernel.toml exists; perm-restore is best-effort so a chmod failure can't strand a committed write. Hardened per Fable + cog-review.",
"is_bot": false,
"headline": "fix(self-update): write-ahead kernel.toml maintainer to end version-r…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-07-06T21:39:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b40c804d783614a5067d84022fec736c8fd7c8ec",
"body": "…aware fallback (#445)\n\nProbe now bounded by an internal deadline so availMu isn't held for the full client timeout; stream_options.include_usage restores token accounting on the cancel-safe streaming path; fallback skips model-incompatible LOCAL providers (IsLocal && !AgenticHarness) so a downed local LMS fails over to a sibling serving the model instead of firing a bogus model id at a frontier provider. Addresses the Fable pipeline review.",
"is_bot": false,
"headline": "fix(inference): robust availability probes, end-to-end usage, compat-…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-07-06T21:39:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5a9bc943ea659fc419549569e3d27f02eb3e23b3",
"body": "…v1/models polling (#443)\n\nOpenAICompat, ClaudeOAuth, and Ollama providers now cache their Available() reachability probe for 30s (availCacheTTL), so the router's 10s availability ticker and the per-request /v1/providers handler stop issuing a live GET /v1/models (and /api/tags) on every call. A cal\n[…]\nning); a probeTimeout deadline on a slow provider IS cached as unavailable. Anthropic/Codex/ClaudeCode/Pi Available() are cheap local checks needing no cache; MLXSupervised already caches.\n\nRefs #441.",
"is_bot": false,
"headline": "perf(inference): cache live provider Available() probes to stop 10s /…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-07-06T19:47:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3c437feb6ca9cbf59aaf0659d5c63405d23bdfc0",
"body": "* feat(dispatch): async job handle for cog_dispatch_to_harness (fixes #32001)\n\ncog_dispatch_to_harness is fully synchronous -- the MCP request blocks\nuntil every fan-out slot completes, errors, or hits its per-slot timeout\n(up to 600s). Interactive MCP clients often close their request window\nwell b\n[…]\n pre-existing MCP-side async tests\n(TestToolDispatchToHarness_AsyncReturnsImmediateJobHandle et al.) carry\nthe same latent hazard but are out of scope for this PR's confirmed\nfindings; left untouched.",
"is_bot": false,
"headline": "feat(dispatch): async job handle + harness capability gating (#437)",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-07-05T23:15:20Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "776b66698d1beaff2c701b2a6cdb757b1e36268d",
"body": "…itHub (#438)\n\n* fix(ci): gate must fail closed — neutral passes a required check on GitHub\n\nDiscovered once cog-review became a required check: GitHub treats a\n`neutral` required check-run as PASSING, not blocking. The gate mapped its\nfail-safe cases (reviewer error, sandbox-canary failure, unconfi\n[…]\nle, within the trust model): a bot CHANGES_REQUESTED review at\nhead -> reconcile; a COMMENTED review or none (errors post none) ->\nescalate to operator (exit 4), matching the script's header contract.",
"is_bot": false,
"headline": "fix(ci): gate must fail closed — neutral passes a required check on G…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-07-05T22:31:36Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b00db12b9c7e5d426274526d1125b0e165ed94aa",
"body": "…ge stays local (#436)\n\n* ci(review): repo-resident cog-review gate — approve-authority, merge stays local\n\nAdds a two-tier PR gate that any contributor's PR passes through identically\n(the gate is identity-blind; merge authority is not):\n\n- mechanical: deterministic Conventional-Commits title check\n[…]\np mechanical job re-validates; guard the expensive\ncog-review job with action != 'edited' since a title/body edit leaves the\ndiff (and thus the code verdict) unchanged — no wasted AI review on a typo.",
"is_bot": false,
"headline": "ci(review): repo-resident cog-review gate with approve authority, mer…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-07-05T20:55:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ed0714aa94770edf7e7948e878ce0af76771746e",
"body": "…ispatch_to_harness (#435)\n\nOperator directive (2026-07-04): \"expand the timeout caps to at least 5m.\nWith agentic workflows that will likely get pushed even further out, so\nthe timeout should be a parameter, not hardcoded.\"\n\n- Per-slot timeout cap becomes config-driven: dispatch_timeout_cap_seconds\n[…]\nday), which deliberately raised the default to 240s as\nan incident fix (zombie generations under a 30s ceiling). The default is\nleft at 240s to avoid regressing that fix; the doc strings now state it.",
"is_bot": false,
"headline": "feat(dispatch): config-driven timeout cap + doc-drift fixes for cog_d…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-07-05T00:53:56Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e4e6acae5c60ffa8a66073d97c0b2b592d521eb7",
"body": "…etries (#432) (#434)\n\nNon-streaming completion calls to LM Studio (openai-compat) did not abort\ngeneration server-side when the kernel gave up waiting: the client-side\nComplete() call returns on ctx cancel, but the connection isn't torn down\nin time for the server to notice, so the model keeps gene\n[…]\n, so without the override a countingProvider wrapping a\ncancel-safe-capable provider silently fell back to plain Complete on the\ndispatch path specifically. Found via the retry-dedup integration test.",
"is_bot": false,
"headline": "fix(engine): propagate local-inference cancellation, bound timeouts/r…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-07-04T14:32:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "704ae050bc02c8a7102e58625e90eccdc3a7bc63",
"body": "…lt (#431)\n\ncog_dispatch_to_harness silently discarded an explicit model the caller\nrequested in two places: DispatchRequest.Normalize() collapsed any\nnon-enum model string to \"e4b\" before routing ever saw it, and the\nexplicit-provider / harness-provider-default / state-routing paths in\nDispatchToHa\n[…]\nuest over the config default. When the provider cannot serve the\n requested model it still fails loudly via the existing non-2xx wire\n error path — no client-side substitution was added.\n\nFixes #430",
"is_bot": false,
"headline": "fix(dispatch): honor caller-explicit model over provider config defau…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-07-04T05:18:47Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "19c17189d39e451be74ef85288d30d2780a8fd7e",
"body": "…ace (#426)\n\n* fix(dispatch): default local-LLM endpoint to LM Studio :1234, not Ollama :11434\n\nopenaiCompatDefaultEndpoint had drifted back to Ollama's decommissioned\n:11434 after PR #417 moved the default local backend to LM Studio\n(lmstudio-darkstar, 127.0.0.1:1234). A no-provider cog_dispatch_to\n[…]\nlog, ~57 entries, one\nscan per rejection) to help with typos.\n\nExtends the existing TestToolInvoke_* family with both cases plus focused\nunit tests on the new eagerToolExists/nearestToolNames helpers.",
"is_bot": false,
"headline": "fix(dispatch,mcp): LM Studio default endpoint + eager-tool error surf…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-07-04T00:48:12Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e03ad3860f2672270c478fabed903601973235c0",
"body": "… leftovers (#419)\n\n* fix(constellation): harden the FTS write path — serialize index writes, refresh mtime on hash-skip, prune ghost rows on reindex\n\nThree write-path fixes in the constellation indexer:\n\n1. Concurrent IndexFile corrupted transaction state: upsertFTSRow issued\n SAVEPOINT/RELEASE a\n[…]\nsion exercises the real\nStreamable HTTP transport without a prior register call and asserts the\ndenial; the existing TestToolInvoke_EnforcesCapabilityGating (registered\nallow/deny paths) still passes.",
"is_bot": false,
"headline": "fix: FTS write-path hardening, drift-repair correctness, decommission…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-07-02T04:04:52Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e38ae77becca59e261418b841e5542b303cec222",
"body": "feat(mcp): porcelain/plumbing tool surface — lean eager set fronting a deferred catalog",
"is_bot": false,
"headline": "Merge pull request #418 from myrgic/feat/porcelain-plumbing-tool-surface",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-07-01T09:12:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "136f71de7cff537d1545aa719cbfc32a8cfadf0a",
"body": "…quote corruption\n\n- backfillEagerSchemas ran only in the constructor, before RegisterMCPExtensions\n fires in registerMCPRoutes — so extension eager tools (cog_search_conversations,\n cog_get_conversation_turn) kept nil InputSchema and cog_tool_search returned null\n schemas for them. Re-run the idempotent backfill after the extension hook.\n- revert 3 doc-comment backtick pairs mangled into curly quotes by a find-replace\n in mcp_modality_proxy.go; fix stale ~13 -> ~14 porcelain-count comment.",
"is_bot": false,
"headline": "fix(mcp): backfill extension-registered eager schemas + revert curly-…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-07-01T09:06:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "baa4df273c378209b09567a151e6ccef8b6e3698",
"body": "…s schema\n\nFixes toolInvokeInput.Args: json.RawMessage infers as an array/null\nJSON Schema (byte slice), not an object, so any real args payload\nfailed schema validation before the handler ever ran. Switched to\nmap[string]any (re-marshaled to JSON before handing to the deferred\nhandler, which still \n[…]\nt)\n - a porcelain tool (cog_get_state) is still directly callable\n - a deferred tool (cog_read_ledger, mod3_speak) is absent from\n ListTools/tools-list while still present in the toolMeta catalog",
"is_bot": false,
"headline": "test(mcp): regression coverage for porcelain/plumbing split + fix arg…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-07-01T08:48:17Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a929214aa4f12c95c9454cee4ef3fc2503c81389",
"body": "Server-autonomous porcelain/plumbing split (workflow wkweyu50g, plan\ncog:mem/semantic/architecture/mcp-tool-surface-tier-then-trim.cog.md\n#Mechanism, RESOLVED). The kernel cannot ask a harness to defer-load\nspecific MCP tools, so it shrinks what it advertises instead.\n\n- trackToolDeferred (serve_man\n[…]\n KernelToolRegistry (tool_loop.go)\nis unaffected — it calls handler functions directly and was never\nrouted through mcp.AddTool or m.server, so named scopes (audit, emit,\netc.) keep working unchanged.",
"is_bot": false,
"headline": "feat(mcp): partition tool surface into porcelain + deferred plumbing",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-07-01T08:44:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5877ccaf013b0ae6f8846ef6d2940cefc49df35b",
"body": "mcpToolMeta gains Eager and InputSchema fields. trackTool captures\nt.InputSchema before the pointer reaches mcp.AddTool (which internally\ncopies via tt := *t, so inferred schemas never write back onto the\noriginal pointer). A new backfillEagerSchemas queries the live server\nvia the same in-process L\n[…]\nhema instead of nil.\n\nGroundwork for the porcelain/plumbing tool-surface split (workflow\nwkweyu50g): the deferred catalog needs InputSchema on every entry for\ncog_tool_search to return usable results.",
"is_bot": false,
"headline": "feat(mcp): capture InputSchema on toolMeta, backfill eager schemas",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-07-01T08:37:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8d37652088f72c9329e94b227e015de11540c75f",
"body": "chore(dispatch): decommission Ollama backend; default to LM Studio",
"is_bot": false,
"headline": "Merge pull request #417 from myrgic/chore/drop-ollama-backend",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-30T14:05:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c321093a4d9636ab8f548448a6bf0436f39ddf27",
"body": "…d issue template ref\n\n- .cog/config/node/manifest.yaml: removed ollama observed-service block (port 11434)\n- .github/workflows/nightly-integration.yml: removed integration-ollama job (ollama/ollama\n service container, OLLAMA_HOST env, wait-for-Ollama step); updated header comment\n- .github/ISSUE_TEMPLATE/bug_report.yml: updated provider example from\n 'ollama (gemma4:e4b)' to 'lmstudio-darkstar (gemma-4-26b)'",
"is_bot": false,
"headline": "chore(ci+config): remove Ollama service container, manifest entry, an…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-30T14:00:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "19b0a2808b0dc0983988113612958c69273b1057",
"body": "… lmstudio-darkstar\n\n- provider_ollama.go: added decommission header; defaultOllamaModel kept for compat\n- provider_ollama_integration_test.go: removed (Ollama CI service gone)\n- router.go: applyLocalModelConfig now covers lmstudio/openai-compat types;\n defaultProvidersConfig Ollama branch emits a \n[…]\nscription updated (LM Studio as default);\n Model jsonschema updated (no longer says 'e4b default, local Ollama');\n cog_patch_config patch fields list removes ollama_embed_endpoint/ollama_embed_model",
"is_bot": false,
"headline": "chore(providers): tombstone Ollama provider; default providers.yaml →…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-30T14:00:24Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "159ecc33f803b6cdeab43663d8c83786c32673fb",
"body": "… backend\n\n- detectLocalLLMTarget now probes OpenAI-compat (/v1/models) first, Ollama second\n- resolvePreferredLocalModel no longer hard-codes defaultOllamaModel as a priority\n floor; falls back to models[0] (first model the server advertises)\n- localModelHint returns empty string when LocalModel i\n[…]\nrom Ollama wire format (/api/tags + /api/chat) to OpenAI-compat\n (/v1/models + /v1/chat/completions); legacy state-routing fallback tests work via\n the secondary Ollama probe in detectLocalLLMTarget",
"is_bot": false,
"headline": "feat(dispatch): decommission Ollama as default; LM Studio is the live…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-30T14:00:12Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a0752cba4b3f90ab925e569bb7021f3b62fe008e",
"body": "IndexWorkspace accumulated per-doc parse/index errors in indexErr and\nreturned it after a fully successful walk + commit + ref-resolve + FTS\nrebuild. A single cogdoc with malformed YAML frontmatter therefore caused\n'cogos reindex' to exit 1 even when 14,000+ other docs indexed cleanly.\n\nPer-doc fail\n[…]\nwith the exact YAML error class seen in production (mapping values\nnot allowed in this context), asserts IndexWorkspace returns nil, and\nverifies the valid sibling docs are indexed and FTS-searchable.",
"is_bot": false,
"headline": "fix(cli): cogos reindex tolerates per-doc parse failures (#416)",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-30T13:33:36Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "906f5f245c256d56e4199e0eaafaae39a3d672c9",
"body": "fix(search): idempotent lazy FTS reindex — keep cog_search_memory current",
"is_bot": false,
"headline": "Merge pull request #415 from myrgic/fts-lazy-reindex",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-30T12:54:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3e1f869e6ee1d6e7abba4de2e623a084c3546e0e",
"body": "…space\n\nThe generalized purge (DELETE FROM documents WHERE path NOT LIKE <root>/%)\nintroduced in the portability pass was unsafe on two counts: (1) it would\ndelete legitimately-indexed rows whose path falls outside the workspace root\n(conversation/session documents indexed from ~/.claude), and (2) t\n[…]\nxing is idempotent and does not require it.\nOrphan cleanup (rows whose file no longer exists) is deferred to a dedicated\nstat-based sweep. Test rewritten to assert out-of-workspace rows are preserved.",
"is_bot": false,
"headline": "fix(constellation): remove unsafe out-of-workspace purge in IndexWork…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-30T12:48:32Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "429a1758594988be62a54a5aeb17a467d4887329",
"body": "…rkspace\n\nsdk/constellation/indexer.go:70 contained a literal DELETE predicate\n WHERE path LIKE '/Users/slowbro/cog-workspace/%'\nwhich silently purged nothing on any machine other than the original author's\nand would never purge correctly if the workspace was renamed or moved.\n\nReplace with a param\n[…]\nhose absolute path falls\noutside the current workspace root — the actual portability-correct intent\nof the CRITICAL-4 purge — and uses a bound ? parameter so no literal path\nappears in the SQL source.",
"is_bot": false,
"headline": "fix(constellation): variabilize hardcoded stale-path purge in IndexWo…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-30T12:37:52Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f2d779679f593319af6f749b1c9a017ec6fb4bb6",
"body": "~/.cog/config is a directory holding self-update.yaml. The old fallback\npath in loadGlobalConfig checked only statErr2 == nil before assigning\npath = oldPath, so os.ReadFile would attempt to read a directory and crash\non any kernel that has a self-update config installed.\n\nFix:\n- oldPath branch: us\n[…]\nh: widen the fallback condition from os.IsNotExist-only to\n also cover the case where newPath exists but is a directory, so the\n legacy fallback is tried when the canonical file path is itself a dir",
"is_bot": false,
"headline": "fix(providers/all): guard IsDir in loadGlobalConfig config-path fallback",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-30T12:37:09Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "28291a46597f97a36a284c5e9eca619db1fa56d5",
"body": "…index\n\nlazy drift-repair (d11f3a4) warns users to run `cogos reindex` when\nwidespread drift is detected (>10 drifted rows), but the command was\nmissing — the CLI exited with 'unknown command reindex'.\n\nAdd internal/engine/cli_reindex.go modeled on cli_reconcile.go:\n- own flag.NewFlagSet with --work\n[…]\n_*.go files may\n import sdk/constellation — only the long-lived daemon boot path may not\n- register case \"reindex\": in the switch in cli.go (~:159) and add a\n printUsage line adjacent to \"reconcile\"",
"is_bot": false,
"headline": "feat(cli): add `cogos reindex` command to rebuild FTS5 constellation …",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-30T12:36:20Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e6ba790468a94a07670660fddbc2aa8342409476",
"body": "Add MemWatcher (internal/engine/mem_watcher.go) to keep FTS current for\n.cog/mem/ writes that bypass the MCP write path (direct editor saves, ingest\nCLI, CI scripts).\n\nTwo behaviours:\n\n1. Recursive-add on directory Create. macOS kqueue (and Windows\n ReadDirectoryChangesW) is non-recursive: a newl\n[…]\npkgFTSRepairIndexer being non-nil. In tests and CLI paths where no\n indexer is wired the block is a no-op.\n- Watcher goroutine is stopped via a context-cancel listener when kernelCtx\n is cancelled.",
"is_bot": false,
"headline": "feat(engine): mem-watcher with recursive subdir-add on fsnotify Create",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-30T12:34:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4c6d2f19dec835f6d4713b1bcbe124fea4dda3bc",
"body": "… FTS hook\n\nRemove the direct sdk/constellation import from internal/engine/mcp_stubs.go\n(package-boundary guard #2 per cogdoc_service.go:22).\n\nThe lazy drift-repair path in searchMemoryFTSDriftRepair previously called\nconstellation.Open directly. Replace with pkgFTSRepairIndexer, a package-level\nC\n[…]\ng FTS in lockstep with the\nfile system. WithConstellationIndexer is now called from a production path\n(MCPServer.SetConstellationIndexer) — previously the setter existed but had\nno production caller.",
"is_bot": false,
"headline": "fix(engine): kill sdk/constellation boundary violation; wire on-write…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-30T12:31:46Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d11f3a46bc46d6a579076e0c6b4b1c4c8e0a0aca",
"body": "Before running the FTS5 query, sample up to 100 recently-indexed documents\nand compare their stored file_mtime to os.Stat. For ≤10 drifted paths,\ncall constellation.IndexFile (now O(1) upsert) within a 200ms budget.\nIf drift is widespread, log once and fall through to serve current results\n(bulk repair belongs to `cogos reindex`). No latency impact on the common\ncase (0 drifted rows in sample).",
"is_bot": false,
"headline": "feat(search): lazy FTS drift repair on every searchMemoryFTS call",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-30T12:03:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4a3af8cf185f10eb3b8045abaa690e18baf87d32",
"body": "…n tests\n\nReplace the per-file rebuildFTS() (O(N) full table rebuild) in IndexFile\nwith upsertFTSRow(), a targeted DELETE+INSERT FROM documents WHERE id=? pair\nwrapped in a savepoint for crash-consistency. A package-level ftsMu\nserialises all FTS mutations so a watcher-triggered IndexFile cannot\nin\n[…]\nh a CLI-driven rebuildFTS. IndexWorkspace continues to use\nrebuildFTS after the full walk.\n\nAdd three regression tests: FTSIndexFileSearchable, FTSIndexFileIdempotent,\nand FTSIndexFileChangedContent.",
"is_bot": false,
"headline": "feat(constellation): incremental FTS upsert + mutex guard + regressio…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-30T12:02:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b21d4a96912aa0ffb1e5ec85dd47d8d1cabce616",
"body": "…ance\n\nWave 2 — harness: provisional-binding conformance",
"is_bot": false,
"headline": "Merge pull request #414 from myrgic/harness/wave2-provisional-conform…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-30T11:11:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "aeabdc5d70793478469507758ea8901aed9b0341",
"body": null,
"is_bot": false,
"headline": "style(harness): gofmt changed files",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-30T11:07:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "96f3823151d95e6369700a05c0cafed3e458a1a9",
"body": "…-B (ADR-031, RFC-020 subset)",
"is_bot": false,
"headline": "feat(harness): four-element is_error bodies for loop sentinels + gate…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-30T10:59:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c566316168cf19489267bcc21fb2d0978fd8a802",
"body": "…pe reads (ADR pointer-first)",
"is_bot": false,
"headline": "refactor(harness): pointer-first (res=abstract) default for audit-sco…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-30T10:56:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "859a672897e969d8372f042e3bf98f6be21fe03c",
"body": "…C-016)",
"is_bot": false,
"headline": "refactor(harness): scope catalog cleanup + task-type micro-scopes (RF…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-30T10:50:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "91c7311c348e8666b4c4eb38cf29a0e399ee2bff",
"body": "…018, ADR-066)",
"is_bot": false,
"headline": "feat(harness): four-bundle orientation block on dispatch prompt (RFC-…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-30T10:46:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ef67f47a7fa235395d228aaface2fbe09518f7f4",
"body": "…ymous fallback (RFC-identity-embedding)",
"is_bot": false,
"headline": "feat(harness): thread dispatch identity into inference + events, anon…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-30T10:44:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9438bed3ad3e5a72bad806348bb9a1b42f3ceeda",
"body": "Wave 1 — harness: accepted-ADR conformance",
"is_bot": false,
"headline": "Merge pull request #413 from myrgic/harness/wave1-adr-conformance",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-30T10:09:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e05cffea3def9610775e650c8e330c7fbf2dbd28",
"body": "… handling",
"is_bot": false,
"headline": "docs(harness): correct misleading comment on autonomic cycle sentinel…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-30T10:05:58Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "407cc86ba17b4296e793e69c8825ae27e23bee9e",
"body": "… cog_get_index (ADR-045, ADR-066)",
"is_bot": false,
"headline": "refactor(harness): dedupe URI block, reconcile tool descriptions, cap…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-30T09:51:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fa0b97aea386ffd679ac4a5cd21b360badd625bf",
"body": "…83, ADR-033, ADR-072)",
"is_bot": false,
"headline": "feat(harness): emit cycle-trace + ledger events for dispatches (ADR-0…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-30T09:48:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e67f25ac652ae3cd32bd8ea78691f72bc7e7ec51",
"body": "…rrors, respond hard-break (ADR-031, ADR-052)",
"is_bot": false,
"headline": "fix(harness): legible loop exits — max-turns/no-progress structured e…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-30T09:44:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4bc157076b15de9b0baa0a75bf2d95c817f0693f",
"body": "…ch (ADR-eigen, RFC-027)",
"is_bot": false,
"headline": "fix(harness): output contract + channel-token sanitization for dispat…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-30T09:41:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "507df4ffa1e90a24f83f5aaeecd1bf260ed67d59",
"body": "…t-keyed RequestID (ADR-066)",
"is_bot": false,
"headline": "refactor(harness): make dispatch temp/max_tokens overridable + conten…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-30T09:39:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f1a5f18819d5ddf3f3a348f9304bbecab5f54138",
"body": "* feat(embed): use OpenAI /v1/embeddings instead of Ollama-native API\n\nSwitch the two embedding clients from Ollama's native endpoints to the\nOpenAI-compatible /v1/embeddings surface, so the kernel can use LM Studio\n(or any OpenAI-compatible server) for embeddings:\n\n- internal/engine/trm_context.go \n[…]\nndpoint+model stay config-driven (OllamaEmbed* keys retained for compat).\nOllama also serves /v1/embeddings, so this works against both backends during\nthe transition.\n\n* chore: bump VERSION to 0.16.6",
"is_bot": false,
"headline": "feat(embed): OpenAI /v1/embeddings instead of Ollama-native API (#412)",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-27T12:49:56Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2ee0175df4f073182eeca4cfb36b2484872c57d7",
"body": "Ships the reconcile-driven self-update feature (#410) so the daemon can keep\nitself current with GitHub releases. After this release, install once to\nbootstrap, then 'cogos self-update' (or auto-apply) handles subsequent updates.",
"is_bot": false,
"headline": "chore: bump version to 0.16.5 (#411)",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-25T10:54:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "99f264b966396b5270986213efb7f2dcb72af70c",
"body": "…eases (#410)\n\nAdds a SelfUpdate Reconcilable provider + a 'cogos self-update' CLI subcommand\nthat keep the launchd-managed daemon current with GitHub releases, per the\nreconcile philosophy (the kernel reconciles its own version like everything\nelse).\n\nProvider (internal/providers/selfupdate): throt\n[…]\ng\n.cog/config/self-update.yaml with enabled:true (intended opt-in). Chicken-and-\negg: this code must be in a release first, so v0.16.x must be installed once to\nbootstrap, after which it self-updates.",
"is_bot": false,
"headline": "feat(self-update): reconcile-driven cogos self-update from GitHub rel…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-25T10:50:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bb53d8ea4e9cba3aa6f856f676ebba9907801649",
"body": "Cuts a release of the overnight audit-remediation batch: #396-#408 (two\npath-traversal security sweeps, the worktree ledger-scan CPU fix, log/map leak\nfixes, data-race + deadlock fixes, reconcile hygiene + purity, and per-cycle\nperf reductions). Release notes auto-generate from PR titles since v0.16.3.",
"is_bot": false,
"headline": "chore: bump version to 0.16.4 (#409)",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-25T09:32:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "820054c4c5b3e62f91e63e79606a72f23d29e2d1",
"body": "…-reading the corpus (#408)\n\nAudit Q1 (projection_reconciler.go:387) + Q2 (decision_lineage_reconciler.go:219).\nBoth ApplyPlan implementations re-read and re-parsed the entire nodes/decision\ncorpus and re-rendered the projection — work FetchLive + ComputePlan already did\nearlier in the same reconcil\n[…]\ne per-action logs use the count already in Details.\n\nTest: ApplyPlan writes a sentinel carried in Details verbatim (proving no\nre-derive); existing full-cycle reconciler tests still green under -race.",
"is_bot": false,
"headline": "perf(reconcile): carry rendered projection in ApplyPlan instead of re…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-25T09:27:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "00c9cebeba790b054e343917d22bc3e1c1c1f125",
"body": "ServiceProvider.Health() issues a Docker Ping plus one ContainerList per declared\nservice on every call, with no caching. Health() is on hot paths — every\nPOST /v1/infer (foveated context buildHealthBlock), every autonomic tick, and\nafter every reconcile cycle — so a workspace with N docker-mode ser\n[…]\n cache. Service liveness changes are still picked\nup within the TTL and at the latest by the next ~30s reconcile cycle.\n\nTest: a fresh cache is returned without recompute; an expired cache recomputes.",
"is_bot": false,
"headline": "perf(service): cache ServiceProvider.Health() behind a short TTL (#407)",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-25T09:27:01Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9e6abf615070178f0eddb4a62e41eeea3f77f4ed",
"body": "…chLive (#406)\n\nEvalProvider.ComputePlan called readAndClearDispatchTriggers(e.root), which\nDESTRUCTIVELY clears the eval-dispatch-triggers.json sidecar. ComputePlan is\ncontractually pure (deterministic, side-effect-free) — the reconcile daemon may\ncall it and discard the plan, and a concurrent daem\n[…]\nin the audit.)\n\nTest: the dispatch-trigger test now drives the real flow — FetchLive drains the\nsidecar into live state, ComputePlan produces the non-skip action, and the\nsidecar is confirmed cleared.",
"is_bot": false,
"headline": "fix(eval): make ComputePlan pure by draining dispatch triggers in Fet…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-25T09:26:57Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3e07dfc3b865ab219712c0d074b3f924a58e3520",
"body": "…Config init race (#404)\n\nTwo related worktree-reconciler defects from the 2026-06-25 audit (C2 high, C3).\n\nC2 (worktree_reconciler.go:648) — perpetual Degraded after alarm acknowledgement.\nApplyPlan's health loop counted ANY action whose Details[\"classification\"] is an\nalarm type, including the Act\n[…]\nes the field race) that don't conflict with a later C1.\n\nTests: alarm-idempotent test now asserts Degraded while firing then Healthy after\nacknowledgement (C2); constructor defaults nil adapters (C3).",
"is_bot": false,
"headline": "fix(worktree): stop acknowledged alarms pinning Degraded; remove Load…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-25T09:26:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "843825f3da7751e4f36b580f1a2a6895e14073d1",
"body": "… order (#405)\n\nTwo bus_session robustness fixes from the 2026-06-25 audit (A1/A2).\n\nA1 (bus_session.go:232) — saveRegistry used os.WriteFile (truncate-before-write).\nA SIGKILL/crash between truncate and write leaves registry.json empty;\nloadRegistry swallows the parse error and returns an empty reg\n[…]\nus until the next append recreated it. Move\nthe cache reset inside the create-succeeded branch; on create failure, warn and\nretain the cache.\n\nTest: saveRegistry round-trips and leaves no .tmp behind.",
"is_bot": false,
"headline": "fix(engine): atomic bus registry write + correct rotation cache-reset…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-24T16:12:30Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "da224b444f2261fa83f6588a588c784baba838ef",
"body": "…#403)\n\nThe manual SIGTERM->SIGKILL escalation path (taken when proc.cancel is nil, i.e.\nthe foreground streaming providers) spawned a goroutine that slept an\nuninterruptible 5s. On daemon shutdown it outlived the daemon by up to that 5s,\nfiring a pointless SIGKILL at an already-reaped PID (harmless\n[…]\ncalations during shutdown\nstill fire; only goroutines still pending after teardown abort.\n\nTest: Shutdown closes shutdownCh and a repeat Shutdown does not panic (double\nclose guarded by shutdownOnce).",
"is_bot": false,
"headline": "fix(engine): abort procmgr SIGKILL-escalation goroutine on shutdown (…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-24T15:55:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "837ffdf1eb2df70ed02ef0b120a7cb6cdd8508f8",
"body": "…eopen (#402)\n\nRegression in #397 found by the 2026-06-25 audit. rotateLocked() closed the\nactive handle up front, then on either failure branch (rename succeeds but the\npost-rename reopen fails on a full disk; or rename fails AND the recovery reopen\nfails) returned with w.f still pointing at that c\n[…]\nd of writing to a dead descriptor.\n\nTests: Write-after-Close self-heal, and a forced post-failed-rotation state\n(closed handle, nil w.f, size over cap) that must not panic and must persist the\nrecord.",
"is_bot": false,
"headline": "fix(engine): keep rotating log writer's handle valid after a failed r…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-24T15:51:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "559f87e4ea159e48c11bf5d07524b1a8b561c3b4",
"body": "The 2026-06-24 deep audit found four caller-supplied-path sites on the loopback\nHTTP+MCP surface that #396 did not cover. All reuse the pathWithin/containedJoin\nhelpers #396 already established. All are reject-only — valid inputs are\nunaffected; only previously-exploitable inputs are now refused.\n\n-\n[…]\ntName helper and apply it to both. (LOW)\n\nTests: sector-containment on both fallback paths; validClaudeProjectName table.\nLoopback-only by default, so these are local-access hardening, not remote RCE.",
"is_bot": false,
"headline": "fix(security): close path-traversal holes the #396 sweep missed (#401)",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-24T15:43:37Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9e31bf99e1111c0d7a361d4bc891d3aaf13f4c48",
"body": "…very (#400)\n\nTestBuildRouterRegistersMLXSupervisedType failed on any host running LM Studio\non :1234: BuildRouter live-probes well-known OpenAI-compat backends and\nregisters a reachable 'lmstudio' ahead of the configured mlx-gemma, so\nFirstLocalProvider returned 'lmstudio'. It passed in CI only bec\n[…]\nys on by default); only the test opts out so\nrouter construction no longer depends on what LLM servers are live on the host.\n\nVerified: with LM Studio live on :1234, the test now passes (was failing).",
"is_bot": false,
"headline": "test(router): make BuildRouter MLX test hermetic via WithoutAutoDisco…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-24T15:13:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "847e08a43c4a2a7e061869eec4542c1a555d26fe",
"body": "…(#399)\n\nWorktreeReconciler.LoadConfig runs every ~30s reconcile cycle and calls\nFilesystemLedgerReader.ReadWorktreeEvents, which listed every\n.cog/ledger/<session>/ dir and fully read + JSON-parsed each events.jsonl to\nextract a handful of worktree.* events. On a long-lived workspace that is\nhundre\n[…]\nam so the test can count cache-miss\nparses (mirrors the existing psLookup seam).\n\nTest: cache-hit on unchanged file (no re-parse), re-parse on append, eviction\non delete, and repoRoot-keyed isolation.",
"is_bot": false,
"headline": "perf(worktree): cache per-session ledger scans in ReadWorktreeEvents …",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-24T14:57:07Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "24ceef2542c6c3c98c0d89839329981770cf2646",
"body": "…r-cycle work (#398)\n\nReconcile-contract cluster from the codebase audit, low-risk subset (the\ncontract-semantics items — worktree re-degrade, eval ComputePlan write, MLX\nconvergence, per-cycle subprocess batching — are deferred to review-required\nfollow-ups).\n\n- reconcile.GetProvider: recursive-RLo\n[…]\nmon (mirrors WorktreeReconciler.ComputePlan).\n\nTests: registry deadlock regression (verified it hangs against the buggy code),\ncogdoc disabled-skips-walk, decision-lineage wrong-live-type error paths.",
"is_bot": false,
"headline": "fix(reconcile): kill GetProvider deadlock + stop disabled-pipeline pe…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-24T14:34:51Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "87708bc7a9175899e81e59d882186724f403b537",
"body": "…ks (#397)\n\n* fix(engine): cap kernel log growth and stop procmgr map/goroutine leaks\n\nTwo unbounded-resource bugs found in the codebase audit:\n\n1. kernel.log.jsonl grew without bound. The slog JSON sink was opened\n O_APPEND and left open for the process lifetime with no rotation,\n reaching ~446\n[…]\nats read it). Add a dedicated -race regression so the loadStatus/\nsnapshot guard can't silently regress. Processes use an unstarted cmd so the\nescalation goroutine is skipped and no real signals fire.",
"is_bot": false,
"headline": "fix(engine): cap kernel log growth and stop procmgr map/goroutine lea…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-24T14:24:01Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9d52cb71615a65fb00374bb4a659a08d1b6c9b18",
"body": "…(#396)\n\nThe kernel's HTTP/MCP surface treats callers as trusted-local, but several\nsites built filesystem paths from caller input via filepath.Join with no\ncontainment check — each an arbitrary read/write surface via \"../\" traversal\nor an absolute path:\n\n - WriteCogDoc / cog_write_cogdoc (mcp_serv\n[…]\nt and contains\nto the workspace root (it legitimately reaches .cog/ontology, so cogRoot is the\nboundary). Tests cover traversal rejection, the absolute-containment nuance, and\nthe memory-resolver gap.",
"is_bot": false,
"headline": "fix(security): contain caller-supplied paths on the HTTP+MCP surface …",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-24T13:58:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c7ead4a0ad33a594fc5568cdf96f8a74975a93c3",
"body": null,
"is_bot": false,
"headline": "chore: bump version to 0.16.3 (#395)",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-24T11:20:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6f21948a8b4ac58d0b27909504f7cbe60b2c063b",
"body": "GitHub's macos-13 runners chronically sit queued for hours, and the release job\nneeds the full build matrix, so the darwin-amd64 (Intel Mac) build wedges every\nrelease — it cancelled v0.16.1 after 24h and stalled v0.16.2. Drop it; release\ntargets are arm64 Mac + linux (+ windows). The Makefile `all` target still\ncross-builds darwin-amd64 for local use; re-add the matrix entry when an\nIntel-Mac target or a reliable runner is needed.",
"is_bot": false,
"headline": "ci(release): drop darwin-amd64 from the release matrix (#394)",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-24T11:11:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3131cd1d1728170cf72687bf6c39591c56971e87",
"body": "…hash (#393)\n\nFetchLive re-spawned `python3 cogblock.py parse` for every source cogdoc on\nevery reconcile cycle — one subprocess per file, ~1.5s/cycle with the current\ncorpus (per the per-phase timing from #389; the convergence self-reporter from\n#391 flagged projection-compiler as the next over-bud\n[…]\nwnstream in ComputePlan/ApplyPlan, so sharing the\npointer is safe). Cache entries for deleted/renamed sources are evicted.\n\nSole-corpus fetch_ms drops from ~1.5s toward a few ms (file reads + hashes).",
"is_bot": false,
"headline": "perf(projection-compiler): cache cogblock.py parse by source content …",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-24T11:09:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2ccc94826a53f5987ecf03f3c9466cb290947244",
"body": "…392)\n\nFetchLive reloaded the entire conversation index from disk every reconcile\ncycle (idx.Load reads _meta.json + every per-session turn file) — ~950ms and\n~92% of the cycle per the per-phase timing added in #389 (cycle fetch_ms). But\nthe daemon is almost always the sole writer: UpsertSession/Del\n[…]\n cycle.\n\nBoth the reconcile daemon and the autonomic ticker drive FetchLive, so this\nremoves the dominant per-cycle cost from both loops. Sole-writer fetch_ms drops\nfrom ~950ms toward single-digit ms.",
"is_bot": false,
"headline": "perf(conversations): skip FetchLive reload when index is unchanged (#…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-24T03:57:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "01102bf5f9f5235389412b108fe96079c2a20123",
"body": "The reconcile daemon recorded per-cycle cost but nothing watched the stream, so\na misbehaving provider only surfaced when an operator noticed elevated CPU and\nhand-traced the logs. Add a convergence tracker that flags two clean signals and\nemits a WARN (de-duped) plus a queryable snapshot:\n\n - cost\n[…]\n behaviour (flagged / not-flagged), not just code\npaths — see convergence_tracker_test.go, which asserts the real ~950ms\nconversations regression would be flagged and a fast healthy provider never is.",
"is_bot": false,
"headline": "feat(reconcile): self-report per-provider reconcile anomalies (#391)",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-24T03:21:26Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ff5364f54b76d903362cebdf4b47b80cc9cb6d06",
"body": "…ssions (#387)\" (#390)\n\nThis reverts commit ecdc366d746579999f0417b13db7bd9004d9cd33.",
"is_bot": false,
"headline": "Revert \"perf(conversations): incremental append-aware parse for CC se…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-24T03:21:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0f1a78272b82389604af165d0ff17d8e66735454",
"body": "The reconcile daemon recorded only the opaque cycle total (cycle.duration_ms),\nso a slow provider cycle could not be attributed to a phase without attaching a\nprofiler. Time each phase (LoadConfig, FetchLive, LoadState, ComputePlan,\nApplyPlan, BuildState+WriteState) and emit the breakdown both in th\n[…]\ntelemetry alone, without attaching a profiler.\n\nThis immediately surfaced that the conversations provider spends ~92% of its\n~1s cycle in FetchLive (a full index reload from disk), not in parse/apply.",
"is_bot": false,
"headline": "feat(reconcile): per-phase timing in the reconcile cycle (#389)",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-24T03:09:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ecdc366d746579999f0417b13db7bd9004d9cd33",
"body": "…#387)\n\nThe Conversations Observatory reconcile cycle never converged: every cycle\nre-read and re-parsed each growing Claude Code session JSONL from byte 0.\nA live session whose mtime/size changes each cycle forever triggered\nActionUpdate -> full ParseSession -> UpsertSession -> drift again, holding\n[…]\nce regression\nguard; full-reparse fallback on rewrite; and an end-to-end reconcile that\nasserts an append yields an is_append_only update and a no-change cycle\nconverges to zero create/update actions.",
"is_bot": false,
"headline": "perf(conversations): incremental append-aware parse for CC sessions (…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-24T02:13:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1823a2db614b7b2c6872ed5f1894bddcaad64a77",
"body": "…(#388)\n\nIn the daemon binary LoadRegistry is intentionally nil — it is wired only\nthrough the cog CLI DI seams — so the component provider is inert: LoadConfig\nreturns nil and the reconcile cycle reports \"in sync\" with nothing to observe.\nHealth(), however, returned Degraded/Unknown for that same n\n[…]\nw mirrors the other nil-handling paths (LoadConfig,\nFetchLive, ComputePlan) and returns Synced/Healthy when LoadRegistry is nil.\n\nAdds a test asserting the inert nil-LoadRegistry path reports Healthy.",
"is_bot": false,
"headline": "fix(component): report Healthy when LoadRegistry is unwired (daemon) …",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-24T02:13:35Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "94c5031a7d82de1320f2cbf93d7bfd6adead7edd",
"body": "…ts (#386)\n\nUnsent composer drafts captured by the claude-ai-web observer carry role\n\"user-draft\", which the ingest schema did not recognize. Every reconcile\ncycle re-rejected all of them (one log line per record) and held the\nconversations provider permanently Degraded, so it never reached a\nconver\n[…]\nxisting convergence-safe terminal\n(mirrors the unmapped-component path), so the source becomes fully\naccounted and the loop stops while the drafts are preserved, not dropped.\n\nBumps version to 0.16.2.",
"is_bot": false,
"headline": "fix(conversations): recognize user-draft role; quarantine unsent draf…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-24T00:40:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9d73ff42f8a22dc0e13ed62f19f21451b9154528",
"body": "…nged sources\n\nStop the per-cycle full-corpus coverage re-parse in the conversations reconcile: cache per-source coverage, serve unchanged (ActionSkip) sources from cache, recompute only on create/update, cold-fill once after restart, prune removed sources. Eliminates a ~3-core CPU sink. Verified with build/vet/race tests + 3-lens adversarial review.",
"is_bot": false,
"headline": "fix(conversations): cache per-source coverage; skip re-parse on uncha…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-17T01:33:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "229a3d39d38efcc2ba5201bd884ac96f1b750e37",
"body": null,
"is_bot": false,
"headline": "chore: bump version to 0.16.1",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-16T20:25:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ebb2a15f45c7e5cc2f98ddfafa0d816a7ee60d3d",
"body": "Side-effect-free kernel-boundary admission check (IsKnownModel + AvailableModelIDs): handleChat rejects an unknown non-empty model id with HTTP 400 naming the model + available menu, instead of forwarding to the default provider and emitting an opaque 500-wrapped upstream 404.",
"is_bot": false,
"headline": "fix(engine): reject unknown model ids at kernel boundary with 400",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-16T20:24:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c1566ae21263abd239fac030050d5b0be898ffd1",
"body": "Scrub private cog:// slugs, hardcoded user paths, and a resolvable private RFC path from public docs; gitignore runtime/private spill dirs (.cog/blobs, .cog/mem/episodic, .cog/mem/working, .hermes). Docs + .gitignore only; no code change.",
"is_bot": false,
"headline": "chore(docs): scrub residual private refs and ignore runtime spill",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-16T20:18:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e6e0d1f205299f220bd7bc8563afb98ebfe2be80",
"body": "…ls have working FTS5 search (#381)\n\n* fix(release): build with CGO_ENABLED=1 + -tags fts5 so released kernels have working FTS5 search\n\nThe release workflow built every artifact with CGO_ENABLED=0 and no -tags\nfts5. The kernel reaches sqlite's FTS5 engine through mattn/go-sqlite3, a\nCGO binding tha\n[…]\n=0 / missing -tags fts5\nregression — which shipped silently in v0.16.0 — from recurring: the\nrelease fails loudly if the build path drifts away from the Makefile's\nBUILD_TAGS=fts5 + host-CGO contract.",
"is_bot": false,
"headline": "fix(release): build with CGO_ENABLED=1 + -tags fts5 so released kerne…",
"author_name": "Chaz Dinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-15T12:47:27Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "462fbfbf09ca78b71895548686e7981bd17d61f5",
"body": "* docs(adr): flatten yaml-cog-block frontmatter and scrub private refs in ADR-100/101\n\nADR-100 and ADR-101 used a nonstandard nested cog: YAML block instead of\nflat frontmatter. Flatten to standard flat YAML. In the same pass, replace\nall cog:// private-corpus URIs in the refs fields:\n- ADR-091 and \n[…]\nvate internal research corpus name) in §1b and Discussion log\n- Replace RFC-025 body reference in §4 Composition with description\n- Replace private memory-file slugs in §8 Provenance with descriptions",
"is_bot": false,
"headline": "docs: remove internal references from public ADRs/RFCs (#379)",
"author_name": "cdinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-11T23:53:44Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "13c0368546e167c6ae13af168f5812b30eee0f7e",
"body": "Release content: conversations observatory ingest surface v0.1 (#369),\nquery-aware URI resolver per ratified RFC (#370), MCP tool-output byte\ncaps (#371), e2e MCP transport probe (#372), daemon wiring test +\nproviders/all extraction (#374), chat 501 fix (#376), nightly\nintegration workflow (#377), ontology-as-class enforcement (#375).",
"is_bot": false,
"headline": "chore: bump version to 0.16.0 (#378)",
"author_name": "cdinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-10T21:19:16Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e084b372f4ec8ee7b0cacf16fb1598fd5dfc4b17",
"body": "…uarantine, coverage metric (v0.2 groundwork) (#375)\n\n* feat(conversations): add ontology loader, quarantine writer, coverage tracker (v0.2 data layer)\n\nIntroduces the four data-layer types that back ontology-as-class enforcement:\n\n- ontology.go: ParseL1Ontology (L0 grammar validation), LoadOntology\n[…]\nwo cycles,\nhermes-darkstar degenerate=14690 (baseline 14690), hermes-cog\ndegenerate=1857 (baseline 1857), counts stable across cycles.\n\n* test: t.Fatal on nil LoadedOntology guard (staticcheck SA5011)",
"is_bot": false,
"headline": "feat(conversations): ontology-as-class enforcement — load L0/L1/L2, q…",
"author_name": "cdinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-10T20:17:20Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0b7a7dd1926ed26a8c0f77253ddaa6548de71637",
"body": "Job 1 runs the self-contained -tags integration suites (httptest/tempdir\nbased); job 2 attempts the Ollama-dependent set, clearly labeled and\ncontinue-on-error. No || true on enforced jobs. Re-verified on current\nmain after fix(engine) #376 unblocked TestIntegrationFullLifecycle.\nSupersedes #373 (branch history unmergeable after squash cascade).",
"is_bot": false,
"headline": "ci(nightly): run the dormant integration-tagged test suites (#377)",
"author_name": "cdinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-10T20:09:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "25185470009346b8e5b82cbaf352b86074e91f02",
"body": "…nfigured (#376)\n\nMoves the s.router == nil guard to the top of handleChat, ahead of the\nio.ReadAll / json.Unmarshal calls. Previously a nil or empty request body\n(e.g. the integration test's bare POST) would hit the JSON parser first and\nreturn 400 before reaching the 501 branch — breaking\nTestIntegrationFullLifecycle/chat_returns_501. The duplicate nil-check lower\nin the function is removed; behavior for the router-present path is unchanged.",
"is_bot": false,
"headline": "fix(engine): return 501 before parsing chat body when no router is co…",
"author_name": "cdinkle",
"author_login": "chazmaniandinkle",
"committed_at": "2026-06-10T20:03:18Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 38,
"commits_last_year": 810,
"latest_release_at": "2026-07-17T13:43:00Z",
"latest_release_tag": "v0.16.20",
"releases_from_tags": false,
"days_since_last_push": 0,
"active_weeks_last_year": 21,
"days_since_latest_release": 6,
"mean_days_between_releases": 1.7
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": true,
"health_percentage": 100,
"has_issue_template": false,
"has_code_of_conduct": true,
"has_pull_request_template": true
},
"ecosystem": {
"packages": [
{
"name": "github.com/myrgic/cogos",
"exists": true,
"license": null,
"keywords": [],
"ecosystem": "go",
"matches_repo": true,
"registry_url": "https://pkg.go.dev/github.com/myrgic/cogos",
"is_deprecated": false,
"latest_version": "v0.16.20",
"repository_url": "https://github.com/myrgic/cogos",
"versions_count": 40,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": null,
"first_published_at": null,
"latest_published_at": "2026-07-17T13:34:45Z",
"latest_version_yanked": null,
"days_since_latest_publish": 6
}
]
},
"popularity": {
"forks": 1,
"stars": 2,
"watchers": 0,
"fork_history": {
"days": [
{
"date": "2026-04-06",
"count": 1
}
],
"complete": true,
"collected": 1,
"total_forks": 1
},
"star_history": null,
"open_issues_and_prs": 39
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [],
"has_llms_txt": false,
"has_dockerfile": true,
"has_mcp_signal": true,
"bootstrap_files": [
"Makefile"
],
"api_schema_files": [
"bep_proto/bep.proto"
],
"has_devcontainer": false,
"typecheck_configs": [],
"toolchain_manifests": [
"envspec/go.mod",
"go.mod",
"harness/go.mod",
"pkg/bep/go.mod",
"pkg/cogblock/go.mod",
"pkg/cogfield/go.mod",
"pkg/coordination/go.mod",
"pkg/modality/go.mod",
"pkg/reconcile/go.mod",
"pkg/substrate/go.mod",
"pkg/uri/go.mod",
"sdk/go.mod"
],
"largest_source_bytes": 138356,
"source_files_sampled": 697,
"oversized_source_files": 4,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"dependencies": {
"manifests": [
"envspec/go.mod",
"go.mod",
"harness/go.mod",
"sdk/go.mod"
],
"advisories": {
"error": null,
"scope": null,
"source": null,
"findings": [],
"collected": false,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 0,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"go"
],
"dependencies": [
{
"name": "github.com/charmbracelet/bubbles",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.21.0"
},
{
"name": "github.com/charmbracelet/bubbletea",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.3.10"
},
{
"name": "github.com/charmbracelet/lipgloss",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.1.0"
},
{
"name": "github.com/coder/acp-go-sdk",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.13.0"
},
{
"name": "github.com/coder/websocket",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.8.14"
},
{
"name": "github.com/fsnotify/fsnotify",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.7.0"
},
{
"name": "github.com/go-git/go-git/v5",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v5.16.4"
},
{
"name": "github.com/google/uuid",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.6.0"
},
{
"name": "github.com/hashicorp/hcl/v2",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v2.24.0"
},
{
"name": "github.com/mattn/go-sqlite3",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.14.24"
},
{
"name": "github.com/modelcontextprotocol/go-sdk",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.5.0"
},
{
"name": "github.com/myrgic/cogos/envspec",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0"
},
{
"name": "github.com/myrgic/cogos/harness",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0"
},
{
"name": "github.com/myrgic/cogos/pkg/cogblock",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-00010101000000-000000000000"
},
{
"name": "github.com/myrgic/cogos/pkg/cogfield",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0"
},
{
"name": "github.com/myrgic/cogos/pkg/coordination",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-00010101000000-000000000000"
},
{
"name": "github.com/myrgic/cogos/pkg/modality",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-00010101000000-000000000000"
},
{
"name": "github.com/myrgic/cogos/pkg/reconcile",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-00010101000000-000000000000"
},
{
"name": "github.com/myrgic/cogos/sdk",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0"
},
{
"name": "github.com/opencontainers/go-digest",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.0.0"
},
{
"name": "github.com/opencontainers/image-spec",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.1.1"
},
{
"name": "github.com/santhosh-tekuri/jsonschema/v5",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v5.3.1"
},
{
"name": "github.com/zclconf/go-cty",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.17.0"
},
{
"name": "go.opentelemetry.io/otel",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.43.0"
},
{
"name": "go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.43.0"
},
{
"name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.40.0"
},
{
"name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.43.0"
},
{
"name": "go.opentelemetry.io/otel/metric",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.43.0"
},
{
"name": "go.opentelemetry.io/otel/sdk",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.43.0"
},
{
"name": "go.opentelemetry.io/otel/sdk/metric",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.43.0"
},
{
"name": "go.opentelemetry.io/otel/trace",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.43.0"
},
{
"name": "golang.org/x/mod",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.37.0"
},
{
"name": "golang.org/x/net",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.54.0"
},
{
"name": "golang.org/x/sys",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.44.0"
},
{
"name": "google.golang.org/protobuf",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.36.11"
},
{
"name": "gopkg.in/yaml.v3",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v3.0.1"
},
{
"name": "oras.land/oras-go/v2",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v2.6.0"
},
{
"name": "go.opentelemetry.io/otel",
"manifest": "harness/go.mod",
"ecosystem": "go",
"version_constraint": "v1.43.0"
},
{
"name": "go.opentelemetry.io/otel/trace",
"manifest": "harness/go.mod",
"ecosystem": "go",
"version_constraint": "v1.43.0"
},
{
"name": "gopkg.in/yaml.v3",
"manifest": "harness/go.mod",
"ecosystem": "go",
"version_constraint": "v3.0.1"
},
{
"name": "github.com/coder/websocket",
"manifest": "sdk/go.mod",
"ecosystem": "go",
"version_constraint": "v1.8.14"
},
{
"name": "github.com/fsnotify/fsnotify",
"manifest": "sdk/go.mod",
"ecosystem": "go",
"version_constraint": "v1.7.0"
},
{
"name": "github.com/mattn/go-sqlite3",
"manifest": "sdk/go.mod",
"ecosystem": "go",
"version_constraint": "v1.14.24"
},
{
"name": "gopkg.in/yaml.v3",
"manifest": "sdk/go.mod",
"ecosystem": "go",
"version_constraint": "v3.0.1"
}
],
"all_dependencies": {
"error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
"source": null,
"packages": [],
"collected": false,
"truncated": false,
"total_count": null,
"direct_count": null,
"indirect_count": null
}
},
"maintainership": {
"issues": {
"open_prs": 0,
"merged_prs": 334,
"open_issues": 39,
"closed_ratio": 0.702,
"closed_issues": 92,
"closed_unmerged_prs": 8
},
"bus_factor": 1,
"bot_contributors": 0,
"top_contributors": [
{
"type": "User",
"login": "chazmaniandinkle",
"commits": 611,
"avatar_url": "https://avatars.githubusercontent.com/u/357329?v=4"
}
],
"contributors_sampled": 1,
"top_contributor_share": 1
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"ci.yml",
"nightly-integration.yml",
"pr-review.yml",
"release.yml"
],
"has_docs_dir": true,
"linter_configs": [
".golangci.yml"
],
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"go.sum"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 9,
"reason": "binaries present in source code",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": null,
"reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 10,
"reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 7,
"reason": "Found 22/30 approved changesets -- score normalized to 7",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 0,
"reason": "project has 0 contributing companies or organizations -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 0,
"reason": "no update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": null,
"reason": "packaging workflow not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 0,
"reason": "dependency not pinned by hash detected -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 0,
"reason": "SAST tool is not run on all commits -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 4,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": 1,
"reason": "1 out of the last 5 releases have a total of 1 signed artifacts.",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 0,
"reason": "40 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "7ebe6461c7b0d381e6b90f85dbc47b9f1943bb68",
"ran_at": "2026-07-23T17:18:20Z",
"aggregate_score": 4,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": false,
"has_dependabot_config": false
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-23T11:16:28Z",
"oldest_open_prs": [],
"last_merged_pr_at": "2026-07-22T23:46:54Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": [
{
"number": 98,
"created_at": "2026-04-30T16:59:54Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 101,
"created_at": "2026-04-30T17:01:09Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 105,
"created_at": "2026-04-30T18:29:18Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 205,
"created_at": "2026-05-06T02:33:17Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 206,
"created_at": "2026-05-06T02:33:27Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 207,
"created_at": "2026-05-06T02:33:36Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 208,
"created_at": "2026-05-06T02:34:20Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 274,
"created_at": "2026-05-17T16:24:22Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 275,
"created_at": "2026-05-17T16:24:29Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 276,
"created_at": "2026-05-17T16:24:38Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 301,
"created_at": "2026-05-19T16:41:07Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 302,
"created_at": "2026-05-19T18:00:52Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 310,
"created_at": "2026-05-20T22:56:18Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 321,
"created_at": "2026-05-26T00:28:25Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 322,
"created_at": "2026-05-26T00:29:04Z",
"last_comment_at": "2026-05-26T01:15:26Z",
"last_comment_author": "chazmaniandinkle"
},
{
"number": 330,
"created_at": "2026-05-26T01:46:07Z",
"last_comment_at": "2026-05-26T03:10:16Z",
"last_comment_author": "chazmaniandinkle"
},
{
"number": 340,
"created_at": "2026-05-27T11:52:40Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 383,
"created_at": "2026-06-17T01:31:50Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 384,
"created_at": "2026-06-17T01:33:48Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 385,
"created_at": "2026-06-17T01:33:49Z",
"last_comment_at": null,
"last_comment_author": null
}
]
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/myrgic/cogos",
"host": "github.com",
"name": "cogos",
"owner": "myrgic"
},
"metrics": {
"overall": {
"key": "overall",
"band": "moderate",
"name": "Overall health",
"note": null,
"notes": [],
"value": 61,
"inputs": {
"security": 40,
"vitality": 83,
"community": 43,
"governance": 54,
"engineering": 80
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 83,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "good",
"name": "Development activity",
"note": null,
"notes": [],
"value": 78,
"inputs": {
"commits_last_year": 810,
"human_commit_share": 1,
"days_since_last_push": 0,
"active_weeks_last_year": 21
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "21/52 weeks with commits",
"points": 14.5,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 21
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "810 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 810
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": null,
"notes": [],
"value": 91,
"inputs": {
"releases_count": 38,
"latest_release_tag": "v0.16.20",
"releases_from_tags": false,
"days_since_latest_release": 6,
"mean_days_between_releases": 1.7
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "38 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 38
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 6 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 6
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~1.7 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 1.7
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "1 out of the last 5 releases have a total of 1 signed artifacts.",
"points": 1,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "repository_too_young",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "at_risk",
"name": "Community & Adoption",
"value": 43,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "critical",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 1,
"inputs": {
"forks": 1,
"stars": 2,
"watchers": 0,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "2 stars",
"points": 0,
"status": "missed",
"details": [
{
"code": "stars",
"params": {
"count": 2
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "1 forks",
"points": 0,
"status": "missed",
"details": [
{
"code": "forks",
"params": {
"count": 1
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "0 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 0
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "excellent",
"name": "Community health",
"note": null,
"notes": [],
"value": 92,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": true,
"has_issue_template": false,
"has_code_of_conduct": true,
"has_pull_request_template": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (MIT)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "MIT"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 18,
"status": "met",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 13.5,
"status": "met",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 6.3,
"status": "met",
"details": [],
"max_points": 6.3
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "moderate",
"name": "Sustainability & Governance",
"value": 54,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 10,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 1,
"top_contributor_share": 1
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 100% of commits",
"points": 0,
"status": "missed",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 100
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "1 contributors",
"points": 1.4,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 1
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 0 contributing companies or organizations -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "good",
"name": "Issue & PR responsiveness",
"note": null,
"notes": [],
"value": 81,
"inputs": {
"merged_prs": 334,
"open_issues": 39,
"closed_issues": 92,
"issue_closed_ratio": 0.702,
"closed_unmerged_prs": 8
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "70% of issues closed",
"points": 32.8,
"status": "partial",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 70
}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "334/342 decided PRs merged",
"points": 37.4,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 334,
"decided": 342
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 22/30 approved changesets -- score normalized to 7",
"points": 10.5,
"status": "partial",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "at_risk",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 42,
"inputs": {
"followers": 1,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "myrgic",
"public_repos": 18,
"account_age_days": 107
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "1 followers of myrgic",
"points": 2.2,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 1,
"login": "myrgic"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "18 public repos, account ~0 yr old",
"points": 9.9,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 18
}
},
{
"code": "account_age_years",
"params": {
"years": 0
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"github.com/myrgic/cogos"
],
"ecosystems": "go",
"any_deprecated": false,
"min_days_since_publish": 6
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on go",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "go"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 6 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 6
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "40 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 40
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "good",
"name": "Engineering Quality",
"value": 80,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "good",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 84,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "4 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 4
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": ".golangci.yml",
"points": 16,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".golangci.yml"
}
}
],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
"points": 20,
"status": "met",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "good",
"name": "Documentation",
"note": null,
"notes": [],
"value": 75,
"inputs": {
"topics": [
"ai-agents",
"claude-code",
"context-assembly",
"golang",
"local-first",
"mcp"
],
"has_wiki": false,
"homepage": null,
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": "6 topics",
"points": 10,
"status": "met",
"details": [
{
"code": "topics_count",
"params": {
"count": 6
}
}
],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "at_risk",
"name": "Security",
"value": 40,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "at_risk",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Branch-Protection, Packaging. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"branch_protection",
"packaging"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 40,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 16,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 2,
"scorecard_aggregate": 4
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "binaries present in source code",
"points": 6.8,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 22/30 approved changesets -- score normalized to 7",
"points": 5.2,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 0 contributing companies or organizations -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "no update tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow not detected",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is not run on all commits -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 2,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "1 out of the last 5 releases have a total of 1 signed artifacts.",
"points": 0.8,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "40 existing vulnerabilities detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 1
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "moderate",
"name": "AI Readiness",
"value": 65,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "at_risk",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 1,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "no CLAUDE.md / AGENTS.md / editor rules",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_instructions",
"params": {}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "100 of 100 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 100,
"sampled": 100
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "good",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 72,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"go.sum"
],
"has_dockerfile": true,
"typed_language": true,
"bootstrap_files": [
"Makefile"
],
"has_devcontainer": false,
"has_linter_config": true,
"typecheck_configs": [],
"agent_commit_share": 0,
"toolchain_manifests": [
"envspec/go.mod",
"go.mod",
"harness/go.mod",
"pkg/bep/go.mod",
"pkg/cogblock/go.mod",
"pkg/cogfield/go.mod",
"pkg/coordination/go.mod",
"pkg/modality/go.mod",
"pkg/reconcile/go.mod",
"pkg/substrate/go.mod",
"pkg/uri/go.mod",
"sdk/go.mod"
],
"dependency_bot_commit_share": 0
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "Makefile",
"points": 18,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Makefile"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": ".golangci.yml",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".golangci.yml"
}
}
],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "Go (statically typed)",
"points": 11,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "Dockerfile, lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Dockerfile, lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "no agent-authored commits among the last 100",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_authored_commits",
"params": {
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "no automated dependency updates observed",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_dependency_automation",
"params": {}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"primary_language": "Go",
"largest_source_bytes": 138356,
"source_files_sampled": 697,
"oversized_source_files": 4
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Go (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "4/697 source files over 60KB",
"points": 54.7,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 697,
"oversized": 4
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "moderate",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 60,
"inputs": {
"example_dirs": [],
"has_mcp_signal": true,
"api_schema_files": [
"bep_proto/bep.proto"
]
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": "bep_proto/bep.proto",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "bep_proto/bep.proto"
}
}
],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 20,
"status": "met",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
"GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
],
"report_type": "repository",
"generated_at": "2026-07-23T17:18:42.764479Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/m/myrgic/cogos.svg",
"full_name": "myrgic/cogos",
"license_state": "standard",
"license_spdx": "MIT"
}