Public record
Software health reportschema 0.27.0 · metrics 1.13.0 · 2026-07-23 17:18 UTC

myrgic / cogos

Local Go daemon that gives AI tools persistent shared workspace state. Context assembly, multi-provider inference routing, hash-chained ledger, MCP server.

GoMIT★ 2 stars⑂ 1 forksince Apr 2026View on GitHub ↗

myrgic/cogos holds a health index of 61 out of 100, placing it in the Moderate band. It scores highest on Vitality (83/100) and lowest on Security (40/100). It was last updated today. A single contributor accounts for most of its recent work.

61
overall / 100
Moderate

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

61
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

Myrgic LabsOrganization
1 follower18 public repossince Apr 2026

This repository is backed by an organization — shared, accountable stewardship that can outlive any single maintainer.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publish
Gogithub.com/myrgic/cogosv0.16.20-406 days ago

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

83Good · 22% of overall
How it's scored
36/36Push recency — last push 0 days ago
14.5/36Commit cadence — 21/52 weeks with commits
18/18Commit volume — 810 commits in the last year
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year810
human_commit_share1
days_since_last_push0
active_weeks_last_year21
How it's scored
27/27Ships releases — 38 releases published
36/36Release recency — latest release 6 days ago
27/27Release cadence — a release every ~1.7 days
1/10OpenSSF Scorecard: Signed-Releases — 1 out of the last 5 releases have a total of 1 signed artifacts.
Inputs used
releases_count38
latest_release_tagv0.16.20
releases_from_tagsno
days_since_latest_release6
mean_days_between_releases1.7

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

43At risk · 18% of overall
How it's scored
0/60Stars — 2 stars
0/25Forks — 1 forks
0/15Watchers — 0 watchers
Inputs used
forks1
stars2
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

Community health

92Excellent
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (MIT)
18/18CONTRIBUTING guide
13.5/13.5Code of conduct
0/7.2Issue template
6.3/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingyes
has_issue_templateno
has_code_of_conductyes
has_pull_request_templateyes

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

54Moderate · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
0/22.5Commit distribution — top contributor authored 100% of commits
1.4/13.5Contributor breadth — 1 contributors
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Inputs used
bus_factor1
contributors_sampled1
top_contributor_share1
How it's scored
32.8/46.8Issue resolution — 70% of issues closed
37.4/38.3PR acceptance — 334/342 decided PRs merged
10.5/15OpenSSF Scorecard: Code-Review — Found 22/30 approved changesets -- score normalized to 7
Inputs used
merged_prs334
open_issues39
closed_issues92
issue_closed_ratio0.702
closed_unmerged_prs8
How it's scored
30/30Ownership backing — organization-owned
0/20Verified domain
2.2/25Owner reach — 1 followers of myrgic
9.9/25Track record — 18 public repos, account ~0 yr old
Inputs used
followers1
owner_typeOrganization
is_verified
owner_loginmyrgic
public_repos18
account_age_days107
How it's scored
25/25Published & resolvable — 1 package(s) on go
35/35Publish recency — latest publish 6 days ago
20/20Version history — 40 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packagesgithub.com/myrgic/cogos
ecosystemsgo
any_deprecatedno
min_days_since_publish6

Engineering Quality

Are baseline engineering and documentation practices in place?

80Good · 20% of overall
How it's scored
24/24CI workflows — 4 workflow(s)
24/24Tests present
16/16Linter config — .golangci.yml
0/9.6Pre-commit hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configyes
has_precommit_configno
How it's scored
30/30README
25/25Documentation directory
0/15Documentation / homepage site
10/10Repository description
10/10Topics — 6 topics
0/10Wiki
Inputs used
topicsai-agents, claude-code, context-assembly, golang, local-first, mcp
has_wikino
homepage
has_readmeyes
has_docs_diryes
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

40At risk · 16% of overall
How it's scored
6.8/7.5Binary-Artifacts — binaries present in source code
0/7.5Branch-Protection — no data
2.5/2.5CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
5.2/7.5Code-Review — Found 22/30 approved changesets -- score normalized to 7
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — no data
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
2/5Security-Policy — security policy file detected
0.8/7.5Signed-Releases — 1 out of the last 5 releases have a total of 1 signed artifacts.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 40 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate4
Excluded from scoring (no data or not applicable): branch_protection, packaging. Remaining weights renormalized.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

65Moderate · 0% of overall
How it's scored
0/45Agent instructions — no CLAUDE.md / AGENTS.md / editor rules
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 100 of 100 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share1
agent_instruction_files
agent_instruction_max_bytes
How it's scored
18/18One-command bootstrap — Makefile
22/22Automated tests
11/11Lint / format config — .golangci.yml
11/11Static type checking — Go (statically typed)
10/10Reproducible environment — Dockerfile, lockfile
0/10Demonstrated agent practice — no agent-authored commits among the last 100
0/8Automated maintenance — no automated dependency updates observed
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Inputs used
has_nixno
has_testsyes
lockfilesgo.sum
has_dockerfileyes
typed_languageyes
bootstrap_filesMakefile
has_devcontainerno
has_linter_configyes
typecheck_configs
agent_commit_share0
toolchain_manifestsenvspec/go.mod, go.mod, harness/go.mod, pkg/bep/go.mod, pkg/cogblock/go.mod, pkg/cogfield/go.mod, pkg/coordination/go.mod, pkg/modality/go.mod, pkg/reconcile/go.mod, pkg/substrate/go.mod, pkg/uri/go.mod, sdk/go.mod
dependency_bot_commit_share0
How it's scored
45/45Type-checkable code — Go (statically typed)
54.7/55Manageable file sizes — 4/697 source files over 60KB
Inputs used
primary_languageGo
largest_source_bytes138,356
source_files_sampled697
oversized_source_files4
How it's scored
40/40API schema (OpenAPI/GraphQL/proto) — bep_proto/bep.proto
20/20MCP server
0/40Runnable examples
Inputs used
example_dirs
has_mcp_signalyes
api_schema_filesbep_proto/bep.proto

Key facts

2GitHub stars
1contributors
810commits, last 12 months
0days since last push
38releases
1bus factor
39open issues
Gopackage ecosystems

Data collection warnings

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

More detail

OpenSSF Scorecard 4.0 / 10
4.0aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-23 17:18 UTC

9Binary-Artifactsbinaries present in source code
n/aBranch-Protectioninternal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
10CI-Tests30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
7Code-ReviewFound 22/30 approved changesets -- score normalized to 7
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
n/aPackagingpackaging workflow not detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
4Security-Policysecurity policy file detected
1Signed-Releases1 out of the last 5 releases have a total of 1 signed artifacts.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities40 existing vulnerabilities detected
Direct dependencies 44
RegistryPackageVersion constraintManifest
Gogithub.com/charmbracelet/bubblesv0.21.0go.mod
Gogithub.com/charmbracelet/bubbleteav1.3.10go.mod
Gogithub.com/charmbracelet/lipglossv1.1.0go.mod
Gogithub.com/coder/acp-go-sdkv0.13.0go.mod
Gogithub.com/coder/websocketv1.8.14go.mod
Gogithub.com/fsnotify/fsnotifyv1.7.0go.mod
Gogithub.com/go-git/go-git/v5v5.16.4go.mod
Gogithub.com/google/uuidv1.6.0go.mod
Gogithub.com/hashicorp/hcl/v2v2.24.0go.mod
Gogithub.com/mattn/go-sqlite3v1.14.24go.mod
Gogithub.com/modelcontextprotocol/go-sdkv1.5.0go.mod
Gogithub.com/myrgic/cogos/envspecv0.0.0go.mod
Gogithub.com/myrgic/cogos/harnessv0.0.0go.mod
Gogithub.com/myrgic/cogos/pkg/cogblockv0.0.0-00010101000000-000000000000go.mod
Gogithub.com/myrgic/cogos/pkg/cogfieldv0.0.0go.mod
Gogithub.com/myrgic/cogos/pkg/coordinationv0.0.0-00010101000000-000000000000go.mod
Gogithub.com/myrgic/cogos/pkg/modalityv0.0.0-00010101000000-000000000000go.mod
Gogithub.com/myrgic/cogos/pkg/reconcilev0.0.0-00010101000000-000000000000go.mod
Gogithub.com/myrgic/cogos/sdkv0.0.0go.mod
Gogithub.com/opencontainers/go-digestv1.0.0go.mod
Gogithub.com/opencontainers/image-specv1.1.1go.mod
Gogithub.com/santhosh-tekuri/jsonschema/v5v5.3.1go.mod
Gogithub.com/zclconf/go-ctyv1.17.0go.mod
Gogo.opentelemetry.io/otelv1.43.0go.mod
Gogo.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttpv1.43.0go.mod
Gogo.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpcv1.40.0go.mod
Gogo.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttpv1.43.0go.mod
Gogo.opentelemetry.io/otel/metricv1.43.0go.mod
Gogo.opentelemetry.io/otel/sdkv1.43.0go.mod
Gogo.opentelemetry.io/otel/sdk/metricv1.43.0go.mod
Gogo.opentelemetry.io/otel/tracev1.43.0go.mod
Gogolang.org/x/modv0.37.0go.mod
Gogolang.org/x/netv0.54.0go.mod
Gogolang.org/x/sysv0.44.0go.mod
Gogoogle.golang.org/protobufv1.36.11go.mod
Gogopkg.in/yaml.v3v3.0.1go.mod
Gooras.land/oras-go/v2v2.6.0go.mod
Gogo.opentelemetry.io/otelv1.43.0harness/go.mod
Gogo.opentelemetry.io/otel/tracev1.43.0harness/go.mod
Gogopkg.in/yaml.v3v3.0.1harness/go.mod
Gogithub.com/coder/websocketv1.8.14sdk/go.mod
Gogithub.com/fsnotify/fsnotifyv1.7.0sdk/go.mod
Gogithub.com/mattn/go-sqlite3v1.14.24sdk/go.mod
Gogopkg.in/yaml.v3v3.0.1sdk/go.mod
All dependencies not collected

The resolved dependency set could not be collected for this report: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [
        "ai-agents",
        "claude-code",
        "context-assembly",
        "golang",
        "local-first",
        "mcp"
      ],
      "is_fork": false,
      "size_kb": 36708,
      "has_wiki": false,
      "homepage": null,
      "languages": {
        "Go": 7261564,
        "HTML": 150293,
        "Shell": 180576,
        "Python": 153714,
        "Makefile": 6207,
        "Dockerfile": 1956,
        "JavaScript": 8817
      },
      "pushed_at": "2026-07-22T23:46:55Z",
      "created_at": "2026-04-06T17:20:02Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-22T23:46:58Z",
      "description": "Local Go daemon that gives AI tools persistent shared workspace state. Context assembly, multi-provider inference routing, hash-chained ledger, MCP server.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "Go",
      "significant_languages": [
        "Go"
      ]
    },
    "owner": {
      "blog": null,
      "name": "Myrgic Labs",
      "type": "Organization",
      "login": "myrgic",
      "company": null,
      "location": null,
      "followers": 1,
      "avatar_url": "https://avatars.githubusercontent.com/u/274069615?v=4",
      "created_at": "2026-04-06T17:19:21Z",
      "is_verified": null,
      "public_repos": 18,
      "account_age_days": 107
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.16.20",
          "kind": "patch",
          "published_at": "2026-07-17T13:43:00Z"
        },
        {
          "tag": "v0.16.19",
          "kind": "patch",
          "published_at": "2026-07-07T20:37:53Z"
        },
        {
          "tag": "v0.16.18",
          "kind": "patch",
          "published_at": "2026-07-07T16:32:50Z"
        },
        {
          "tag": "v0.16.17",
          "kind": "patch",
          "published_at": "2026-07-06T21:44:42Z"
        },
        {
          "tag": "v0.16.16",
          "kind": "patch",
          "published_at": "2026-07-06T19:53:36Z"
        },
        {
          "tag": "v0.16.15",
          "kind": "patch",
          "published_at": "2026-07-05T00:59:26Z"
        },
        {
          "tag": "v0.16.14",
          "kind": "patch",
          "published_at": "2026-07-04T14:37:52Z"
        },
        {
          "tag": "v0.16.13",
          "kind": "patch",
          "published_at": "2026-07-04T05:24:56Z"
        },
        {
          "tag": "v0.16.12",
          "kind": "patch",
          "published_at": "2026-07-04T00:53:06Z"
        },
        {
          "tag": "v0.16.11",
          "kind": "patch",
          "published_at": "2026-07-02T04:09:54Z"
        },
        {
          "tag": "v0.16.10",
          "kind": "patch",
          "published_at": "2026-07-01T09:18:25Z"
        },
        {
          "tag": "v0.16.9",
          "kind": "patch",
          "published_at": "2026-06-30T14:10:25Z"
        },
        {
          "tag": "v0.16.8",
          "kind": "patch",
          "published_at": "2026-06-30T13:01:07Z"
        },
        {
          "tag": "v0.16.7",
          "kind": "patch",
          "published_at": "2026-06-30T11:17:59Z"
        },
        {
          "tag": "v0.16.6",
          "kind": "patch",
          "published_at": "2026-06-27T12:54:56Z"
        },
        {
          "tag": "v0.16.5",
          "kind": "patch",
          "published_at": "2026-06-25T10:59:37Z"
        },
        {
          "tag": "v0.16.4",
          "kind": "patch",
          "published_at": "2026-06-25T09:37:49Z"
        },
        {
          "tag": "v0.16.3",
          "kind": "patch",
          "published_at": "2026-06-24T11:25:41Z"
        },
        {
          "tag": "v0.16.0",
          "kind": "minor",
          "published_at": "2026-06-10T21:25:19Z"
        },
        {
          "tag": "v0.15.1",
          "kind": "patch",
          "published_at": "2026-06-08T22:42:03Z"
        },
        {
          "tag": "v0.15.0",
          "kind": "minor",
          "published_at": "2026-06-07T02:55:59Z"
        },
        {
          "tag": "v0.14.2",
          "kind": "patch",
          "published_at": "2026-06-04T21:24:50Z"
        },
        {
          "tag": "v0.14.1",
          "kind": "patch",
          "published_at": "2026-06-04T20:25:12Z"
        },
        {
          "tag": "v0.14.0",
          "kind": "minor",
          "published_at": "2026-06-03T01:33:34Z"
        },
        {
          "tag": "v0.13.0",
          "kind": "minor",
          "published_at": "2026-05-27T02:11:42Z"
        },
        {
          "tag": "v0.12.0",
          "kind": "minor",
          "published_at": "2026-05-25T17:54:41Z"
        },
        {
          "tag": "v0.10.0",
          "kind": "minor",
          "published_at": "2026-05-19T21:12:05Z"
        },
        {
          "tag": "v0.9.0",
          "kind": "minor",
          "published_at": "2026-05-17T00:15:15Z"
        },
        {
          "tag": "v0.8.0",
          "kind": "minor",
          "published_at": "2026-05-15T20:31:05Z"
        },
        {
          "tag": "v0.7.0",
          "kind": "minor",
          "published_at": "2026-05-13T16:14:32Z"
        },
        {
          "tag": "v0.6.0",
          "kind": "minor",
          "published_at": "2026-05-08T21:43:02Z"
        },
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2026-05-08T02:56:44Z"
        },
        {
          "tag": "v0.4.2",
          "kind": "patch",
          "published_at": "2026-05-05T21:37:54Z"
        },
        {
          "tag": "v0.4.1",
          "kind": "patch",
          "published_at": "2026-05-02T16:21:28Z"
        },
        {
          "tag": "v0.4.0",
          "kind": "minor",
          "published_at": "2026-05-01T21:42:20Z"
        },
        {
          "tag": "v0.3.0",
          "kind": "minor",
          "published_at": "2026-04-22T16:01:50Z"
        },
        {
          "tag": "v0.2.0",
          "kind": "minor",
          "published_at": "2026-04-20T01:45:10Z"
        },
        {
          "tag": "v0.1.0",
          "kind": "minor",
          "published_at": "2026-04-14T20:52:26Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "7ebe6461c7b0d381e6b90f85dbc47b9f1943bb68",
          "body": "…reconcile + ConfigExporter snapshot (#473)\n\n* refactor(providers): re-home discord provider into internal/providers/discord\n\nADR-121 Wave 4: the daemon's discordProvider registration\n(internal/providers/daemon/daemon.go) was a Health()-only stub embedding\nstubMethods, standing in for the real Recon\n[…]\nuracy (its one confirmed\nfinding) was already corrected in the PR body, and the daemon\nreconcile-loop Tokenable gap is already disclosed in the PR's \"Not in\nscope\" section as an intentional follow-up.",
          "is_bot": false,
          "headline": "feat(providers): ADR-121 Wave 4 — re-home discord provider with real …",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-22T23:46:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5c677ee4c1461680ef7dadcfd6ef31f7f0d27030",
          "body": "…(#468)\n\n* feat(marginbridge): add margin-bridge GitHub signal watcher provider\n\nKernel-native replacement for the Python bridge_github.py prototype:\noutbound-only gh-api polling of a workspace's signal inboxes and\nsettlement ledger, surfaced as kernel-native wakes (ledger event +\nbus_margin_bridge)\n[…]\ng two actions resolved in the same ApplyPlan call\ncollide if they land in the same millisecond. Mixed in a per-process\nmonotonic counter as a tiebreaker.\n\nPR #468 round-3 cog-review CHANGES_REQUESTED.",
          "is_bot": false,
          "headline": "feat(marginbridge): add margin-bridge GitHub signal watcher provider …",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-22T23:06:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "59606d76aaab39b16a4eb5eca6cc678a85e78076",
          "body": "…463)\n\nA quarantine-only ingest source — every record rejected, e.g. the\nclaude-ai-web observer's unsent composer drafts (role user-draft →\nreason draft_role) — never reaches a converged state, so the\nreconciler re-reads its unchanged ingest file every cycle. Quarantine\nwas append-only with no dedup\n[…]\nason uniformly, not just draft_role.\n\nRegression test: same record across 50 cycles and a simulated restart\n→ 1 line; distinct records still append; content-hash dedup for\nrecords without a stable_id.",
          "is_bot": false,
          "headline": "fix(conversations): make quarantine writes idempotent by stable_id (#…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-22T16:14:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6fcdd2a1f8740fe06c6e2a2729f44168e8c38130",
          "body": "* docs(adr): ADR-121 single-binary consolidation -- fold CLI into cogos, delete legacy root package\n\n* chore(cli): delete legacy root package main per ADR-121\n\nRemoves all 232 root-level .go files (the legacy standalone CLI,\npackage main). The shipped entrypoint is cmd/cogos -> internal/engine\nand a\n[…]\nsubsystem, which predates and is orthogonal to the\nReconcilable-provider pattern and isn't part of ADR-121's Wave 4 list.\n\nVerified: go build ./..., go build -tags fts5 ./..., go vet ./... all\nexit 0.",
          "is_bot": false,
          "headline": "chore(cli): delete legacy root package main per ADR-121 (#464)",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-22T16:12:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e9cb104b537b5d7211e1ec5d347d9e3520a84862",
          "body": "…, chunk 2) (#472)\n\n* feat(identity): ledger-backed identity grants + revoke (board task 60, chunk 2)\n\nChunk 1 (dce2d68, #471) proved kernel-issued identity grants in memory\nonly, with an explicitly-filed gap: a kernel restart silently invalidated\nevery live grant, and a full grant store had no non-\n[…]\ny succeeds\nonce the ledger recovers and the token dies),\nTestIdentityGrantMint_LedgerAppendFailureMapsTo503. Existing Revoke\ncall sites updated to the error-returning signature; all prior tests\ngreen.",
          "is_bot": false,
          "headline": "feat(identity): ledger-backed identity grants + revoke (board task 60…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-22T03:52:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dce2d6889e528f217b15df54ee7b61d04404a47a",
          "body": "…) (#471)\n\n* feat(identity): kernel-issued identity grants (board task 60, chunk 1)\n\nAdds POST /v1/identity/grants, POST /v1/identity/verify, GET /v1/identity/grants,\nand GET /v1/identity/grants/current -- an in-memory, surface-scoped credential\nissuance/verification surface following the serve_sess\n[…]\nfor both: alternating scope across repeated mints for\none surface holds byGrantID at exactly one live entry, and minting past the\ncap is rejected with the capacity error while bySurface stays bounded.",
          "is_bot": false,
          "headline": "feat(identity): kernel-issued identity grants (board task 60, chunk 1…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-22T00:03:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b530df6c1cb7b048e377ffc30e12162ca537f124",
          "body": "…precated temperature (#467)",
          "is_bot": false,
          "headline": "fix(dispatch): route current-generation Anthropic models and strip de…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-17T13:34:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a4d7477761617d9ef8dd446a7878f52370c2fab2",
          "body": "The SiteProvider drift check was a stub (\"ArtifactSHA empty -> update;\notherwise -> skip. Full SHA comparison is planned for v0.1.\"). It only\ndeployed targets that had never been deployed, so once a target had any\ncontent, every subsequent content change was silently skipped and never\nshipped.\n\nRepl\n[…]\n, hashes the output, compares to the live hash:\n  differ or missing -> update, equal -> skip.\n\nContent-only changes now plan as update. Tests added for synced,\ncontent-drift, and missing-marker cases.",
          "is_bot": false,
          "headline": "fix(site): real per-app content-hash drift detection (#462)",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-08T22:32:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "32dbfc619d9d4a6f2d09a53af08b4c9cc9ab1880",
          "body": "…n (#458)\n\n* fix(conversations): atomic + cross-process-locked writes to _meta.json\n\nFixes #449. writeMetaFileLocked previously did a plain os.WriteFile with\nno cross-process coordination, so a CLI-invoked \"cog reconcile\nconversations\" run and the daemon's own reconcile cycle could each\nread-modify-\n[…]\nop races MCP writes; in cmd/cogos the eval reconcile provider is a\n  no-op stub. Comments now state the real guarded races: concurrent MCP\n  invocations, and any future real-provider reconcile wiring.",
          "is_bot": false,
          "headline": "fix(conversations): atomic + cross-process-locked writes to _meta.jso…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-08T00:25:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "62e9d337e4be0c07f27813c714d4cf030d5d3f86",
          "body": "…utation (#460)\n\n* fix(config): gate config-mutation HTTP endpoints, warn on unauthenticated non-loopback bind\n\nGET/PATCH /v1/config and POST /v1/config/rollback were reachable by any\nlocal process on the same host with no gate at all, unlike the existing\nEnableSkillExec (serve_skills.go) / EnableSe\n[…]\ne \"disabled\"/enable_config_mutation wording, matching the established\npattern for resource-read failures elsewhere in this file (resourceState).\n\nTests: TestResourceConfigMCP_GateDisabled/GateEnabled.",
          "is_bot": false,
          "headline": "fix(config): gate config-mutation HTTP endpoints behind EnableConfigM…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-07T22:28:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "24b3ce9cf8593b35c23e860d487f76b51497e66e",
          "body": "Extends the existing lint CI job with a cheap mechanical check\n(scripts/check-shell-hardening.sh) requiring every tracked scripts/*.sh\nfile to declare `set -euo pipefail` (or `set -eu` for POSIX sh, which\nhas no pipefail) or carry a documented `# no-pipefail: <reason>`\nopt-out, plus a shellcheck err\n[…]\nened POSIX\nsh, documented opt-out, unhardened, non-shell-shebang skip, shellcheck\nerror-severity, mixed tree), plus an acceptance test running the real\ngate against this repo's own scripts/ directory.",
          "is_bot": false,
          "headline": "ci(shell): add shell-hardening gate for scripts/*.sh (ledger L15) (#459)",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-07T21:49:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "39d63c2c2ababb7c343344c90dbf839c95eb44eb",
          "body": "Adds keyless Sigstore signing of checksums.txt to the release pipeline\nusing the GitHub OIDC identity (id-token: write, scoped to the release\njob), plus a fail-closed self-verify step before publishing. Documents\nwhat is signed, the exact consumer verify command, and the trust model\nin docs/release-signing.md.\n\nRatified v1.0 alignment item L12 (release integrity), phase 1\n(release-side signing). Kernel self-update verification of this\nsignature is out of scope here and tracked in #454.",
          "is_bot": false,
          "headline": "ci(release): sign checksums.txt with Sigstore/cosign (keyless) (#456)",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-07T21:49:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "863ce4e2919f3a83b8512730b9f5de00775cb7d9",
          "body": "…ism (#457)\n\n* fix(replay): implement real sha256 hash and wire VerifyReplayDeterminism into tests\n\nhashString was a placeholder that returned its input bytes verbatim\ninstead of hashing (replay.go:402), so ComputeReplayHash was string\nidentity dressed as a hash. VerifyReplayDeterminism, its only re\n[…]\nng covers ID/Type/branch/branchSeq\nand not Timestamp/ParentID/Data -- pre-existing scope, not a regression,\nflagged per review rather than widened, since that's a design call\noutside this fix's scope.",
          "is_bot": false,
          "headline": "fix(replay): implement real sha256 hash and wire VerifyReplayDetermin…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-07T20:48:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f6d860322df832de7a1a5776e31637374a12f46e",
          "body": "…on (#455)\n\nendpointReachable unconditionally cached a negative probe result on any\nHTTP failure, including when the failure was caused by the CALLER's own\ncontext being cancelled (e.g. an HTTP client disconnecting mid-dispatch,\nsince ctx traces back to r.Context() via DispatchToHarness). That\npoiso\n[…]\nmeout firing on a genuinely slow/hung\nendpoint) is unaffected and still caches negative.\n\nAdds two regression tests: a cancelled caller ctx must not write the\ncache; a genuine connection refusal must.",
          "is_bot": false,
          "headline": "fix(dispatch): guard reachability cache against caller-ctx cancellati…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-07T20:41:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9893d6267ba79761211e37d27e13080e8428291b",
          "body": "…y + salience-strip (ADR-103) (#452)\n\n* feat(foveation): cache-aware placement, salience strip, session-scoped light-cone key\n\nUnder a plain prefix cache (llama.cpp / LM Studio / OpenAI-compat), the volatile\nfoveal doc manifest sat at the FRONT of the token stream, so its per-turn churn\nre-prefilled\n[…]\n build ./... and go test -race\n./internal/engine/... green.\n\n* chore: re-trigger review (cog-review transient error on prior head)\n\n* chore: re-trigger review (cog-review errored twice on prior heads)",
          "is_bot": false,
          "headline": "feat(foveation): cache-aware placement + session-scoped light-cone ke…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-07T20:26:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "04cb2f2e87902802b7e4127ad29966ad80618d60",
          "body": "…104) (#453)\n\n* feat(engine): lms-model-state declarative reconciler (opt-in, off by default)\n\nAdd a Reconcilable that keeps an LM Studio backend loaded with the declared\nmodel at the declared context length, orthogonal to OpenAI-compat dispatch.\nModels the mlx-supervised dual-shape precedent, swapp\n[…]\nMSModelStateProviderConcurrentFieldAccess (SetToken/LoadConfig writes\n  vs FetchLive/Health reads) so -race flags any regression.\n\n* chore: re-trigger review (cog-review transient error on prior head)",
          "is_bot": false,
          "headline": "feat(inference): lms-model-state declarative reconciler, opt-in (ADR-…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-07T20:26:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "32d445e0b74b4c9106848b55320f836f7e37abf7",
          "body": "…ackends) (#451)\n\n* feat(inference): live /v1/models composition with admission-parity fixes\n\nLive-view GET /v1/models: enumerate every ModelLister provider (bounded,\nconcurrent, graceful-skip), emit composite \"<provider>/<model>\" ids for\nlocal/OpenAI-compat providers and bare claude ids for frontie\n[…]\next caller rebuilds\ncleanly. Mirrors the #441 Available() TTL-cache guard. Adds a regression test\n(cancelled caller -> next healthy caller still gets the full menu) and makes the\nlisterStub ctx-aware.",
          "is_bot": false,
          "headline": "feat(inference): live /v1/models composition (Anthropic + LM Studio b…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-07T16:21:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dcba52627fb267954c94a58a40d76eafb82c1888",
          "body": "… A-E) (#447)\n\n* feat(testkernel): First Instruments Module A — cadence + cell-lattice test surface\n\nAdds the boot/testkernel extensions needed to observe and control kernel\ncadence in tests: WithPollInterval (wires the previously-dead\nbootConfig.pollInterval into ReconcileDaemonConfig.PollInterval)\n[…]\nre-check -- multi-hour-to-multi-day wall-clock time the runner\nitself does not shorten. Running that sweep is the next action once this\nPR lands, not a step this implementation session could complete.",
          "is_bot": false,
          "headline": "feat(instruments): First Instruments Stage-2 instrumentation (Modules…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-07T12:54:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "207e329cd8bebcb75c1aa2384fa6732875721e1b",
          "body": "cog_fork_session and POST /v1/sessions/{id}/fork both register the child\nsession via ApplyRegister with appendFn=nil, relying on the session.fork\nbus event written just before as the child's only durable record. But\nReplaySessionRegistry's switch had no case for \"session.fork\", so the\nchild row was \n[…]\nerve.go) and the stdio MCP path (cli_mcp.go), which previously never\nwired a ForkRegistry at all. PinnedUntil is preserved via the fork body\nround-trip so GC expiry semantics survive replay unchanged.",
          "is_bot": false,
          "headline": "fix(sessions): forked sessions and lineage survive kernel restart (#446)",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-06T22:01:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "735a138891576edee9406133197197d97eecb5a3",
          "body": "…ecord drift (#444)\n\nSelf-update writes kernel.toml (version + current-platform checksum) write-ahead before the binary swap and rolls it back on failure, so the pinned-version record stops drifting from the running daemon (#442). Dormant no-op where no kernel.toml exists; perm-restore is best-effort so a chmod failure can't strand a committed write. Hardened per Fable + cog-review.",
          "is_bot": false,
          "headline": "fix(self-update): write-ahead kernel.toml maintainer to end version-r…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-06T21:39:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b40c804d783614a5067d84022fec736c8fd7c8ec",
          "body": "…aware fallback (#445)\n\nProbe now bounded by an internal deadline so availMu isn't held for the full client timeout; stream_options.include_usage restores token accounting on the cancel-safe streaming path; fallback skips model-incompatible LOCAL providers (IsLocal && !AgenticHarness) so a downed local LMS fails over to a sibling serving the model instead of firing a bogus model id at a frontier provider. Addresses the Fable pipeline review.",
          "is_bot": false,
          "headline": "fix(inference): robust availability probes, end-to-end usage, compat-…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-06T21:39:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5a9bc943ea659fc419549569e3d27f02eb3e23b3",
          "body": "…v1/models polling (#443)\n\nOpenAICompat, ClaudeOAuth, and Ollama providers now cache their Available() reachability probe for 30s (availCacheTTL), so the router's 10s availability ticker and the per-request /v1/providers handler stop issuing a live GET /v1/models (and /api/tags) on every call. A cal\n[…]\nning); a probeTimeout deadline on a slow provider IS cached as unavailable. Anthropic/Codex/ClaudeCode/Pi Available() are cheap local checks needing no cache; MLXSupervised already caches.\n\nRefs #441.",
          "is_bot": false,
          "headline": "perf(inference): cache live provider Available() probes to stop 10s /…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-06T19:47:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3c437feb6ca9cbf59aaf0659d5c63405d23bdfc0",
          "body": "* feat(dispatch): async job handle for cog_dispatch_to_harness (fixes #32001)\n\ncog_dispatch_to_harness is fully synchronous -- the MCP request blocks\nuntil every fan-out slot completes, errors, or hits its per-slot timeout\n(up to 600s). Interactive MCP clients often close their request window\nwell b\n[…]\n pre-existing MCP-side async tests\n(TestToolDispatchToHarness_AsyncReturnsImmediateJobHandle et al.) carry\nthe same latent hazard but are out of scope for this PR's confirmed\nfindings; left untouched.",
          "is_bot": false,
          "headline": "feat(dispatch): async job handle + harness capability gating (#437)",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-05T23:15:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "776b66698d1beaff2c701b2a6cdb757b1e36268d",
          "body": "…itHub (#438)\n\n* fix(ci): gate must fail closed — neutral passes a required check on GitHub\n\nDiscovered once cog-review became a required check: GitHub treats a\n`neutral` required check-run as PASSING, not blocking. The gate mapped its\nfail-safe cases (reviewer error, sandbox-canary failure, unconfi\n[…]\nle, within the trust model): a bot CHANGES_REQUESTED review at\nhead -> reconcile; a COMMENTED review or none (errors post none) ->\nescalate to operator (exit 4), matching the script's header contract.",
          "is_bot": false,
          "headline": "fix(ci): gate must fail closed — neutral passes a required check on G…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-05T22:31:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b00db12b9c7e5d426274526d1125b0e165ed94aa",
          "body": "…ge stays local (#436)\n\n* ci(review): repo-resident cog-review gate — approve-authority, merge stays local\n\nAdds a two-tier PR gate that any contributor's PR passes through identically\n(the gate is identity-blind; merge authority is not):\n\n- mechanical: deterministic Conventional-Commits title check\n[…]\np mechanical job re-validates; guard the expensive\ncog-review job with action != 'edited' since a title/body edit leaves the\ndiff (and thus the code verdict) unchanged — no wasted AI review on a typo.",
          "is_bot": false,
          "headline": "ci(review): repo-resident cog-review gate with approve authority, mer…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-05T20:55:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ed0714aa94770edf7e7948e878ce0af76771746e",
          "body": "…ispatch_to_harness (#435)\n\nOperator directive (2026-07-04): \"expand the timeout caps to at least 5m.\nWith agentic workflows that will likely get pushed even further out, so\nthe timeout should be a parameter, not hardcoded.\"\n\n- Per-slot timeout cap becomes config-driven: dispatch_timeout_cap_seconds\n[…]\nday), which deliberately raised the default to 240s as\nan incident fix (zombie generations under a 30s ceiling). The default is\nleft at 240s to avoid regressing that fix; the doc strings now state it.",
          "is_bot": false,
          "headline": "feat(dispatch): config-driven timeout cap + doc-drift fixes for cog_d…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-05T00:53:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e4e6acae5c60ffa8a66073d97c0b2b592d521eb7",
          "body": "…etries (#432) (#434)\n\nNon-streaming completion calls to LM Studio (openai-compat) did not abort\ngeneration server-side when the kernel gave up waiting: the client-side\nComplete() call returns on ctx cancel, but the connection isn't torn down\nin time for the server to notice, so the model keeps gene\n[…]\n, so without the override a countingProvider wrapping a\ncancel-safe-capable provider silently fell back to plain Complete on the\ndispatch path specifically. Found via the retry-dedup integration test.",
          "is_bot": false,
          "headline": "fix(engine): propagate local-inference cancellation, bound timeouts/r…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-04T14:32:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "704ae050bc02c8a7102e58625e90eccdc3a7bc63",
          "body": "…lt (#431)\n\ncog_dispatch_to_harness silently discarded an explicit model the caller\nrequested in two places: DispatchRequest.Normalize() collapsed any\nnon-enum model string to \"e4b\" before routing ever saw it, and the\nexplicit-provider / harness-provider-default / state-routing paths in\nDispatchToHa\n[…]\nuest over the config default. When the provider cannot serve the\n  requested model it still fails loudly via the existing non-2xx wire\n  error path — no client-side substitution was added.\n\nFixes #430",
          "is_bot": false,
          "headline": "fix(dispatch): honor caller-explicit model over provider config defau…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-04T05:18:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "19c17189d39e451be74ef85288d30d2780a8fd7e",
          "body": "…ace (#426)\n\n* fix(dispatch): default local-LLM endpoint to LM Studio :1234, not Ollama :11434\n\nopenaiCompatDefaultEndpoint had drifted back to Ollama's decommissioned\n:11434 after PR #417 moved the default local backend to LM Studio\n(lmstudio-darkstar, 127.0.0.1:1234). A no-provider cog_dispatch_to\n[…]\nlog, ~57 entries, one\nscan per rejection) to help with typos.\n\nExtends the existing TestToolInvoke_* family with both cases plus focused\nunit tests on the new eagerToolExists/nearestToolNames helpers.",
          "is_bot": false,
          "headline": "fix(dispatch,mcp): LM Studio default endpoint + eager-tool error surf…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-04T00:48:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e03ad3860f2672270c478fabed903601973235c0",
          "body": "… leftovers (#419)\n\n* fix(constellation): harden the FTS write path — serialize index writes, refresh mtime on hash-skip, prune ghost rows on reindex\n\nThree write-path fixes in the constellation indexer:\n\n1. Concurrent IndexFile corrupted transaction state: upsertFTSRow issued\n   SAVEPOINT/RELEASE a\n[…]\nsion exercises the real\nStreamable HTTP transport without a prior register call and asserts the\ndenial; the existing TestToolInvoke_EnforcesCapabilityGating (registered\nallow/deny paths) still passes.",
          "is_bot": false,
          "headline": "fix: FTS write-path hardening, drift-repair correctness, decommission…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-02T04:04:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e38ae77becca59e261418b841e5542b303cec222",
          "body": "feat(mcp): porcelain/plumbing tool surface — lean eager set fronting a deferred catalog",
          "is_bot": false,
          "headline": "Merge pull request #418 from myrgic/feat/porcelain-plumbing-tool-surface",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-01T09:12:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "136f71de7cff537d1545aa719cbfc32a8cfadf0a",
          "body": "…quote corruption\n\n- backfillEagerSchemas ran only in the constructor, before RegisterMCPExtensions\n  fires in registerMCPRoutes — so extension eager tools (cog_search_conversations,\n  cog_get_conversation_turn) kept nil InputSchema and cog_tool_search returned null\n  schemas for them. Re-run the idempotent backfill after the extension hook.\n- revert 3 doc-comment backtick pairs mangled into curly quotes by a find-replace\n  in mcp_modality_proxy.go; fix stale ~13 -> ~14 porcelain-count comment.",
          "is_bot": false,
          "headline": "fix(mcp): backfill extension-registered eager schemas + revert curly-…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-01T09:06:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "baa4df273c378209b09567a151e6ccef8b6e3698",
          "body": "…s schema\n\nFixes toolInvokeInput.Args: json.RawMessage infers as an array/null\nJSON Schema (byte slice), not an object, so any real args payload\nfailed schema validation before the handler ever ran. Switched to\nmap[string]any (re-marshaled to JSON before handing to the deferred\nhandler, which still \n[…]\nt)\n  - a porcelain tool (cog_get_state) is still directly callable\n  - a deferred tool (cog_read_ledger, mod3_speak) is absent from\n    ListTools/tools-list while still present in the toolMeta catalog",
          "is_bot": false,
          "headline": "test(mcp): regression coverage for porcelain/plumbing split + fix arg…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-01T08:48:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a929214aa4f12c95c9454cee4ef3fc2503c81389",
          "body": "Server-autonomous porcelain/plumbing split (workflow wkweyu50g, plan\ncog:mem/semantic/architecture/mcp-tool-surface-tier-then-trim.cog.md\n#Mechanism, RESOLVED). The kernel cannot ask a harness to defer-load\nspecific MCP tools, so it shrinks what it advertises instead.\n\n- trackToolDeferred (serve_man\n[…]\n KernelToolRegistry (tool_loop.go)\nis unaffected — it calls handler functions directly and was never\nrouted through mcp.AddTool or m.server, so named scopes (audit, emit,\netc.) keep working unchanged.",
          "is_bot": false,
          "headline": "feat(mcp): partition tool surface into porcelain + deferred plumbing",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-01T08:44:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5877ccaf013b0ae6f8846ef6d2940cefc49df35b",
          "body": "mcpToolMeta gains Eager and InputSchema fields. trackTool captures\nt.InputSchema before the pointer reaches mcp.AddTool (which internally\ncopies via tt := *t, so inferred schemas never write back onto the\noriginal pointer). A new backfillEagerSchemas queries the live server\nvia the same in-process L\n[…]\nhema instead of nil.\n\nGroundwork for the porcelain/plumbing tool-surface split (workflow\nwkweyu50g): the deferred catalog needs InputSchema on every entry for\ncog_tool_search to return usable results.",
          "is_bot": false,
          "headline": "feat(mcp): capture InputSchema on toolMeta, backfill eager schemas",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-07-01T08:37:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8d37652088f72c9329e94b227e015de11540c75f",
          "body": "chore(dispatch): decommission Ollama backend; default to LM Studio",
          "is_bot": false,
          "headline": "Merge pull request #417 from myrgic/chore/drop-ollama-backend",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T14:05:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c321093a4d9636ab8f548448a6bf0436f39ddf27",
          "body": "…d issue template ref\n\n- .cog/config/node/manifest.yaml: removed ollama observed-service block (port 11434)\n- .github/workflows/nightly-integration.yml: removed integration-ollama job (ollama/ollama\n  service container, OLLAMA_HOST env, wait-for-Ollama step); updated header comment\n- .github/ISSUE_TEMPLATE/bug_report.yml: updated provider example from\n  'ollama (gemma4:e4b)' to 'lmstudio-darkstar (gemma-4-26b)'",
          "is_bot": false,
          "headline": "chore(ci+config): remove Ollama service container, manifest entry, an…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T14:00:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "19b0a2808b0dc0983988113612958c69273b1057",
          "body": "… lmstudio-darkstar\n\n- provider_ollama.go: added decommission header; defaultOllamaModel kept for compat\n- provider_ollama_integration_test.go: removed (Ollama CI service gone)\n- router.go: applyLocalModelConfig now covers lmstudio/openai-compat types;\n  defaultProvidersConfig Ollama branch emits a \n[…]\nscription updated (LM Studio as default);\n  Model jsonschema updated (no longer says 'e4b default, local Ollama');\n  cog_patch_config patch fields list removes ollama_embed_endpoint/ollama_embed_model",
          "is_bot": false,
          "headline": "chore(providers): tombstone Ollama provider; default providers.yaml →…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T14:00:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "159ecc33f803b6cdeab43663d8c83786c32673fb",
          "body": "… backend\n\n- detectLocalLLMTarget now probes OpenAI-compat (/v1/models) first, Ollama second\n- resolvePreferredLocalModel no longer hard-codes defaultOllamaModel as a priority\n  floor; falls back to models[0] (first model the server advertises)\n- localModelHint returns empty string when LocalModel i\n[…]\nrom Ollama wire format (/api/tags + /api/chat) to OpenAI-compat\n  (/v1/models + /v1/chat/completions); legacy state-routing fallback tests work via\n  the secondary Ollama probe in detectLocalLLMTarget",
          "is_bot": false,
          "headline": "feat(dispatch): decommission Ollama as default; LM Studio is the live…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T14:00:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a0752cba4b3f90ab925e569bb7021f3b62fe008e",
          "body": "IndexWorkspace accumulated per-doc parse/index errors in indexErr and\nreturned it after a fully successful walk + commit + ref-resolve + FTS\nrebuild. A single cogdoc with malformed YAML frontmatter therefore caused\n'cogos reindex' to exit 1 even when 14,000+ other docs indexed cleanly.\n\nPer-doc fail\n[…]\nwith the exact YAML error class seen in production (mapping values\nnot allowed in this context), asserts IndexWorkspace returns nil, and\nverifies the valid sibling docs are indexed and FTS-searchable.",
          "is_bot": false,
          "headline": "fix(cli): cogos reindex tolerates per-doc parse failures (#416)",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T13:33:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "906f5f245c256d56e4199e0eaafaae39a3d672c9",
          "body": "fix(search): idempotent lazy FTS reindex — keep cog_search_memory current",
          "is_bot": false,
          "headline": "Merge pull request #415 from myrgic/fts-lazy-reindex",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T12:54:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3e1f869e6ee1d6e7abba4de2e623a084c3546e0e",
          "body": "…space\n\nThe generalized purge (DELETE FROM documents WHERE path NOT LIKE <root>/%)\nintroduced in the portability pass was unsafe on two counts: (1) it would\ndelete legitimately-indexed rows whose path falls outside the workspace root\n(conversation/session documents indexed from ~/.claude), and (2) t\n[…]\nxing is idempotent and does not require it.\nOrphan cleanup (rows whose file no longer exists) is deferred to a dedicated\nstat-based sweep. Test rewritten to assert out-of-workspace rows are preserved.",
          "is_bot": false,
          "headline": "fix(constellation): remove unsafe out-of-workspace purge in IndexWork…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T12:48:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "429a1758594988be62a54a5aeb17a467d4887329",
          "body": "…rkspace\n\nsdk/constellation/indexer.go:70 contained a literal DELETE predicate\n  WHERE path LIKE '/Users/slowbro/cog-workspace/%'\nwhich silently purged nothing on any machine other than the original author's\nand would never purge correctly if the workspace was renamed or moved.\n\nReplace with a param\n[…]\nhose absolute path falls\noutside the current workspace root — the actual portability-correct intent\nof the CRITICAL-4 purge — and uses a bound ? parameter so no literal path\nappears in the SQL source.",
          "is_bot": false,
          "headline": "fix(constellation): variabilize hardcoded stale-path purge in IndexWo…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T12:37:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f2d779679f593319af6f749b1c9a017ec6fb4bb6",
          "body": "~/.cog/config is a directory holding self-update.yaml.  The old fallback\npath in loadGlobalConfig checked only statErr2 == nil before assigning\npath = oldPath, so os.ReadFile would attempt to read a directory and crash\non any kernel that has a self-update config installed.\n\nFix:\n- oldPath branch: us\n[…]\nh: widen the fallback condition from os.IsNotExist-only to\n  also cover the case where newPath exists but is a directory, so the\n  legacy fallback is tried when the canonical file path is itself a dir",
          "is_bot": false,
          "headline": "fix(providers/all): guard IsDir in loadGlobalConfig config-path fallback",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T12:37:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "28291a46597f97a36a284c5e9eca619db1fa56d5",
          "body": "…index\n\nlazy drift-repair (d11f3a4) warns users to run `cogos reindex` when\nwidespread drift is detected (>10 drifted rows), but the command was\nmissing — the CLI exited with 'unknown command reindex'.\n\nAdd internal/engine/cli_reindex.go modeled on cli_reconcile.go:\n- own flag.NewFlagSet with --work\n[…]\n_*.go files may\n  import sdk/constellation — only the long-lived daemon boot path may not\n- register case \"reindex\": in the switch in cli.go (~:159) and add a\n  printUsage line adjacent to \"reconcile\"",
          "is_bot": false,
          "headline": "feat(cli): add `cogos reindex` command to rebuild FTS5 constellation …",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T12:36:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e6ba790468a94a07670660fddbc2aa8342409476",
          "body": "Add MemWatcher (internal/engine/mem_watcher.go) to keep FTS current for\n.cog/mem/ writes that bypass the MCP write path (direct editor saves, ingest\nCLI, CI scripts).\n\nTwo behaviours:\n\n1. Recursive-add on directory Create.  macOS kqueue (and Windows\n   ReadDirectoryChangesW) is non-recursive: a newl\n[…]\npkgFTSRepairIndexer being non-nil.  In tests and CLI paths where no\n  indexer is wired the block is a no-op.\n- Watcher goroutine is stopped via a context-cancel listener when kernelCtx\n  is cancelled.",
          "is_bot": false,
          "headline": "feat(engine): mem-watcher with recursive subdir-add on fsnotify Create",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T12:34:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4c6d2f19dec835f6d4713b1bcbe124fea4dda3bc",
          "body": "… FTS hook\n\nRemove the direct sdk/constellation import from internal/engine/mcp_stubs.go\n(package-boundary guard #2 per cogdoc_service.go:22).\n\nThe lazy drift-repair path in searchMemoryFTSDriftRepair previously called\nconstellation.Open directly.  Replace with pkgFTSRepairIndexer, a package-level\nC\n[…]\ng FTS in lockstep with the\nfile system.  WithConstellationIndexer is now called from a production path\n(MCPServer.SetConstellationIndexer) — previously the setter existed but had\nno production caller.",
          "is_bot": false,
          "headline": "fix(engine): kill sdk/constellation boundary violation; wire on-write…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T12:31:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d11f3a46bc46d6a579076e0c6b4b1c4c8e0a0aca",
          "body": "Before running the FTS5 query, sample up to 100 recently-indexed documents\nand compare their stored file_mtime to os.Stat.  For ≤10 drifted paths,\ncall constellation.IndexFile (now O(1) upsert) within a 200ms budget.\nIf drift is widespread, log once and fall through to serve current results\n(bulk repair belongs to `cogos reindex`).  No latency impact on the common\ncase (0 drifted rows in sample).",
          "is_bot": false,
          "headline": "feat(search): lazy FTS drift repair on every searchMemoryFTS call",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T12:03:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4a3af8cf185f10eb3b8045abaa690e18baf87d32",
          "body": "…n tests\n\nReplace the per-file rebuildFTS() (O(N) full table rebuild) in IndexFile\nwith upsertFTSRow(), a targeted DELETE+INSERT FROM documents WHERE id=? pair\nwrapped in a savepoint for crash-consistency.  A package-level ftsMu\nserialises all FTS mutations so a watcher-triggered IndexFile cannot\nin\n[…]\nh a CLI-driven rebuildFTS.  IndexWorkspace continues to use\nrebuildFTS after the full walk.\n\nAdd three regression tests: FTSIndexFileSearchable, FTSIndexFileIdempotent,\nand FTSIndexFileChangedContent.",
          "is_bot": false,
          "headline": "feat(constellation): incremental FTS upsert + mutex guard + regressio…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T12:02:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b21d4a96912aa0ffb1e5ec85dd47d8d1cabce616",
          "body": "…ance\n\nWave 2 — harness: provisional-binding conformance",
          "is_bot": false,
          "headline": "Merge pull request #414 from myrgic/harness/wave2-provisional-conform…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T11:11:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aeabdc5d70793478469507758ea8901aed9b0341",
          "body": null,
          "is_bot": false,
          "headline": "style(harness): gofmt changed files",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T11:07:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "96f3823151d95e6369700a05c0cafed3e458a1a9",
          "body": "…-B (ADR-031, RFC-020 subset)",
          "is_bot": false,
          "headline": "feat(harness): four-element is_error bodies for loop sentinels + gate…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T10:59:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c566316168cf19489267bcc21fb2d0978fd8a802",
          "body": "…pe reads (ADR pointer-first)",
          "is_bot": false,
          "headline": "refactor(harness): pointer-first (res=abstract) default for audit-sco…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T10:56:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "859a672897e969d8372f042e3bf98f6be21fe03c",
          "body": "…C-016)",
          "is_bot": false,
          "headline": "refactor(harness): scope catalog cleanup + task-type micro-scopes (RF…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T10:50:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "91c7311c348e8666b4c4eb38cf29a0e399ee2bff",
          "body": "…018, ADR-066)",
          "is_bot": false,
          "headline": "feat(harness): four-bundle orientation block on dispatch prompt (RFC-…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T10:46:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ef67f47a7fa235395d228aaface2fbe09518f7f4",
          "body": "…ymous fallback (RFC-identity-embedding)",
          "is_bot": false,
          "headline": "feat(harness): thread dispatch identity into inference + events, anon…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T10:44:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9438bed3ad3e5a72bad806348bb9a1b42f3ceeda",
          "body": "Wave 1 — harness: accepted-ADR conformance",
          "is_bot": false,
          "headline": "Merge pull request #413 from myrgic/harness/wave1-adr-conformance",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T10:09:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e05cffea3def9610775e650c8e330c7fbf2dbd28",
          "body": "… handling",
          "is_bot": false,
          "headline": "docs(harness): correct misleading comment on autonomic cycle sentinel…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T10:05:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "407cc86ba17b4296e793e69c8825ae27e23bee9e",
          "body": "… cog_get_index (ADR-045, ADR-066)",
          "is_bot": false,
          "headline": "refactor(harness): dedupe URI block, reconcile tool descriptions, cap…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T09:51:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fa0b97aea386ffd679ac4a5cd21b360badd625bf",
          "body": "…83, ADR-033, ADR-072)",
          "is_bot": false,
          "headline": "feat(harness): emit cycle-trace + ledger events for dispatches (ADR-0…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T09:48:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e67f25ac652ae3cd32bd8ea78691f72bc7e7ec51",
          "body": "…rrors, respond hard-break (ADR-031, ADR-052)",
          "is_bot": false,
          "headline": "fix(harness): legible loop exits — max-turns/no-progress structured e…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T09:44:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4bc157076b15de9b0baa0a75bf2d95c817f0693f",
          "body": "…ch (ADR-eigen, RFC-027)",
          "is_bot": false,
          "headline": "fix(harness): output contract + channel-token sanitization for dispat…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T09:41:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "507df4ffa1e90a24f83f5aaeecd1bf260ed67d59",
          "body": "…t-keyed RequestID (ADR-066)",
          "is_bot": false,
          "headline": "refactor(harness): make dispatch temp/max_tokens overridable + conten…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-30T09:39:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f1a5f18819d5ddf3f3a348f9304bbecab5f54138",
          "body": "* feat(embed): use OpenAI /v1/embeddings instead of Ollama-native API\n\nSwitch the two embedding clients from Ollama's native endpoints to the\nOpenAI-compatible /v1/embeddings surface, so the kernel can use LM Studio\n(or any OpenAI-compatible server) for embeddings:\n\n- internal/engine/trm_context.go \n[…]\nndpoint+model stay config-driven (OllamaEmbed* keys retained for compat).\nOllama also serves /v1/embeddings, so this works against both backends during\nthe transition.\n\n* chore: bump VERSION to 0.16.6",
          "is_bot": false,
          "headline": "feat(embed): OpenAI /v1/embeddings instead of Ollama-native API (#412)",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-27T12:49:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2ee0175df4f073182eeca4cfb36b2484872c57d7",
          "body": "Ships the reconcile-driven self-update feature (#410) so the daemon can keep\nitself current with GitHub releases. After this release, install once to\nbootstrap, then 'cogos self-update' (or auto-apply) handles subsequent updates.",
          "is_bot": false,
          "headline": "chore: bump version to 0.16.5 (#411)",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-25T10:54:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "99f264b966396b5270986213efb7f2dcb72af70c",
          "body": "…eases (#410)\n\nAdds a SelfUpdate Reconcilable provider + a 'cogos self-update' CLI subcommand\nthat keep the launchd-managed daemon current with GitHub releases, per the\nreconcile philosophy (the kernel reconciles its own version like everything\nelse).\n\nProvider (internal/providers/selfupdate): throt\n[…]\ng\n.cog/config/self-update.yaml with enabled:true (intended opt-in). Chicken-and-\negg: this code must be in a release first, so v0.16.x must be installed once to\nbootstrap, after which it self-updates.",
          "is_bot": false,
          "headline": "feat(self-update): reconcile-driven cogos self-update from GitHub rel…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-25T10:50:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bb53d8ea4e9cba3aa6f856f676ebba9907801649",
          "body": "Cuts a release of the overnight audit-remediation batch: #396-#408 (two\npath-traversal security sweeps, the worktree ledger-scan CPU fix, log/map leak\nfixes, data-race + deadlock fixes, reconcile hygiene + purity, and per-cycle\nperf reductions). Release notes auto-generate from PR titles since v0.16.3.",
          "is_bot": false,
          "headline": "chore: bump version to 0.16.4 (#409)",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-25T09:32:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "820054c4c5b3e62f91e63e79606a72f23d29e2d1",
          "body": "…-reading the corpus (#408)\n\nAudit Q1 (projection_reconciler.go:387) + Q2 (decision_lineage_reconciler.go:219).\nBoth ApplyPlan implementations re-read and re-parsed the entire nodes/decision\ncorpus and re-rendered the projection — work FetchLive + ComputePlan already did\nearlier in the same reconcil\n[…]\ne per-action logs use the count already in Details.\n\nTest: ApplyPlan writes a sentinel carried in Details verbatim (proving no\nre-derive); existing full-cycle reconciler tests still green under -race.",
          "is_bot": false,
          "headline": "perf(reconcile): carry rendered projection in ApplyPlan instead of re…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-25T09:27:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "00c9cebeba790b054e343917d22bc3e1c1c1f125",
          "body": "ServiceProvider.Health() issues a Docker Ping plus one ContainerList per declared\nservice on every call, with no caching. Health() is on hot paths — every\nPOST /v1/infer (foveated context buildHealthBlock), every autonomic tick, and\nafter every reconcile cycle — so a workspace with N docker-mode ser\n[…]\n cache. Service liveness changes are still picked\nup within the TTL and at the latest by the next ~30s reconcile cycle.\n\nTest: a fresh cache is returned without recompute; an expired cache recomputes.",
          "is_bot": false,
          "headline": "perf(service): cache ServiceProvider.Health() behind a short TTL (#407)",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-25T09:27:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9e6abf615070178f0eddb4a62e41eeea3f77f4ed",
          "body": "…chLive (#406)\n\nEvalProvider.ComputePlan called readAndClearDispatchTriggers(e.root), which\nDESTRUCTIVELY clears the eval-dispatch-triggers.json sidecar. ComputePlan is\ncontractually pure (deterministic, side-effect-free) — the reconcile daemon may\ncall it and discard the plan, and a concurrent daem\n[…]\nin the audit.)\n\nTest: the dispatch-trigger test now drives the real flow — FetchLive drains the\nsidecar into live state, ComputePlan produces the non-skip action, and the\nsidecar is confirmed cleared.",
          "is_bot": false,
          "headline": "fix(eval): make ComputePlan pure by draining dispatch triggers in Fet…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-25T09:26:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3e07dfc3b865ab219712c0d074b3f924a58e3520",
          "body": "…Config init race (#404)\n\nTwo related worktree-reconciler defects from the 2026-06-25 audit (C2 high, C3).\n\nC2 (worktree_reconciler.go:648) — perpetual Degraded after alarm acknowledgement.\nApplyPlan's health loop counted ANY action whose Details[\"classification\"] is an\nalarm type, including the Act\n[…]\nes the field race) that don't conflict with a later C1.\n\nTests: alarm-idempotent test now asserts Degraded while firing then Healthy after\nacknowledgement (C2); constructor defaults nil adapters (C3).",
          "is_bot": false,
          "headline": "fix(worktree): stop acknowledged alarms pinning Degraded; remove Load…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-25T09:26:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "843825f3da7751e4f36b580f1a2a6895e14073d1",
          "body": "… order (#405)\n\nTwo bus_session robustness fixes from the 2026-06-25 audit (A1/A2).\n\nA1 (bus_session.go:232) — saveRegistry used os.WriteFile (truncate-before-write).\nA SIGKILL/crash between truncate and write leaves registry.json empty;\nloadRegistry swallows the parse error and returns an empty reg\n[…]\nus until the next append recreated it. Move\nthe cache reset inside the create-succeeded branch; on create failure, warn and\nretain the cache.\n\nTest: saveRegistry round-trips and leaves no .tmp behind.",
          "is_bot": false,
          "headline": "fix(engine): atomic bus registry write + correct rotation cache-reset…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-24T16:12:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "da224b444f2261fa83f6588a588c784baba838ef",
          "body": "…#403)\n\nThe manual SIGTERM->SIGKILL escalation path (taken when proc.cancel is nil, i.e.\nthe foreground streaming providers) spawned a goroutine that slept an\nuninterruptible 5s. On daemon shutdown it outlived the daemon by up to that 5s,\nfiring a pointless SIGKILL at an already-reaped PID (harmless\n[…]\ncalations during shutdown\nstill fire; only goroutines still pending after teardown abort.\n\nTest: Shutdown closes shutdownCh and a repeat Shutdown does not panic (double\nclose guarded by shutdownOnce).",
          "is_bot": false,
          "headline": "fix(engine): abort procmgr SIGKILL-escalation goroutine on shutdown (…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-24T15:55:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "837ffdf1eb2df70ed02ef0b120a7cb6cdd8508f8",
          "body": "…eopen (#402)\n\nRegression in #397 found by the 2026-06-25 audit. rotateLocked() closed the\nactive handle up front, then on either failure branch (rename succeeds but the\npost-rename reopen fails on a full disk; or rename fails AND the recovery reopen\nfails) returned with w.f still pointing at that c\n[…]\nd of writing to a dead descriptor.\n\nTests: Write-after-Close self-heal, and a forced post-failed-rotation state\n(closed handle, nil w.f, size over cap) that must not panic and must persist the\nrecord.",
          "is_bot": false,
          "headline": "fix(engine): keep rotating log writer's handle valid after a failed r…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-24T15:51:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "559f87e4ea159e48c11bf5d07524b1a8b561c3b4",
          "body": "The 2026-06-24 deep audit found four caller-supplied-path sites on the loopback\nHTTP+MCP surface that #396 did not cover. All reuse the pathWithin/containedJoin\nhelpers #396 already established. All are reject-only — valid inputs are\nunaffected; only previously-exploitable inputs are now refused.\n\n-\n[…]\ntName helper and apply it to both. (LOW)\n\nTests: sector-containment on both fallback paths; validClaudeProjectName table.\nLoopback-only by default, so these are local-access hardening, not remote RCE.",
          "is_bot": false,
          "headline": "fix(security): close path-traversal holes the #396 sweep missed (#401)",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-24T15:43:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9e31bf99e1111c0d7a361d4bc891d3aaf13f4c48",
          "body": "…very (#400)\n\nTestBuildRouterRegistersMLXSupervisedType failed on any host running LM Studio\non :1234: BuildRouter live-probes well-known OpenAI-compat backends and\nregisters a reachable 'lmstudio' ahead of the configured mlx-gemma, so\nFirstLocalProvider returned 'lmstudio'. It passed in CI only bec\n[…]\nys on by default); only the test opts out so\nrouter construction no longer depends on what LLM servers are live on the host.\n\nVerified: with LM Studio live on :1234, the test now passes (was failing).",
          "is_bot": false,
          "headline": "test(router): make BuildRouter MLX test hermetic via WithoutAutoDisco…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-24T15:13:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "847e08a43c4a2a7e061869eec4542c1a555d26fe",
          "body": "…(#399)\n\nWorktreeReconciler.LoadConfig runs every ~30s reconcile cycle and calls\nFilesystemLedgerReader.ReadWorktreeEvents, which listed every\n.cog/ledger/<session>/ dir and fully read + JSON-parsed each events.jsonl to\nextract a handful of worktree.* events. On a long-lived workspace that is\nhundre\n[…]\nam so the test can count cache-miss\nparses (mirrors the existing psLookup seam).\n\nTest: cache-hit on unchanged file (no re-parse), re-parse on append, eviction\non delete, and repoRoot-keyed isolation.",
          "is_bot": false,
          "headline": "perf(worktree): cache per-session ledger scans in ReadWorktreeEvents …",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-24T14:57:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "24ceef2542c6c3c98c0d89839329981770cf2646",
          "body": "…r-cycle work (#398)\n\nReconcile-contract cluster from the codebase audit, low-risk subset (the\ncontract-semantics items — worktree re-degrade, eval ComputePlan write, MLX\nconvergence, per-cycle subprocess batching — are deferred to review-required\nfollow-ups).\n\n- reconcile.GetProvider: recursive-RLo\n[…]\nmon (mirrors WorktreeReconciler.ComputePlan).\n\nTests: registry deadlock regression (verified it hangs against the buggy code),\ncogdoc disabled-skips-walk, decision-lineage wrong-live-type error paths.",
          "is_bot": false,
          "headline": "fix(reconcile): kill GetProvider deadlock + stop disabled-pipeline pe…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-24T14:34:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "87708bc7a9175899e81e59d882186724f403b537",
          "body": "…ks (#397)\n\n* fix(engine): cap kernel log growth and stop procmgr map/goroutine leaks\n\nTwo unbounded-resource bugs found in the codebase audit:\n\n1. kernel.log.jsonl grew without bound. The slog JSON sink was opened\n   O_APPEND and left open for the process lifetime with no rotation,\n   reaching ~446\n[…]\nats read it). Add a dedicated -race regression so the loadStatus/\nsnapshot guard can't silently regress. Processes use an unstarted cmd so the\nescalation goroutine is skipped and no real signals fire.",
          "is_bot": false,
          "headline": "fix(engine): cap kernel log growth and stop procmgr map/goroutine lea…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-24T14:24:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9d52cb71615a65fb00374bb4a659a08d1b6c9b18",
          "body": "…(#396)\n\nThe kernel's HTTP/MCP surface treats callers as trusted-local, but several\nsites built filesystem paths from caller input via filepath.Join with no\ncontainment check — each an arbitrary read/write surface via \"../\" traversal\nor an absolute path:\n\n  - WriteCogDoc / cog_write_cogdoc (mcp_serv\n[…]\nt and contains\nto the workspace root (it legitimately reaches .cog/ontology, so cogRoot is the\nboundary). Tests cover traversal rejection, the absolute-containment nuance, and\nthe memory-resolver gap.",
          "is_bot": false,
          "headline": "fix(security): contain caller-supplied paths on the HTTP+MCP surface …",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-24T13:58:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c7ead4a0ad33a594fc5568cdf96f8a74975a93c3",
          "body": null,
          "is_bot": false,
          "headline": "chore: bump version to 0.16.3 (#395)",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-24T11:20:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6f21948a8b4ac58d0b27909504f7cbe60b2c063b",
          "body": "GitHub's macos-13 runners chronically sit queued for hours, and the release job\nneeds the full build matrix, so the darwin-amd64 (Intel Mac) build wedges every\nrelease — it cancelled v0.16.1 after 24h and stalled v0.16.2. Drop it; release\ntargets are arm64 Mac + linux (+ windows). The Makefile `all` target still\ncross-builds darwin-amd64 for local use; re-add the matrix entry when an\nIntel-Mac target or a reliable runner is needed.",
          "is_bot": false,
          "headline": "ci(release): drop darwin-amd64 from the release matrix (#394)",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-24T11:11:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3131cd1d1728170cf72687bf6c39591c56971e87",
          "body": "…hash (#393)\n\nFetchLive re-spawned `python3 cogblock.py parse` for every source cogdoc on\nevery reconcile cycle — one subprocess per file, ~1.5s/cycle with the current\ncorpus (per the per-phase timing from #389; the convergence self-reporter from\n#391 flagged projection-compiler as the next over-bud\n[…]\nwnstream in ComputePlan/ApplyPlan, so sharing the\npointer is safe). Cache entries for deleted/renamed sources are evicted.\n\nSole-corpus fetch_ms drops from ~1.5s toward a few ms (file reads + hashes).",
          "is_bot": false,
          "headline": "perf(projection-compiler): cache cogblock.py parse by source content …",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-24T11:09:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2ccc94826a53f5987ecf03f3c9466cb290947244",
          "body": "…392)\n\nFetchLive reloaded the entire conversation index from disk every reconcile\ncycle (idx.Load reads _meta.json + every per-session turn file) — ~950ms and\n~92% of the cycle per the per-phase timing added in #389 (cycle fetch_ms). But\nthe daemon is almost always the sole writer: UpsertSession/Del\n[…]\n cycle.\n\nBoth the reconcile daemon and the autonomic ticker drive FetchLive, so this\nremoves the dominant per-cycle cost from both loops. Sole-writer fetch_ms drops\nfrom ~950ms toward single-digit ms.",
          "is_bot": false,
          "headline": "perf(conversations): skip FetchLive reload when index is unchanged (#…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-24T03:57:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "01102bf5f9f5235389412b108fe96079c2a20123",
          "body": "The reconcile daemon recorded per-cycle cost but nothing watched the stream, so\na misbehaving provider only surfaced when an operator noticed elevated CPU and\nhand-traced the logs. Add a convergence tracker that flags two clean signals and\nemits a WARN (de-duped) plus a queryable snapshot:\n\n  - cost\n[…]\n behaviour (flagged / not-flagged), not just code\npaths — see convergence_tracker_test.go, which asserts the real ~950ms\nconversations regression would be flagged and a fast healthy provider never is.",
          "is_bot": false,
          "headline": "feat(reconcile): self-report per-provider reconcile anomalies (#391)",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-24T03:21:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ff5364f54b76d903362cebdf4b47b80cc9cb6d06",
          "body": "…ssions (#387)\" (#390)\n\nThis reverts commit ecdc366d746579999f0417b13db7bd9004d9cd33.",
          "is_bot": false,
          "headline": "Revert \"perf(conversations): incremental append-aware parse for CC se…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-24T03:21:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0f1a78272b82389604af165d0ff17d8e66735454",
          "body": "The reconcile daemon recorded only the opaque cycle total (cycle.duration_ms),\nso a slow provider cycle could not be attributed to a phase without attaching a\nprofiler. Time each phase (LoadConfig, FetchLive, LoadState, ComputePlan,\nApplyPlan, BuildState+WriteState) and emit the breakdown both in th\n[…]\ntelemetry alone, without attaching a profiler.\n\nThis immediately surfaced that the conversations provider spends ~92% of its\n~1s cycle in FetchLive (a full index reload from disk), not in parse/apply.",
          "is_bot": false,
          "headline": "feat(reconcile): per-phase timing in the reconcile cycle (#389)",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-24T03:09:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ecdc366d746579999f0417b13db7bd9004d9cd33",
          "body": "…#387)\n\nThe Conversations Observatory reconcile cycle never converged: every cycle\nre-read and re-parsed each growing Claude Code session JSONL from byte 0.\nA live session whose mtime/size changes each cycle forever triggered\nActionUpdate -> full ParseSession -> UpsertSession -> drift again, holding\n[…]\nce regression\nguard; full-reparse fallback on rewrite; and an end-to-end reconcile that\nasserts an append yields an is_append_only update and a no-change cycle\nconverges to zero create/update actions.",
          "is_bot": false,
          "headline": "perf(conversations): incremental append-aware parse for CC sessions (…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-24T02:13:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1823a2db614b7b2c6872ed5f1894bddcaad64a77",
          "body": "…(#388)\n\nIn the daemon binary LoadRegistry is intentionally nil — it is wired only\nthrough the cog CLI DI seams — so the component provider is inert: LoadConfig\nreturns nil and the reconcile cycle reports \"in sync\" with nothing to observe.\nHealth(), however, returned Degraded/Unknown for that same n\n[…]\nw mirrors the other nil-handling paths (LoadConfig,\nFetchLive, ComputePlan) and returns Synced/Healthy when LoadRegistry is nil.\n\nAdds a test asserting the inert nil-LoadRegistry path reports Healthy.",
          "is_bot": false,
          "headline": "fix(component): report Healthy when LoadRegistry is unwired (daemon) …",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-24T02:13:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "94c5031a7d82de1320f2cbf93d7bfd6adead7edd",
          "body": "…ts (#386)\n\nUnsent composer drafts captured by the claude-ai-web observer carry role\n\"user-draft\", which the ingest schema did not recognize. Every reconcile\ncycle re-rejected all of them (one log line per record) and held the\nconversations provider permanently Degraded, so it never reached a\nconver\n[…]\nxisting convergence-safe terminal\n(mirrors the unmapped-component path), so the source becomes fully\naccounted and the loop stops while the drafts are preserved, not dropped.\n\nBumps version to 0.16.2.",
          "is_bot": false,
          "headline": "fix(conversations): recognize user-draft role; quarantine unsent draf…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-24T00:40:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9d73ff42f8a22dc0e13ed62f19f21451b9154528",
          "body": "…nged sources\n\nStop the per-cycle full-corpus coverage re-parse in the conversations reconcile: cache per-source coverage, serve unchanged (ActionSkip) sources from cache, recompute only on create/update, cold-fill once after restart, prune removed sources. Eliminates a ~3-core CPU sink. Verified with build/vet/race tests + 3-lens adversarial review.",
          "is_bot": false,
          "headline": "fix(conversations): cache per-source coverage; skip re-parse on uncha…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-17T01:33:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "229a3d39d38efcc2ba5201bd884ac96f1b750e37",
          "body": null,
          "is_bot": false,
          "headline": "chore: bump version to 0.16.1",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-16T20:25:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ebb2a15f45c7e5cc2f98ddfafa0d816a7ee60d3d",
          "body": "Side-effect-free kernel-boundary admission check (IsKnownModel + AvailableModelIDs): handleChat rejects an unknown non-empty model id with HTTP 400 naming the model + available menu, instead of forwarding to the default provider and emitting an opaque 500-wrapped upstream 404.",
          "is_bot": false,
          "headline": "fix(engine): reject unknown model ids at kernel boundary with 400",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-16T20:24:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c1566ae21263abd239fac030050d5b0be898ffd1",
          "body": "Scrub private cog:// slugs, hardcoded user paths, and a resolvable private RFC path from public docs; gitignore runtime/private spill dirs (.cog/blobs, .cog/mem/episodic, .cog/mem/working, .hermes). Docs + .gitignore only; no code change.",
          "is_bot": false,
          "headline": "chore(docs): scrub residual private refs and ignore runtime spill",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-16T20:18:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e6e0d1f205299f220bd7bc8563afb98ebfe2be80",
          "body": "…ls have working FTS5 search (#381)\n\n* fix(release): build with CGO_ENABLED=1 + -tags fts5 so released kernels have working FTS5 search\n\nThe release workflow built every artifact with CGO_ENABLED=0 and no -tags\nfts5. The kernel reaches sqlite's FTS5 engine through mattn/go-sqlite3, a\nCGO binding tha\n[…]\n=0 / missing -tags fts5\nregression — which shipped silently in v0.16.0 — from recurring: the\nrelease fails loudly if the build path drifts away from the Makefile's\nBUILD_TAGS=fts5 + host-CGO contract.",
          "is_bot": false,
          "headline": "fix(release): build with CGO_ENABLED=1 + -tags fts5 so released kerne…",
          "author_name": "Chaz Dinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-15T12:47:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "462fbfbf09ca78b71895548686e7981bd17d61f5",
          "body": "* docs(adr): flatten yaml-cog-block frontmatter and scrub private refs in ADR-100/101\n\nADR-100 and ADR-101 used a nonstandard nested cog: YAML block instead of\nflat frontmatter. Flatten to standard flat YAML. In the same pass, replace\nall cog:// private-corpus URIs in the refs fields:\n- ADR-091 and \n[…]\nvate internal research corpus name) in §1b and Discussion log\n- Replace RFC-025 body reference in §4 Composition with description\n- Replace private memory-file slugs in §8 Provenance with descriptions",
          "is_bot": false,
          "headline": "docs: remove internal references from public ADRs/RFCs (#379)",
          "author_name": "cdinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-11T23:53:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "13c0368546e167c6ae13af168f5812b30eee0f7e",
          "body": "Release content: conversations observatory ingest surface v0.1 (#369),\nquery-aware URI resolver per ratified RFC (#370), MCP tool-output byte\ncaps (#371), e2e MCP transport probe (#372), daemon wiring test +\nproviders/all extraction (#374), chat 501 fix (#376), nightly\nintegration workflow (#377), ontology-as-class enforcement (#375).",
          "is_bot": false,
          "headline": "chore: bump version to 0.16.0 (#378)",
          "author_name": "cdinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-10T21:19:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e084b372f4ec8ee7b0cacf16fb1598fd5dfc4b17",
          "body": "…uarantine, coverage metric (v0.2 groundwork) (#375)\n\n* feat(conversations): add ontology loader, quarantine writer, coverage tracker (v0.2 data layer)\n\nIntroduces the four data-layer types that back ontology-as-class enforcement:\n\n- ontology.go: ParseL1Ontology (L0 grammar validation), LoadOntology\n[…]\nwo cycles,\nhermes-darkstar degenerate=14690 (baseline 14690), hermes-cog\ndegenerate=1857 (baseline 1857), counts stable across cycles.\n\n* test: t.Fatal on nil LoadedOntology guard (staticcheck SA5011)",
          "is_bot": false,
          "headline": "feat(conversations): ontology-as-class enforcement — load L0/L1/L2, q…",
          "author_name": "cdinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-10T20:17:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0b7a7dd1926ed26a8c0f77253ddaa6548de71637",
          "body": "Job 1 runs the self-contained -tags integration suites (httptest/tempdir\nbased); job 2 attempts the Ollama-dependent set, clearly labeled and\ncontinue-on-error. No || true on enforced jobs. Re-verified on current\nmain after fix(engine) #376 unblocked TestIntegrationFullLifecycle.\nSupersedes #373 (branch history unmergeable after squash cascade).",
          "is_bot": false,
          "headline": "ci(nightly): run the dormant integration-tagged test suites (#377)",
          "author_name": "cdinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-10T20:09:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "25185470009346b8e5b82cbaf352b86074e91f02",
          "body": "…nfigured (#376)\n\nMoves the s.router == nil guard to the top of handleChat, ahead of the\nio.ReadAll / json.Unmarshal calls. Previously a nil or empty request body\n(e.g. the integration test's bare POST) would hit the JSON parser first and\nreturn 400 before reaching the 501 branch — breaking\nTestIntegrationFullLifecycle/chat_returns_501. The duplicate nil-check lower\nin the function is removed; behavior for the router-present path is unchanged.",
          "is_bot": false,
          "headline": "fix(engine): return 501 before parsing chat body when no router is co…",
          "author_name": "cdinkle",
          "author_login": "chazmaniandinkle",
          "committed_at": "2026-06-10T20:03:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 38,
      "commits_last_year": 810,
      "latest_release_at": "2026-07-17T13:43:00Z",
      "latest_release_tag": "v0.16.20",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 21,
      "days_since_latest_release": 6,
      "mean_days_between_releases": 1.7
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 100,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/myrgic/cogos",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/myrgic/cogos",
          "is_deprecated": false,
          "latest_version": "v0.16.20",
          "repository_url": "https://github.com/myrgic/cogos",
          "versions_count": 40,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-17T13:34:45Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 6
        }
      ]
    },
    "popularity": {
      "forks": 1,
      "stars": 2,
      "watchers": 0,
      "fork_history": {
        "days": [
          {
            "date": "2026-04-06",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 1,
        "total_forks": 1
      },
      "star_history": null,
      "open_issues_and_prs": 39
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": true,
      "bootstrap_files": [
        "Makefile"
      ],
      "api_schema_files": [
        "bep_proto/bep.proto"
      ],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "envspec/go.mod",
        "go.mod",
        "harness/go.mod",
        "pkg/bep/go.mod",
        "pkg/cogblock/go.mod",
        "pkg/cogfield/go.mod",
        "pkg/coordination/go.mod",
        "pkg/modality/go.mod",
        "pkg/reconcile/go.mod",
        "pkg/substrate/go.mod",
        "pkg/uri/go.mod",
        "sdk/go.mod"
      ],
      "largest_source_bytes": 138356,
      "source_files_sampled": 697,
      "oversized_source_files": 4,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "envspec/go.mod",
        "go.mod",
        "harness/go.mod",
        "sdk/go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go"
      ],
      "dependencies": [
        {
          "name": "github.com/charmbracelet/bubbles",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.21.0"
        },
        {
          "name": "github.com/charmbracelet/bubbletea",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.3.10"
        },
        {
          "name": "github.com/charmbracelet/lipgloss",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.1.0"
        },
        {
          "name": "github.com/coder/acp-go-sdk",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.13.0"
        },
        {
          "name": "github.com/coder/websocket",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.8.14"
        },
        {
          "name": "github.com/fsnotify/fsnotify",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.7.0"
        },
        {
          "name": "github.com/go-git/go-git/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.16.4"
        },
        {
          "name": "github.com/google/uuid",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.6.0"
        },
        {
          "name": "github.com/hashicorp/hcl/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.24.0"
        },
        {
          "name": "github.com/mattn/go-sqlite3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.14.24"
        },
        {
          "name": "github.com/modelcontextprotocol/go-sdk",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.5.0"
        },
        {
          "name": "github.com/myrgic/cogos/envspec",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0"
        },
        {
          "name": "github.com/myrgic/cogos/harness",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0"
        },
        {
          "name": "github.com/myrgic/cogos/pkg/cogblock",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-00010101000000-000000000000"
        },
        {
          "name": "github.com/myrgic/cogos/pkg/cogfield",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0"
        },
        {
          "name": "github.com/myrgic/cogos/pkg/coordination",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-00010101000000-000000000000"
        },
        {
          "name": "github.com/myrgic/cogos/pkg/modality",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-00010101000000-000000000000"
        },
        {
          "name": "github.com/myrgic/cogos/pkg/reconcile",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-00010101000000-000000000000"
        },
        {
          "name": "github.com/myrgic/cogos/sdk",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0"
        },
        {
          "name": "github.com/opencontainers/go-digest",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.0.0"
        },
        {
          "name": "github.com/opencontainers/image-spec",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.1.1"
        },
        {
          "name": "github.com/santhosh-tekuri/jsonschema/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.3.1"
        },
        {
          "name": "github.com/zclconf/go-cty",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.17.0"
        },
        {
          "name": "go.opentelemetry.io/otel",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.43.0"
        },
        {
          "name": "go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.43.0"
        },
        {
          "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.40.0"
        },
        {
          "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.43.0"
        },
        {
          "name": "go.opentelemetry.io/otel/metric",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.43.0"
        },
        {
          "name": "go.opentelemetry.io/otel/sdk",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.43.0"
        },
        {
          "name": "go.opentelemetry.io/otel/sdk/metric",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.43.0"
        },
        {
          "name": "go.opentelemetry.io/otel/trace",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.43.0"
        },
        {
          "name": "golang.org/x/mod",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.37.0"
        },
        {
          "name": "golang.org/x/net",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.54.0"
        },
        {
          "name": "golang.org/x/sys",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.44.0"
        },
        {
          "name": "google.golang.org/protobuf",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.36.11"
        },
        {
          "name": "gopkg.in/yaml.v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.0.1"
        },
        {
          "name": "oras.land/oras-go/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.6.0"
        },
        {
          "name": "go.opentelemetry.io/otel",
          "manifest": "harness/go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.43.0"
        },
        {
          "name": "go.opentelemetry.io/otel/trace",
          "manifest": "harness/go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.43.0"
        },
        {
          "name": "gopkg.in/yaml.v3",
          "manifest": "harness/go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.0.1"
        },
        {
          "name": "github.com/coder/websocket",
          "manifest": "sdk/go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.8.14"
        },
        {
          "name": "github.com/fsnotify/fsnotify",
          "manifest": "sdk/go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.7.0"
        },
        {
          "name": "github.com/mattn/go-sqlite3",
          "manifest": "sdk/go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.14.24"
        },
        {
          "name": "gopkg.in/yaml.v3",
          "manifest": "sdk/go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.0.1"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 334,
        "open_issues": 39,
        "closed_ratio": 0.702,
        "closed_issues": 92,
        "closed_unmerged_prs": 8
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "chazmaniandinkle",
          "commits": 611,
          "avatar_url": "https://avatars.githubusercontent.com/u/357329?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "nightly-integration.yml",
        "pr-review.yml",
        "release.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        ".golangci.yml"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 9,
            "reason": "binaries present in source code",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": null,
            "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 7,
            "reason": "Found 22/30 approved changesets -- score normalized to 7",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 4,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 1,
            "reason": "1 out of the last 5 releases have a total of 1 signed artifacts.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "40 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "7ebe6461c7b0d381e6b90f85dbc47b9f1943bb68",
        "ran_at": "2026-07-23T17:18:20Z",
        "aggregate_score": 4,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-23T11:16:28Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-22T23:46:54Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 98,
          "created_at": "2026-04-30T16:59:54Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 101,
          "created_at": "2026-04-30T17:01:09Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 105,
          "created_at": "2026-04-30T18:29:18Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 205,
          "created_at": "2026-05-06T02:33:17Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 206,
          "created_at": "2026-05-06T02:33:27Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 207,
          "created_at": "2026-05-06T02:33:36Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 208,
          "created_at": "2026-05-06T02:34:20Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 274,
          "created_at": "2026-05-17T16:24:22Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 275,
          "created_at": "2026-05-17T16:24:29Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 276,
          "created_at": "2026-05-17T16:24:38Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 301,
          "created_at": "2026-05-19T16:41:07Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 302,
          "created_at": "2026-05-19T18:00:52Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 310,
          "created_at": "2026-05-20T22:56:18Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 321,
          "created_at": "2026-05-26T00:28:25Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 322,
          "created_at": "2026-05-26T00:29:04Z",
          "last_comment_at": "2026-05-26T01:15:26Z",
          "last_comment_author": "chazmaniandinkle"
        },
        {
          "number": 330,
          "created_at": "2026-05-26T01:46:07Z",
          "last_comment_at": "2026-05-26T03:10:16Z",
          "last_comment_author": "chazmaniandinkle"
        },
        {
          "number": 340,
          "created_at": "2026-05-27T11:52:40Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 383,
          "created_at": "2026-06-17T01:31:50Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 384,
          "created_at": "2026-06-17T01:33:48Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 385,
          "created_at": "2026-06-17T01:33:49Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/myrgic/cogos",
    "host": "github.com",
    "name": "cogos",
    "owner": "myrgic"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 61,
      "inputs": {
        "security": 40,
        "vitality": 83,
        "community": 43,
        "governance": 54,
        "engineering": 80
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 83,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 78,
            "inputs": {
              "commits_last_year": 810,
              "human_commit_share": 1,
              "days_since_last_push": 0,
              "active_weeks_last_year": 21
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "21/52 weeks with commits",
                "points": 14.5,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 21
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "810 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 810
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 91,
            "inputs": {
              "releases_count": 38,
              "latest_release_tag": "v0.16.20",
              "releases_from_tags": false,
              "days_since_latest_release": 6,
              "mean_days_between_releases": 1.7
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "38 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 38
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 6 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~1.7 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 1.7
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "1 out of the last 5 releases have a total of 1 signed artifacts.",
                "points": 1,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 43,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 1,
              "stars": 2,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "2 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "1 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 54,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 81,
            "inputs": {
              "merged_prs": 334,
              "open_issues": 39,
              "closed_issues": 92,
              "issue_closed_ratio": 0.702,
              "closed_unmerged_prs": 8
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "70% of issues closed",
                "points": 32.8,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 70
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "334/342 decided PRs merged",
                "points": 37.4,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 334,
                      "decided": 342
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 22/30 approved changesets -- score normalized to 7",
                "points": 10.5,
                "status": "partial",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 42,
            "inputs": {
              "followers": 1,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "myrgic",
              "public_repos": 18,
              "account_age_days": 107
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "1 followers of myrgic",
                "points": 2.2,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 1,
                      "login": "myrgic"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "18 public repos, account ~0 yr old",
                "points": 9.9,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 18
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/myrgic/cogos"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 6
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 6 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "40 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 40
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 80,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "4 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": ".golangci.yml",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yml"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "topics": [
                "ai-agents",
                "claude-code",
                "context-assembly",
                "golang",
                "local-first",
                "mcp"
              ],
              "has_wiki": false,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "6 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 6
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 40,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Branch-Protection, Packaging. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "branch_protection",
                    "packaging"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 40,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 4
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "binaries present in source code",
                "points": 6.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 22/30 approved changesets -- score normalized to 7",
                "points": 5.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 2,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "1 out of the last 5 releases have a total of 1 signed artifacts.",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "40 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 1
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 65,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "100 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 100,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 72,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [
                "Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "envspec/go.mod",
                "go.mod",
                "harness/go.mod",
                "pkg/bep/go.mod",
                "pkg/cogblock/go.mod",
                "pkg/cogfield/go.mod",
                "pkg/coordination/go.mod",
                "pkg/modality/go.mod",
                "pkg/reconcile/go.mod",
                "pkg/substrate/go.mod",
                "pkg/uri/go.mod",
                "sdk/go.mod"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": ".golangci.yml",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yml"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 138356,
              "source_files_sampled": 697,
              "oversized_source_files": 4
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "4/697 source files over 60KB",
                "points": 54.7,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 697,
                      "oversized": 4
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "moderate",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "example_dirs": [],
              "has_mcp_signal": true,
              "api_schema_files": [
                "bep_proto/bep.proto"
              ]
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": "bep_proto/bep.proto",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "bep_proto/bep.proto"
                    }
                  }
                ],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-23T17:18:42.764479Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/m/myrgic/cogos.svg",
  "full_name": "myrgic/cogos",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsGo.