Public record
Software health reportschema 0.27.0 · metrics 1.13.0 · 2026-07-26 08:16 UTC

optave / ops-codegraph-tool

Code intelligence CLI — function-level dependency graph across 34 languages, 34-tool MCP server for AI agents, complexity metrics, architecture boundary enforcement, CI quality gates, git diff impact with co-change analysis, hybrid semantic search. Fully local, zero API keys required.

TypeScript · RustApache-2.0★ 81 stars⑂ 17 forkssince Feb 2026View on GitHub ↗

optave/ops-codegraph-tool holds a health index of 67 out of 100, placing it in the Moderate band. It scores highest on Vitality (84/100) and lowest on Security (46/100). It was last updated today. A single contributor accounts for most of its recent work.

67
overall / 100
Moderate

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

67
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

OptaveOrganization
5 followers2 public repossince Jan 2023

This repository is backed by an organization — shared, accountable stewardship that can outlive any single maintainer.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publishTags
npm@optave/codegraph3.16.02,784546 days agocodegraphdependency-graphcode-analysistree-sitterstatic-analysiscall-graphimpact-analysismcp

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

84Good · 22% of overall
How it's scored
36/36Push recency — last push 0 days ago
15.9/36Commit cadence — 23/52 weeks with commits
18/18Commit volume — 1,891 commits in the last year
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year1,891
human_commit_share0.85
days_since_last_push0
active_weeks_last_year23
How it's scored
27/27Ships releases — 53 releases published
36/36Release recency — latest release 5 days ago
27/27Release cadence — a release every ~5.8 days
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Inputs used
releases_count53
latest_release_tagdev-v3.16.1-dev.15
releases_from_tagsno
days_since_latest_release5
mean_days_between_releases5.8

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

63Moderate · 18% of overall
How it's scored
30.9/60Stars — 81 stars
10/25Forks — 17 forks
0/15Watchers — 1 watchers
Inputs used
forks17
stars81
watchers1
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

Community health

92Excellent
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (Apache-2.0)
18/18CONTRIBUTING guide
13.5/13.5Code of conduct
0/7.2Issue template
6.3/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingyes
has_issue_templateno
has_code_of_conductyes
has_pull_request_templateyes
How it's scored
45.9/80Monthly downloads — 2,784 downloads/month across npm
0/20Registry dependents — not reported by this ecosystem
Inputs used
packages@optave/codegraph
dependents
ecosystemsnpm
total_downloads
monthly_downloads2,784
Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

54Moderate · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
0/22.5Commit distribution — top contributor authored 100% of commits
4.1/13.5Contributor breadth — 3 contributors
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Inputs used
bus_factor1
contributors_sampled3
top_contributor_share0.999
How it's scored
39.2/46.8Issue resolution — 84% of issues closed
35.1/38.3PR acceptance — 1,375/1,498 decided PRs merged
0/15OpenSSF Scorecard: Code-Review — Found 0/16 approved changesets -- score normalized to 0
Inputs used
merged_prs1,375
open_issues105
closed_issues546
issue_closed_ratio0.839
closed_unmerged_prs123
How it's scored
30/30Ownership backing — organization-owned
0/20Verified domain
5.6/25Owner reach — 5 followers of optave
10.5/25Track record — 2 public repos, account ~3 yr old
Inputs used
followers5
owner_typeOrganization
is_verified
owner_loginoptave
public_repos2
account_age_days1,275
How it's scored
25/25Published & resolvable — 1 package(s) on npm
35/35Publish recency — latest publish 6 days ago
20/20Version history — 54 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packages@optave/codegraph
ecosystemsnpm
any_deprecatedno
min_days_since_publish6

Engineering Quality

Are baseline engineering and documentation practices in place?

84Good · 20% of overall
How it's scored
24/24CI workflows — 13 workflow(s)
24/24Tests present
16/16Linter config — biome.json
0/9.6Pre-commit hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configyes
has_precommit_configno

Documentation

85Excellent
How it's scored
30/30README
25/25Documentation directory
0/15Documentation / homepage site
10/10Repository description
10/10Topics — 16 topics
10/10Wiki
Inputs used
topicsai-agents, cli, code-analysis, dependency-graph, impact-analysis, incremental-builds, mcp-server, semantic-search, sqlite, static-analysis, tree-sitter, architecture, ci-cd, code-quality, codeowners, complexity-metrics
has_wikiyes
homepage
has_readmeyes
has_docs_diryes
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

46At risk · 16% of overall
How it's scored
6.8/7.5Binary-Artifacts — binaries present in source code
3.8/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/16 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
0/10Dangerous-Workflow — dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — no data
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 16 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate3.5
Excluded from scoring (no data or not applicable): packaging. Remaining weights renormalized.
How it's scored
35/35Direct dependencies free of known advisories — no direct dependency carries a known advisory
13.2/25Indirect dependencies free of known advisories — 1 affected: @hono/node-server 1.19.15 (moderate 5.9)
40/40No advisories left outstanding — no advisory has been public longer than 90 days
Inputs used
sourceosv
advisories1
affected_packages1
assessed_packages138
unassessed_packages0
affected_by_severitymoderate 1
direct_affected_packages0
Matched the npm:@optave/codegraph@3.16.0 runtime dependency closure — what installing the published package pulls in — 138 packages. Reachability is not analyzed.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

78Good · 0% of overall
How it's scored
45/45Agent instructions — CLAUDE.md
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 85 of 85 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share1
agent_instruction_filesCLAUDE.md
agent_instruction_max_bytes21,129
How it's scored
18/18One-command bootstrap — tests/benchmarks/resolution/fixtures/java/Makefile
22/22Automated tests
11/11Lint / format config — biome.json
11/11Static type checking — tsconfig.json
10/10Reproducible environment — lockfile
0/10Demonstrated agent practice — no agent-authored commits among the last 100
8/8Automated maintenance — 13 of the last 100 commits are automated dependency updates
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Inputs used
has_nixno
has_testsyes
lockfilesCargo.lock, package-lock.json
has_dockerfileno
typed_languageyes
bootstrap_filestests/benchmarks/resolution/fixtures/java/Makefile
has_devcontainerno
has_linter_configyes
typecheck_configstsconfig.json
agent_commit_share0
toolchain_manifestsCargo.toml, crates/codegraph-core/Cargo.toml
dependency_bot_commit_share0.13
How it's scored
45/45Type-checkable code — TypeScript (statically typed)
54.3/55Manageable file sizes — 13/990 source files over 60KB
Inputs used
primary_languageTypeScript
largest_source_bytes329,545
source_files_sampled990
oversized_source_files13
How it's scored
0/40API schema (OpenAPI/GraphQL/proto)
0/20MCP server
40/40Runnable examples — examples
Inputs used
example_dirsexamples
has_mcp_signalno
api_schema_files

Key facts

81GitHub stars
3contributors
1,891commits, last 12 months
0days since last push
53releases
1bus factor
105open issues
crates.io, npmpackage ecosystems

Data collection warnings

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

More detail

Star and fork history 0 ★ / 17 ⇿
0Stars
17Forks
47Releases

When each star and fork was added, collected from GitHub and bucketed by day. Cumulative growth sits directly above the daily additions it is made of, so the two read against each other: steady organic accretion looks nothing like an abrupt, short-lived burst. Where that difference is measurable, it is reported as growth authenticity.

0481216201722026-022026-052026-07
Major 2Minor 23Patch 22
OpenSSF Scorecard 3.5 / 10
3.5aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-26 08:16 UTC

9Binary-Artifactsbinaries present in source code
5Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/16 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
0Dangerous-Workflowdangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
n/aPackagingpackaging workflow not detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
10Security-Policysecurity policy file detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities16 existing vulnerabilities detected
Direct dependencies 3
RegistryPackageVersion constraintManifest
npmbetter-sqlite3^12.6.2package.json
npmcommander^15.0.0package.json
npmweb-tree-sitter^0.26.5package.json
All dependencies not collected

The resolved dependency set could not be collected for this report: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Dependency advisories 1

Installing npm:@optave/codegraph@3.16.0 pulls in 138 packages, direct and transitive: 1 carry known advisories, of which 0 are direct dependencies.

PackageVersionRelationSeverityAdvisoriesFixed in
@hono/node-server1.19.15indirectmoderate12.0.5

An advisory means the version recorded in the dependency graph falls inside an advisory’s affected range. Reachability is not analysed, and the graph includes development and test pins — a finding may concern tooling rather than shipped software.

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [
        "ai-agents",
        "cli",
        "code-analysis",
        "dependency-graph",
        "impact-analysis",
        "incremental-builds",
        "mcp-server",
        "semantic-search",
        "sqlite",
        "static-analysis",
        "tree-sitter",
        "architecture",
        "ci-cd",
        "code-quality",
        "codeowners",
        "complexity-metrics"
      ],
      "is_fork": false,
      "size_kb": 19096,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "C": 2490,
        "R": 4835,
        "C#": 2643,
        "F#": 1731,
        "Go": 3557,
        "C++": 2424,
        "HCL": 1079,
        "Lua": 6570,
        "PHP": 6153,
        "Zig": 3176,
        "Cuda": 2781,
        "Dart": 2258,
        "Java": 3787,
        "Ruby": 3336,
        "Rust": 2041838,
        "Gleam": 1933,
        "Julia": 6121,
        "OCaml": 1500,
        "Scala": 2084,
        "Shell": 134190,
        "Swift": 2203,
        "Elixir": 7439,
        "Erlang": 5707,
        "Groovy": 2413,
        "Kotlin": 2949,
        "Python": 5672,
        "Clojure": 5186,
        "Haskell": 2429,
        "Verilog": 1858,
        "Makefile": 200,
        "Solidity": 2859,
        "JavaScript": 322894,
        "TypeScript": 5563684,
        "Objective-C": 3050
      },
      "pushed_at": "2026-07-25T10:23:14Z",
      "created_at": "2026-02-21T09:31:55Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-21T10:40:43Z",
      "description": "Code intelligence CLI — function-level dependency graph across 34 languages, 34-tool MCP server for AI agents, complexity metrics, architecture boundary enforcement, CI quality gates, git diff impact with co-change analysis, hybrid semantic search. Fully local, zero API keys required.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript",
        "Rust"
      ]
    },
    "owner": {
      "blog": "optave.com",
      "name": "Optave",
      "type": "Organization",
      "login": "optave",
      "company": null,
      "location": null,
      "followers": 5,
      "avatar_url": "https://avatars.githubusercontent.com/u/123786295?v=4",
      "created_at": "2023-01-28T01:38:51Z",
      "is_verified": null,
      "public_repos": 2,
      "account_age_days": 1275
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "dev-v3.16.1-dev.15",
          "kind": "other",
          "published_at": "2026-07-21T06:31:10Z"
        },
        {
          "tag": "dev-v3.16.1-dev.10",
          "kind": "other",
          "published_at": "2026-07-20T06:35:27Z"
        },
        {
          "tag": "dev-v3.16.0-dev.0",
          "kind": "other",
          "published_at": "2026-07-18T06:17:51Z"
        },
        {
          "tag": "v3.16.0",
          "kind": "minor",
          "published_at": "2026-07-17T09:02:11Z"
        },
        {
          "tag": "v3.15.0",
          "kind": "minor",
          "published_at": "2026-06-22T03:53:42Z"
        },
        {
          "tag": "v3.14.0",
          "kind": "minor",
          "published_at": "2026-06-20T00:11:02Z"
        },
        {
          "tag": "v3.13.0",
          "kind": "minor",
          "published_at": "2026-06-17T05:43:48Z"
        },
        {
          "tag": "v3.12.0",
          "kind": "minor",
          "published_at": "2026-06-10T07:37:15Z"
        },
        {
          "tag": "v3.11.2",
          "kind": "patch",
          "published_at": "2026-06-01T21:27:07Z"
        },
        {
          "tag": "v3.11.1",
          "kind": "patch",
          "published_at": "2026-05-30T02:31:20Z"
        },
        {
          "tag": "v3.11.0",
          "kind": "minor",
          "published_at": "2026-05-25T22:55:34Z"
        },
        {
          "tag": "v3.10.0",
          "kind": "minor",
          "published_at": "2026-05-01T22:57:51Z"
        },
        {
          "tag": "v3.9.6",
          "kind": "patch",
          "published_at": "2026-04-30T06:12:47Z"
        },
        {
          "tag": "v3.9.5",
          "kind": "patch",
          "published_at": "2026-04-23T22:32:30Z"
        },
        {
          "tag": "v3.9.4",
          "kind": "patch",
          "published_at": "2026-04-17T22:11:03Z"
        },
        {
          "tag": "v3.9.3",
          "kind": "patch",
          "published_at": "2026-04-13T06:27:02Z"
        },
        {
          "tag": "v3.9.2",
          "kind": "patch",
          "published_at": "2026-04-07T06:22:42Z"
        },
        {
          "tag": "v3.9.1",
          "kind": "patch",
          "published_at": "2026-04-06T06:14:36Z"
        },
        {
          "tag": "v3.9.0",
          "kind": "minor",
          "published_at": "2026-04-04T09:52:13Z"
        },
        {
          "tag": "v3.8.1",
          "kind": "patch",
          "published_at": "2026-04-03T07:45:10Z"
        },
        {
          "tag": "v3.8.0",
          "kind": "minor",
          "published_at": "2026-04-02T05:02:46Z"
        },
        {
          "tag": "v3.7.0",
          "kind": "minor",
          "published_at": "2026-03-31T23:49:49Z"
        },
        {
          "tag": "v3.6.0",
          "kind": "minor",
          "published_at": "2026-03-30T16:02:09Z"
        },
        {
          "tag": "v3.5.0",
          "kind": "minor",
          "published_at": "2026-03-30T04:12:57Z"
        },
        {
          "tag": "v3.4.1",
          "kind": "patch",
          "published_at": "2026-03-27T03:25:03Z"
        },
        {
          "tag": "v3.4.0",
          "kind": "minor",
          "published_at": "2026-03-26T03:19:21Z"
        },
        {
          "tag": "v3.3.1",
          "kind": "patch",
          "published_at": "2026-03-20T07:51:06Z"
        },
        {
          "tag": "v3.3.0",
          "kind": "minor",
          "published_at": "2026-03-19T07:10:13Z"
        },
        {
          "tag": "v3.2.0",
          "kind": "minor",
          "published_at": "2026-03-17T14:08:50Z"
        },
        {
          "tag": "v3.1.5",
          "kind": "patch",
          "published_at": "2026-03-17T02:09:12Z"
        },
        {
          "tag": "v3.1.4",
          "kind": "patch",
          "published_at": "2026-03-16T06:45:55Z"
        },
        {
          "tag": "v3.1.3",
          "kind": "patch",
          "published_at": "2026-03-12T02:05:51Z"
        },
        {
          "tag": "v3.1.2",
          "kind": "patch",
          "published_at": "2026-03-11T07:22:42Z"
        },
        {
          "tag": "v3.1.1",
          "kind": "patch",
          "published_at": "2026-03-09T06:09:09Z"
        },
        {
          "tag": "v3.1.0",
          "kind": "minor",
          "published_at": "2026-03-08T09:44:30Z"
        },
        {
          "tag": "v3.0.4",
          "kind": "patch",
          "published_at": "2026-03-06T07:10:05Z"
        },
        {
          "tag": "v3.0.3",
          "kind": "patch",
          "published_at": "2026-03-04T08:28:32Z"
        },
        {
          "tag": "v3.0.2",
          "kind": "patch",
          "published_at": "2026-03-04T07:09:48Z"
        },
        {
          "tag": "v3.0.1",
          "kind": "patch",
          "published_at": "2026-03-04T04:52:18Z"
        },
        {
          "tag": "v3.0.0",
          "kind": "major",
          "published_at": "2026-03-03T10:07:03Z"
        },
        {
          "tag": "v2.6.0",
          "kind": "minor",
          "published_at": "2026-03-02T11:36:37Z"
        },
        {
          "tag": "v2.5.1",
          "kind": "patch",
          "published_at": "2026-02-28T08:49:55Z"
        },
        {
          "tag": "v2.5.0",
          "kind": "minor",
          "published_at": "2026-02-28T03:38:10Z"
        },
        {
          "tag": "v2.4.0",
          "kind": "minor",
          "published_at": "2026-02-26T03:50:26Z"
        },
        {
          "tag": "v2.3.0",
          "kind": "minor",
          "published_at": "2026-02-24T04:14:16Z"
        },
        {
          "tag": "v2.2.1",
          "kind": "patch",
          "published_at": "2026-02-23T08:58:41Z"
        },
        {
          "tag": "v2.2.0",
          "kind": "minor",
          "published_at": "2026-02-23T08:14:19Z"
        },
        {
          "tag": "v2.1.0",
          "kind": "minor",
          "published_at": "2026-02-23T01:22:55Z"
        },
        {
          "tag": "v2.0.0",
          "kind": "major",
          "published_at": "2026-02-22T09:57:51Z"
        },
        {
          "tag": "v1.4.0",
          "kind": "minor",
          "published_at": "2026-02-22T07:32:48Z"
        },
        {
          "tag": "v1.3.0",
          "kind": "minor",
          "published_at": "2026-02-22T03:01:40Z"
        },
        {
          "tag": "v1.2.0",
          "kind": "minor",
          "published_at": "2026-02-21T23:37:54Z"
        },
        {
          "tag": "v1.1.0",
          "kind": "minor",
          "published_at": "2026-02-21T23:37:42Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "1687729db0c5c2aa331f591866097f7f76ec95eb",
          "body": "* fix(export): honor --functions for json and graphson formats\n\nexportJSON and exportGraphSON ignored opts.fileLevel entirely, always\nreturning file-level (json) or a fixed all-kinds (graphson) shape\nregardless of --functions. dot/mermaid/graphml/neo4j already branched\non fileLevel correctly.\n\nClose\n[…]\nscope. Now graphson\ndoes too, so all five function-level exporters agree on scope: calls\nedges only, nodes limited to those participating in at least one call.\n\nImpact: 1 functions changed, 2 affected",
          "is_bot": false,
          "headline": "fix(export): honor --functions for json and graphson formats (#2141)",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-20T23:37:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8147ce18fdf1a9e2f83c3499a1d327af8729c343",
          "body": "* docs: add dogfood report for v3.16.0\n\n* docs(dogfood-skill): fix stale benchmark script refs, add safety notes from v3.16.0 session\n\n- benchmark scripts are .ts, not .js; note npm run benchmark alias and\n  git fetch --tags requirement for correct version labeling\n- warn against running registry pr\n[…]\ns/**\n(hand-annotated resolution fixtures), unlike the full-repo cold-start and\nengine-comparison scans elsewhere in the report. Addresses Greptile review\nfeedback flagging the unexplained discrepancy.",
          "is_bot": false,
          "headline": "docs: add dogfood report for v3.16.0 (#2143)",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-20T17:09:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ec4f102aaf96a688ba15244f1f19d5bdfba06586",
          "body": "…s\" (#2142)\n\n* fix(audit): distinguish \"file not found\" from \"file has zero functions\"\n\ncodegraph audit <file> printed the same \"No file matching\" message for\na file that genuinely isn't in the graph and for a real, tracked file\nthat just has zero own function/method/class definitions (e.g. a pure\nr\n[…]\nns was misreported as \"not found\" --\nthe exact bug this PR set out to fix, reachable via a different input\nshape. Check explained.results (pre-filter) instead.\n\nImpact: 1 functions changed, 3 affected",
          "is_bot": false,
          "headline": "fix(audit): distinguish \"file not found\" from \"file has zero function…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-20T17:07:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "08644a15d9952555fd1965623acd6e0220a309c8",
          "body": "Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>\nCo-authored-by: carlos-alm <127798846+carlos-alm@users.noreply.github.com>",
          "is_bot": true,
          "headline": "docs: update performance benchmarks (3.16.0) (#2133)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-20T07:27:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4a64789f0114aa84e22706dd412715a0f859ce8b",
          "body": "Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore: release v3.16.0 (#2132)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-20T07:25:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9fb80909fe2552070bbada207cf7450e9106c1fc",
          "body": "Bumps [tree-sitter-cli](https://github.com/tree-sitter/tree-sitter/tree/HEAD/crates/cli/npm) from 0.26.10 to 0.26.11.\n- [Release notes](https://github.com/tree-sitter/tree-sitter/releases)\n- [Commits](https://github.com/tree-sitter/tree-sitter/commits/v0.26.11/crates/cli/npm)\n\n---\nupdated-dependenci\n[…]\nependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Carlos Almeida <contato@carlosalmeida.com>\nCo-authored-by: carlos-alm <127798846+carlos-alm@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(deps-dev): bump tree-sitter-cli from 0.26.10 to 0.26.11 (#2122)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-20T05:21:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5feecd015e468c874027ab53f337b5d505306fa0",
          "body": "…2123)\n\nBumps [commit-and-tag-version](https://github.com/absolute-version/commit-and-tag-version) from 12.7.3 to 13.0.0.\n- [Release notes](https://github.com/absolute-version/commit-and-tag-version/releases)\n- [Changelog](https://github.com/absolute-version/commit-and-tag-version/blob/master/CHANGE\n[…]\nependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Carlos Almeida <contato@carlosalmeida.com>\nCo-authored-by: carlos-alm <127798846+carlos-alm@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(deps-dev): bump commit-and-tag-version from 12.7.3 to 13.0.0 (#…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-20T05:21:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3642ae1ba57586c4bf6e6983cd85c3ca77ebc07f",
          "body": "Bumps [web-tree-sitter](https://github.com/tree-sitter/tree-sitter/tree/HEAD/lib/binding_web) from 0.26.10 to 0.26.11.\n- [Release notes](https://github.com/tree-sitter/tree-sitter/releases)\n- [Commits](https://github.com/tree-sitter/tree-sitter/commits/v0.26.11/lib/binding_web)\n\n---\nupdated-dependen\n[…]\nependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Carlos Almeida <contato@carlosalmeida.com>\nCo-authored-by: carlos-alm <127798846+carlos-alm@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(deps): bump web-tree-sitter from 0.26.10 to 0.26.11 (#2124)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-20T05:20:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0eaaa86603c3a845eb53edb18b7b62d881671ca2",
          "body": "…#2126)\n\nBumps [tree-sitter-gleam](https://github.com/gleam-lang/tree-sitter-gleam) from `c610c28` to `cefbd68`.\n- [Commits](https://github.com/gleam-lang/tree-sitter-gleam/compare/c610c282ef73f830d80c1f0999dce8e83f024ef5...cefbd6863983b4df3214b7934bde5e9ca63d5b7f)\n\n---\nupdated-dependencies:\n- depen\n[…]\nependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Carlos Almeida <contato@carlosalmeida.com>\nCo-authored-by: carlos-alm <127798846+carlos-alm@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(deps-dev): bump tree-sitter-gleam from `c610c28` to `cefbd68` (…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-20T05:20:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9da245a9537179604ff92464ac1c92835ff01b1d",
          "body": "Bumps [actions/setup-go](https://github.com/actions/setup-go) from 6 to 7.\n- [Release notes](https://github.com/actions/setup-go/releases)\n- [Commits](https://github.com/actions/setup-go/compare/v6...v7)\n\n---\nupdated-dependencies:\n- dependency-name: actions/setup-go\n  dependency-version: '7'\n  depen\n[…]\n-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: carlos-alm <127798846+carlos-alm@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(deps): bump actions/setup-go from 6 to 7 (#2120)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-20T05:03:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e03b3d254c97920a004843b1e041606a1b6c4843",
          "body": "* build(deps-dev): bump @biomejs/biome from 2.5.3 to 2.5.4\n\nBumps [@biomejs/biome](https://github.com/biomejs/biome/tree/HEAD/packages/@biomejs/biome) from 2.5.3 to 2.5.4.\n- [Release notes](https://github.com/biomejs/biome/releases)\n- [Changelog](https://github.com/biomejs/biome/blob/main/packages/@\n[…]\nependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Carlos Almeida <contato@carlosalmeida.com>\nCo-authored-by: carlos-alm <127798846+carlos-alm@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(deps-dev): bump @biomejs/biome from 2.5.3 to 2.5.4 (#2125)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-20T05:03:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6097f9c39d785e83525f6d7e8dfbac3955787e7c",
          "body": "…ish gate, not just dev (#2129)\n\n* fix(bench): apply KNOWN_REGRESSIONS baseline fallback to release publish gate, not just dev\n\nThe v3.16.0 release tag (2e0e94f) failed its pre-publish benchmark gate on\nFull build (+42%) and 1-file rebuild (+53-83%), blocking publish. Both\nmetrics are already tracke\n[…]\ng to the module-level KNOWN_REGRESSIONS for production use)\nand have the three unit tests pass a local, test-only fixture instead,\nfully decoupling them from data that is expected to change over time.",
          "is_bot": false,
          "headline": "fix(bench): apply KNOWN_REGRESSIONS baseline fallback to release publ…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-20T04:36:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0f51e0cff989c2f89e5f2631ced19f6e5e6850f5",
          "body": "…78 (#2121)\n\nBumps [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action) from 1.0.171 to 1.0.178.\n- [Release notes](https://github.com/anthropics/claude-code-action/releases)\n- [Commits](https://github.com/anthropics/claude-code-action/compare/e90deca47693f9457b72f2b53c17\n[…]\n-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: carlos-alm <127798846+carlos-alm@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(deps): bump anthropics/claude-code-action from 1.0.171 to 1.0.1…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-20T04:36:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0e45e02eda1e3c57d4802c351e973add38ee531a",
          "body": "Bumps [actions/setup-node](https://github.com/actions/setup-node) from 6 to 7.\n- [Release notes](https://github.com/actions/setup-node/releases)\n- [Commits](https://github.com/actions/setup-node/compare/v6...v7)\n\n---\nupdated-dependencies:\n- dependency-name: actions/setup-node\n  dependency-version: '\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(deps): bump actions/setup-node from 6 to 7 (#2119)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-20T04:35:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "94c0af162d50f1523828e5790ce61ede2b3098dd",
          "body": "…t the latest tag (#2128)\n\n* fix(ci): anchor native-change detection to package.json's version, not the latest tag\n\nThe v3.16.0 release attempt tagged the release but failed its pre-publish\nbenchmark gate (#2127) before publish ran, so package.json on main is still\n3.15.0 and nothing was actually pu\n[…]\npackage.json's declared version instead of \"the most\nrecent semver-shaped tag\" ties the check to what's actually checked out.\n\n* fix: parse package.json version via node -p instead of grep/sed (#2128)",
          "is_bot": false,
          "headline": "fix(ci): anchor native-change detection to package.json's version, no…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-20T04:10:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2e0e94fa7a28d5c44a21e8829c3bfcd2e8cf13c5",
          "body": null,
          "is_bot": false,
          "headline": "docs: prepare release notes for v3.16.0 (#2118)",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-17T09:00:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f316d22579b02a975e75ae55099c59f7ea64b615",
          "body": "…ng (#2103)\n\n* fix: persist deleted-export advisories so check survives purge ordering\n\ncheckNoDeletedExportsInUse (#1806) only ever queried the live nodes/edges\ntables, so once any codegraph build purged a deleted file's rows -\ndetectChanges does this unconditionally, independent of whether\ncodegra\n[…]\nectory leaked for the lifetime of the\ntest process. Switch to afterEach so both are cleaned up after every test.\n\ndocs check acknowledged: test-only change, no README/CLAUDE.md/ROADMAP\nchanges needed.",
          "is_bot": false,
          "headline": "fix: persist deleted-export advisories so check survives purge orderi…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-17T07:49:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "500d91682caa40df565c4c1086f0ae1f920596e5",
          "body": "* fix(ci): skip automated Claude review for trivial/docs-only PRs\n\nautomated-review ran an unconditional, deliberately expensive Claude review\n(root-cause analysis, backlog compliance grading, etc.) on every human-\nauthored PR — 271 in the last 30 days, no size or scope gating. Unlike the\nGitHub Act\n[…]\n as 0 lines and could pass the trivial guard,\nskipping the automated review. Detect the \"-\" sentinel explicitly and\nforce TOTAL_CHANGED to a value above the threshold when any binary\nentry is present.",
          "is_bot": false,
          "headline": "fix(ci): skip automated Claude review for trivial/docs-only PRs (#2117)",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-17T06:14:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "46d7058549178a6aa2806a4aa6b051e035a6f168",
          "body": "… (#2116)\n\n* fix(ci): skip native-host-build when no native-relevant paths changed\n\nnative-host-build, test, parity, and pre-publish-benchmark all ran a full\n3-OS Rust build (via native-host-build) unconditionally on every push/PR,\neven for pure-TS/docs changes that can't affect the native addon.\n\nA\n[…]\n without republishing.\n\nDiff against the last release tag instead, so native-host-build\ncorrectly reruns whenever the fallback binary would be stale, not just\nwhen the current PR/push touched crates/.",
          "is_bot": false,
          "headline": "fix(ci): skip native-host-build when no native-relevant paths changed…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-17T06:14:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5ff588d66883db298d16812364ce81011dfec6f2",
          "body": "… (#2104)\n\n* fix(perf): resolve config once in withRepo to avoid double loadConfig\n\nwithRepo() already resolves config once and threads it to its callback as\n(repo, dbConfig) (landed via #1943), but fnImpactData() and briefData() -\nits only two callers that need analysis-tuning config - still ignore\n[…]\nhain. A regression where briefData reverted to calling\nloadConfig() itself would have passed this test undetected. Mirrors the\nanalogous fnImpactData test, which already calls fnImpactData() directly.",
          "is_bot": false,
          "headline": "fix(perf): resolve config once in withRepo to avoid double loadConfig…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-17T06:13:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "156004ace166893e2e2faae69c29c0920f5b2bc0",
          "body": "…ges (#2102)\n\n* fix(extractors): extract bare super(...) constructor calls as call edges\n\nextractCallInfo (WASM/TS) and extract_call_info (native Rust) had no\nbranch for the super keyword-callee call shape, so a bare super(...)\nconstructor call was silently dropped -- unlike super.method(), which\nal\n[…]\noes\nreturn early. Both are fixed the same way, mirroring the Rust\nhandle_call_expr's super branch (which already returns immediately\nafter recording the call).\n\nImpact: 2 functions changed, 4 affected",
          "is_bot": false,
          "headline": "fix(extractors): extract bare super(...) constructor calls as call ed…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-17T06:13:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cb886826969cdef1a8ba003b4de256cc8736acda",
          "body": "…2100)\n\n* fix(hooks): skip edit-log validation for in-progress merge commits\n\ngit commit refuses a partial-pathspec commit while MERGE_HEAD exists, so\nthe edit-log check's own suggested workaround (commit specific files) is\nimpossible during a merge. A merge commit also stages every auto-merged\nfile\n[…]\nf [ \"$MERGE_IN_PROGRESS\" = false ] wrapper around just the edit-log\nvalidation, so any commit-time check added below it in the future\nstill runs during merge commits instead of being silently skipped.",
          "is_bot": false,
          "headline": "fix(hooks): skip edit-log validation for in-progress merge commits (#…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-17T06:13:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0e519901139ee156f0c817d5011a0682ca761ded",
          "body": "* fix(ci): move dev builds from every push to a daily schedule\n\npublish.yml ran the full 6-platform native build + dev release on every\nmerge to main (~8/day), tracking merge frequency instead of actual need.\nMove the dev-build trigger to a daily schedule with a no-new-commits skip,\ndecoupling cost \n[…]\nt <sha>\"\nphrasing used by the publish-dev release notes template instead of\nmatching the first bare 40-char hex string in the body, which could\npick up an unrelated hex string in future release notes.",
          "is_bot": false,
          "headline": "fix(ci): move dev builds from every push to a daily schedule (#2113)",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-16T08:51:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7aa3811803cab381e6c43231e2ce83d9b9f08320",
          "body": "…f excluding 'push' (#2114)\n\nBoth jobs gated on `workflow_run.event != 'push'`, which stops matching once\nPublish's dev-build trigger moves from push to schedule (companion PR).\nSwitch to a positive allow-list of 'release'/'workflow_dispatch' so the\nfilter can't silently drift out of sync with Publish's trigger set again.",
          "is_bot": false,
          "headline": "fix(ci): allow-list Publish trigger events in benchmark.yml instead o…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-16T08:50:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "06ab30405697d926e7fcefbb555219ee945354ba",
          "body": "…es in sedi() (#2097)\n\nGreptile flagged two robustness gaps in the sedi() rewrite: mv \"$tmp\"\n\"$file\" replaces the target's inode with the scratch file's, so the\ntarget picks up mktemp's restrictive 0600 mode instead of keeping its\nown permissions; and a failed mv was not checked, so sedi() reported\n\n[…]\npy surfaces as a failure. The scratch file is\nremoved unconditionally afterward instead of only in the failure\nbranch, since cp (unlike mv) never consumes it.\n\nImpact: 1 functions changed, 12 affected",
          "is_bot": false,
          "headline": "fix(tracer): preserve target file permissions and surface copy failur…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-16T08:50:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d257f88b2d1c9ed2ddcd634fd9ef7434136c544e",
          "body": "…71 (#2090)\n\nBumps [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action) from 1.0.165 to 1.0.171.\n- [Release notes](https://github.com/anthropics/claude-code-action/releases)\n- [Commits](https://github.com/anthropics/claude-code-action/compare/558b1d6cab4085c7753fe402c10b\n[…]\n-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: carlos-alm <127798846+carlos-alm@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(deps): bump anthropics/claude-code-action from 1.0.165 to 1.0.1…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-16T07:20:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cced0eec22d06c553af9ed8617debbaf7fc8f683",
          "body": "Bumps [@commitlint/cli](https://github.com/conventional-changelog/commitlint/tree/HEAD/@commitlint/cli) from 21.2.0 to 21.2.1.\n- [Release notes](https://github.com/conventional-changelog/commitlint/releases)\n- [Changelog](https://github.com/conventional-changelog/commitlint/blob/master/@commitlint/c\n[…]\n-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: carlos-alm <127798846+carlos-alm@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(deps-dev): bump @commitlint/cli from 21.2.0 to 21.2.1 (#2091)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-16T07:19:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ca430e7bbb6c003c4972b8dc7459425595a089a7",
          "body": "Bumps [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8) from 4.1.9 to 4.1.10.\n- [Release notes](https://github.com/vitest-dev/vitest/releases)\n- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)\n- [Commits](https://github.com/vitest\n[…]\n-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: carlos-alm <127798846+carlos-alm@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(deps-dev): bump @vitest/coverage-v8 from 4.1.9 to 4.1.10 (#2094)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-16T07:19:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "90aaaccb8f1e741cea58a73e4bb522c3a0b23b2e",
          "body": "…atrix (#2115)\n\nbuild-native.yml and publish.yml each maintained their own copy of the same\n6-target cross-compilation matrix and toolchain setup, with only a one-step\ndifference (Cargo.toml version sync). Extract build-native-matrix.yml as a\nworkflow_call reusable workflow, parameterized by an optional version input,\nso both callers share one definition instead of two that can silently drift.",
          "is_bot": false,
          "headline": "fix(ci): extract reusable workflow for the native cross-compilation m…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-16T07:19:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1598f79c7dfdcb1f9970b5b40488a5a6dbc119e6",
          "body": "Bumps [@biomejs/biome](https://github.com/biomejs/biome/tree/HEAD/packages/@biomejs/biome) from 2.5.2 to 2.5.3.\n- [Release notes](https://github.com/biomejs/biome/releases)\n- [Changelog](https://github.com/biomejs/biome/blob/main/packages/@biomejs/biome/CHANGELOG.md)\n- [Commits](https://github.com/b\n[…]\n-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: carlos-alm <127798846+carlos-alm@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(deps-dev): bump @biomejs/biome from 2.5.2 to 2.5.3 (#2092)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-16T07:18:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c0fa57d3f689a9ea2d6dd3308ab4e2c4380b5c53",
          "body": "Bumps [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) from 4.1.9 to 4.1.10.\n- [Release notes](https://github.com/vitest-dev/vitest/releases)\n- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)\n- [Commits](https://github.com/vitest-dev/vitest/commit\n[…]\n-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: carlos-alm <127798846+carlos-alm@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(deps-dev): bump vitest from 4.1.9 to 4.1.10 (#2095)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-16T07:18:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8d6d98e9916fa5045013315082fe4448fc6b6802",
          "body": "…ild (#2107)\n\nEvery open PR's pre-publish benchmark gate fails on these two metrics\nagainst the v3.15.0 baseline regardless of PR content. The repo's own\ntracked source file count grew from 629 to 1013 (+61%) since the\nbaseline was recorded, and scripts/benchmark.ts self-benchmarks this\nrepo, so build/rebuild timing legitimately scales with that growth.\nNo release has landed since v3.15.0 to refresh the baseline, since\npublish.yml's pre-publish gate hits the same comparison.",
          "is_bot": false,
          "headline": "fix(bench): exempt 3.15.0 baseline drift for Full build / 1-file rebu…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-16T06:47:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "00bf942641b37281e60dec4885a1a1e039560981",
          "body": "… engine (#2061)\n\n* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\nfilter, so batch\n[…]\nData, hybridSearchData, withReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this wiring pass, bo…",
          "is_bot": false,
          "headline": "fix(native): resolve monorepo workspace package imports in the native…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-11T16:26:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "af18a10111f97d08da16fb6c5442e69c68caf034",
          "body": "…kotlin/swift/scala/bash (#2059)\n\n* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\n\n[…]\ngData, manifestoData, hybridSearchData, withReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this…",
          "is_bot": false,
          "headline": "fix(complexity): add cognitive/cyclomatic/Halstead support for c/cpp/…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-11T15:20:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f4ddef5cc8ab8168dccc79046bf507e847dc72de",
          "body": "…y stubs (#2056)\n\n* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\nfilter, so batch\n[…]\nData, hybridSearchData, withReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this wiring pass, bo…",
          "is_bot": false,
          "headline": "fix(complexity): stop using dotted names as a proxy for signature-onl…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-11T14:46:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6e5313decb8d0880f997a0500d8ff6c679aa4422",
          "body": "…destructures (#2052)\n\n* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\nfilter, so \n[…]\nfestoData, hybridSearchData, withReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this wiring pas…",
          "is_bot": false,
          "headline": "fix(extractors): extract rest/default bindings from dynamic import() …",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-11T13:45:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c7279d4fa10d24763db2382b0ab2f017ab47cf6e",
          "body": "* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\nfilter, so batch complexity <file>\n[…]\nrchData, withReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this wiring pass, both\nintentionall…",
          "is_bot": false,
          "headline": "fix(tracer): fix C/C++ dynamic tracer compile/link/crash bugs (#2050)",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-11T12:59:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "333492ddf58f34630dfa61a94701d39173f3af44",
          "body": "…ve call sites (#2047)\n\n* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\nfilter, so\n[…]\nifestoData, hybridSearchData, withReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this wiring pa…",
          "is_bot": false,
          "headline": "fix(tracer): fix BSD-incompatible sed injection at remaining jvm/nati…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-11T12:27:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "622ad0ebcde49f9d27faaa1ce999d1f153c6a75c",
          "body": "…logic (#2044)\n\n* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\nfilter, so batch c\n[…]\nta, hybridSearchData, withReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this wiring pass, both…",
          "is_bot": false,
          "headline": "docs(roles): correct hasActiveFileSiblings JSDoc to match population …",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-11T11:14:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "529d1a0829f240aa72f34711df5ca9d3d637bc4a",
          "body": "…ctor (#2043)\n\n* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\nfilter, so batch co\n[…]\na, hybridSearchData, withReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this wiring pass, both\n…",
          "is_bot": false,
          "headline": "fix(lua): port eval/computed-key dynamic-call detection to WASM extra…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-11T10:47:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cac0e79cb03bc5087a6132aef2ffe7dea462f9f1",
          "body": "…d module paths (#2041)\n\n* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\nfilter, s\n[…]\nnifestoData, hybridSearchData, withReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this wiring p…",
          "is_bot": false,
          "headline": "fix(scripts): resolve token-benchmark.ts --perf imports to real neste…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-11T09:59:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1f87ca61f1830cbb8086159c2f5e58074bf197d1",
          "body": "* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\nfilter, so batch complexity <file>\n[…]\nwithReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this wiring pass, both\nintentionally out of …",
          "is_bot": false,
          "headline": "refactor: decompose runSession in token-benchmark.ts (#2040)",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-11T09:29:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6e2be0aed200ac2e78c33943e56082045c55b932",
          "body": "…d node (#2039)\n\n* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\nfilter, so batch \n[…]\nata, hybridSearchData, withReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this wiring pass, bot…",
          "is_bot": false,
          "headline": "fix(scripts): resolve benchmark hub targets to a single, kind-filtere…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-11T08:59:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5afbaa6e5a7b91f2573b001240b6db738fb98f6c",
          "body": "…ucturing (#2038)\n\n* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\nfilter, so batc\n[…]\noData, hybridSearchData, withReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this wiring pass, b…",
          "is_bot": false,
          "headline": "fix(extractors): emit per-element definitions for array-pattern destr…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-11T08:21:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cb037944f58350bf054259d7a6407df0901db155",
          "body": "…M (#2035)\n\n* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\nfilter, so batch compl\n[…]\nhybridSearchData, withReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this wiring pass, both\nint…",
          "is_bot": false,
          "headline": "fix(extractors): resolve inline object-literal dispatch tables on WAS…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-11T07:33:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "35ed45d120fc3258d6f25034fa31d07159e54470",
          "body": "…ef liveness (#2034)\n\n* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\nfilter, so b\n[…]\nestoData, hybridSearchData, withReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this wiring pass…",
          "is_bot": false,
          "headline": "fix(resolver): require invocation evidence for object-literal value-r…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-11T06:25:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d3a0232a7b565fac73b4fe34277c5c23f47807bb",
          "body": "… as call edges (#2031)\n\n* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\nfilter, s\n[…]\nnifestoData, hybridSearchData, withReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this wiring p…",
          "is_bot": false,
          "headline": "fix(extractors): attribute same-file ES6 getter/setter property reads…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-11T05:08:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b8a6c1ac8ab320733a029764b5b0c13a6fff5e7a",
          "body": "…hod (#2028)\n\n* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\nfilter, so batch com\n[…]\n, hybridSearchData, withReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this wiring pass, both\ni…",
          "is_bot": false,
          "headline": "fix(resolver): attribute new ClassName() calls to the constructor met…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-11T03:46:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fa678d41daa910b69241944ad3a34d48a5a7d3ef",
          "body": "…aring calls (#2026)\n\n* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\nfilter, so b\n[…]\nestoData, hybridSearchData, withReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this wiring pass…",
          "is_bot": false,
          "headline": "fix(resolver): kind-filter same-file bare-name lookup for receiver-be…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-11T01:35:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7c4cb640f634b7210fe53b2c48b49e6ac3a90580",
          "body": "… native orchestrator (#2024)\n\n* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\nfil\n[…]\nta, manifestoData, hybridSearchData, withReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this wi…",
          "is_bot": false,
          "headline": "fix(native): add Object.defineProperty accessor dispatch post-pass to…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-11T00:44:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "964d8f0b43b50104cf0bfe6656a97db36863c69e",
          "body": "…ion sites (#2022)\n\n* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\nfilter, so bat\n[…]\ntoData, hybridSearchData, withReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this wiring pass, …",
          "is_bot": false,
          "headline": "fix: unwrap computed string-literal keys in typeMap/prototype extract…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-11T00:20:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "90e943103f1f6e374c8100bf75ca5ded6491adf1",
          "body": "…factories (#2021)\n\n* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\nfilter, so bat\n[…]\ntoData, hybridSearchData, withReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this wiring pass, …",
          "is_bot": false,
          "headline": "fix(native): thread config.db.busyTimeoutMs into NativeDatabase open …",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-10T23:39:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6babf15311d2623f6017bdb5d6c49cc104461a10",
          "body": "…nctions (#2018)\n\nResolves conflicts against main: this branch was far behind (82 conflicting files across 3+ weeks of independent merges), of which only 9 files plus a new test file were actually owned by this PR's own commit — the remaining 73 were pure stack-noise from the branch predating those \n[…]\nith the known flaky CI-runner-noise pattern seen throughout this session. Verified locally clean both times: `RUN_REGRESSION_GUARD=1 npm run test:regression-guard` → 25/25 passed. Merging via --admin.",
          "is_bot": false,
          "headline": "fix: derive loadConfig() rootDir from --db path in read-only query fu…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-10T22:20:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "162040956e1e860ad578495e6b1174b5c50cf184",
          "body": "…e also changes (#2014)\n\nResolves conflicts against main (independent #1730/#1812 hierarchy-edge work, #1849 wildcard-reexport markers, and #1997's shared importNamePairs extraction) and adds `alignSiblingLines`/`align_sibling_lines`, replacing the old ordinal/nearest-line two-tier heuristic for rev\n[…]\nered comments, CI green apart from the flaky gate) being satisfied — consistent with the unusually long response times observed for other PRs in this session. Proceeding per established judgment call.",
          "is_bot": false,
          "headline": "fix: reconnect reverse-dep edges correctly when a sibling group's siz…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-10T16:56:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "782fefe4a66d7f2a063ffdfdecd64eb8179d3929",
          "body": "…ge path\n\nfix(native): recover renamed import names in the FFI hybrid import-edge path\n\nFixes a silent edge-miss in the hybrid FFI import path\n(buildImportEdgesNative -> build_import_edges) where renamed import\nspecifiers (import { X as Y }) caused symbol and barrel-through lookups\nto search for the\n[…]\nark gate failed three times in a row (the routine\nflaky \"1-file rebuild\" timing gate seen on prior PRs). Verified clean\nlocally via RUN_REGRESSION_GUARD=1 npm run test:regression-guard (25/25\npassed).",
          "is_bot": false,
          "headline": "fix(native): recover renamed import names in the FFI hybrid import-ed…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-10T15:34:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d90be6ff567920675d583f5142d758e459beefc1",
          "body": "…ster()\n\nfix(scripts): migrate ts-resolve-loader.js off deprecated module.register()\n\nMigrates scripts/ts-resolve-loader.js from the deprecated module.register()\n(DEP0205) to module.registerHooks() for Node >= 22.15.0 / >= 23.5.0, keeping\nregister() as a fallback for older nodes within the repo's do\n[…]\nark gate failed three times in a row (the routine\nflaky \"1-file rebuild\" timing gate seen on prior PRs). Verified clean\nlocally via RUN_REGRESSION_GUARD=1 npm run test:regression-guard (25/25\npassed).",
          "is_bot": false,
          "headline": "fix(scripts): migrate ts-resolve-loader.js off deprecated module.regi…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-10T14:21:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "874967e2d19750932a349fe70db6f0eded069fec",
          "body": "docs: add missing titan-grind mirror to claude-code-skills examples\n\nAdds the missing titan-grind docs mirror -- a 729-line SKILL.md under\ndocs/examples/claude-code-skills/titan-grind/ and the corresponding row\nplus ASCII-diagram node in the README -- so the cp -r install snippet\nproduces all phases\n[…]\n2-117ms baseline\n-> 177-212ms elevated, +50-89% against a 50-75% threshold depending on\ncheck category). Verified clean locally via\nRUN_REGRESSION_GUARD=1 npm run test:regression-guard (25/25 passed).",
          "is_bot": false,
          "headline": "docs: add missing titan-grind mirror to claude-code-skills examples",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-10T13:24:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "56f9dae6d720d41743ce7f0d5f2a4dff94e08dc4",
          "body": "fix(rust): resolve self.field, unit-struct, and constructor-typed locals\n\nFixes three receiver-typing gaps in the Rust extractor that prevented\nself.field.method(), unit-struct values, and constructor-typed locals\nfrom being resolved. Both the WASM (rust.ts) and native (rust_lang.rs)\nextractors are \n[…]\n2-117ms baseline\n-> 176-203ms elevated, +50-81% against a 50-75% threshold depending on\ncheck category). Verified clean locally via\nRUN_REGRESSION_GUARD=1 npm run test:regression-guard (25/25 passed).",
          "is_bot": false,
          "headline": "fix(rust): resolve self.field, unit-struct, and constructor-typed locals",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-10T12:27:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "55538f164901beb234b3c13673e4600cd846d7d8",
          "body": "docs: regenerate stale audit/diff-impact example output blocks\n\nReplaces four stale example output blocks in docs/examples/CLI.md and\ndocs/examples/MCP.md (diff-impact and audit, both CLI + MCP) with output\nregenerated from real tool runs against the repo's own graph.\n\nFixed a genuine Greptile findi\n[…]\n, no\nconflicts) is satisfied.\n\nThe Pre-publish benchmark gate failed twice (the routine flaky \"1-file\nrebuild\" timing gate seen on prior PRs) and passed clean on the second\nrerun with no code changes.",
          "is_bot": false,
          "headline": "docs: regenerate stale audit/diff-impact example output blocks",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-10T11:10:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6f460a95e63b8a0c64da625a6ec4815d8199b6ff",
          "body": "…matic complexity\n\nrefactor(leiden): extract makePartition's inline getters to cut cyclomatic complexity\n\nmakePartition (cyc=10, threshold 10) built its returned Partition object with\nseveral getter closures containing their own inline bounds-check ternaries and\n`|| 0` fallbacks. Extracted fgetOrZer\n[…]\nerge\" review with no actionable comments.\n\nThe Pre-publish benchmark gate failed once (the routine flaky \"1-file rebuild\"\ntiming gate seen on prior PRs) and passed clean on rerun with no code changes.",
          "is_bot": false,
          "headline": "refactor(leiden): extract makePartition's inline getters to cut cyclo…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-10T08:17:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "68949dc0c42581848f73d2216b03f2e2a971e66e",
          "body": "fix(embed): resolve default DB path from positional dir, not cwd (#1869)\n\nFixes embed's default DB path resolution to prefer the positional <dir>\nargument over process.cwd(), matching build's behavior. Also fixes two\nGreptile-flagged issues: rootDirHint priority in findDbPath's no-DB-found\nfallback,\n[…]\ne 22 tests pass clean now.\n\nThe Pre-publish benchmark gate failed once after that fix (the routine\nflaky \"1-file rebuild\" timing gate seen on prior PRs) and passed clean\non rerun with no code changes.",
          "is_bot": false,
          "headline": "fix(embed): resolve default DB path from positional dir, not cwd (#1869)",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-10T07:35:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "90447ea20807c7e000b509cc37a27f68736bad59",
          "body": "… candidate (#2000)\n\nfix(resolver): resolveByGlobal picks the single best match, not every candidate (#2000)\n\nCloses #1863\n\nFixed a genuine Greptile finding: Math.max(...scored.map(...)) can throw\nRangeError for a large candidate array. Replaced with a reduce, matching\nthe fold-based approach the Ru\n[…]\nsholds 50-75% depending on category) that has affected every PR\nmerged this cycle. Verified locally with RUN_REGRESSION_GUARD=1 npm run\ntest:regression-guard (25/25 clean) before merging with --admin.",
          "is_bot": false,
          "headline": "fix(resolver): resolveByGlobal picks the single best match, not every…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-10T06:17:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0149f18da9b6eef10c0a6b3c591fe6a46e3ce973",
          "body": "…1998)\n\nfix(config): derive ENV_LLM_KEYS from ENV_LLM_MAP to prevent drift (#1998)\n\nCloses #1857\n\nFixed a genuine Greptile finding: the regression test hardcoded the same\n4-key list the production fix just eliminated, undermining the fix's\nown purpose. Exported ENV_LLM_MAP and derived the test's key\n[…]\nsholds 50-75% depending on category) that has affected every PR\nmerged this cycle. Verified locally with RUN_REGRESSION_GUARD=1 npm run\ntest:regression-guard (25/25 clean) before merging with --admin.",
          "is_bot": false,
          "headline": "fix(config): derive ENV_LLM_KEYS from ENV_LLM_MAP to prevent drift (#…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-10T05:05:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5dd5b79f105ea6a95126e2cc1a980a31bd7fa914",
          "body": "…edges into watch-mode rebuild (#1997)\n\nfix(incremental): port CHA/RTA dispatch, points-to, and dynamic-sink edges into watch-mode rebuild (#1997)\n\nCloses #1852\n\nFixed a genuine Greptile P1 finding during review: the new CHA post-pass\nused coerceTypeMap directly instead of buildIncrementalTypeMap (w\n[…]\nsholds 50-75% depending on category) that has affected every PR\nmerged this cycle. Verified locally with RUN_REGRESSION_GUARD=1 npm run\ntest:regression-guard (25/25 clean) before merging with --admin.",
          "is_bot": false,
          "headline": "fix(incremental): port CHA/RTA dispatch, points-to, and dynamic-sink …",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-10T04:07:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "26197c0649fa265e9c5a69bb4a92e1eda6a5472f",
          "body": "…into apply-results.ts (#1992)\n\nrefactor(ast-analysis): extract shared CFG/complexity result-merging into apply-results.ts (#1992)\n\nCloses #1850\n\nNote: Pre-publish benchmark gate failed 3 times on the known-flaky\n\"1-file rebuild\" signature (112-117ms baseline -> 178-203ms, +52-81%,\nthresholds 50-75%\n[…]\nirically: vitest's Vite-based transform\nshims __dirname even under this project's \"type\": \"module\", and an\nexisting merged test file (docs-check-flags.test.ts) uses the identical\npattern successfully.",
          "is_bot": false,
          "headline": "refactor(ast-analysis): extract shared CFG/complexity result-merging …",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-10T02:47:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fc125215341caa1f9dcce2af79d4ab4e2c57f9e6",
          "body": "…-parses (#1991)\n\nfix(native): scope barrel-only import skipping to transient barrel re-parses (#1991)\n\nCloses #1848\n\nNote: Pre-publish benchmark gate failed 3 times on the known-flaky\n\"1-file rebuild\" signature (112-117ms baseline -> 174-203ms, +49-81%,\nthresholds 15-75% depending on category) that has affected every PR\nmerged this cycle. Verified locally with RUN_REGRESSION_GUARD=1 npm run\ntest:regression-guard (25/25 clean) before merging with --admin.",
          "is_bot": false,
          "headline": "fix(native): scope barrel-only import skipping to transient barrel re…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-10T01:53:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a5f99bb088af8cc66daa3c874af4223596282e9d",
          "body": "… functions via parameter type (#1989)\n\nfix(resolver): recognize identifier args to user-defined higher-order functions via parameter type (#1989)\n\nCloses #1845\n\nNote: Pre-publish benchmark gate failed once on the known-flaky \"1-file\nrebuild\" signature (117→180-224ms, +54-100%, threshold 15-75%) that has\naffected every PR merged this cycle. Reran once and it passed clean.",
          "is_bot": false,
          "headline": "fix(resolver): recognize identifier args to user-defined higher-order…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-10T00:56:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a00ba491d892b6235ecdffa4e0bddb429e963008",
          "body": "… (#1988)\n\nfix(cycles): classify cycles whose only closing edges are speculative\n\nFixes #1844. Greptile found a real P1 bug in the classification algorithm:\na speculative edge merging a confirmed cycle into a larger SCC caused the\nwhole grouping to be marked speculative, silently dropping the real\nc\n[…]\nted to this PR's change. Verified locally via\nRUN_REGRESSION_GUARD=1 npm run test:regression-guard: 25/25 passed\ncleanly. Merging with --admin per the established flaky-benchmark-gate\nescalation path.",
          "is_bot": false,
          "headline": "fix(cycles): classify cycles whose only closing edges are speculative…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-09T23:15:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d1d84e75843d551d98d0e30c0edbd9003544d298",
          "body": "…d (#1986)\n\ndocs: fix stale codegraph check flag names in recommended-practices.md\n\nFixes #1842. Greptile found a real gap in the regression test's own\ncoverage: the flag extractor only scanned \"codegraph check\" example\nlines, missing the \"Available predicates:\" prose list — exactly the kind\nof plac\n[…]\n25 passed cleanly. CLA signature check also failed once on a transient\nGitHub API 502 (unrelated), passed clean on rerun. Merging with --admin\nper the established flaky-benchmark-gate escalation path.",
          "is_bot": false,
          "headline": "docs: fix stale codegraph check flag names in recommended-practices.m…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-09T21:35:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "61698ae084ab04e219fca891e43422e7d067c4bf",
          "body": "…1983)\n\nfix: capture removed files' cross-directory neighbors before purge\n\nFixes #1839. Investigated a P1 Greptile finding claiming the scoped-rebuild\npath leaves removedFileNeighbors empty — reproduced empirically via\nbuildGraph(dir, { scope: [...] }) on both engines and confirmed the claim\nwas in\n[…]\nted to this PR's change. Verified locally via\nRUN_REGRESSION_GUARD=1 npm run test:regression-guard: 25/25 passed\ncleanly. Merging with --admin per the established flaky-benchmark-gate\nescalation path.",
          "is_bot": false,
          "headline": "fix: capture removed files' cross-directory neighbors before purge (#…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-09T20:37:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "83aa18269953e5615676919f5eb627e0dc2988c7",
          "body": "…'s path (#1982)\n\nfix(hooks): resolve track-edits.sh's PROJECT_DIR from the edited file's path\n\nFixes #1838. Includes a real Windows-only bug found and fixed during CI:\ngit rev-parse --show-toplevel can return a directory's auto-generated 8.3\nshort-name alias (e.g. \"RUNNER~1\" for \"runneradmin\") whil\n[…]\nted to this PR's change. Verified locally via\nRUN_REGRESSION_GUARD=1 npm run test:regression-guard: 25/25 passed\ncleanly. Merging with --admin per the established flaky-benchmark-gate\nescalation path.",
          "is_bot": false,
          "headline": "fix(hooks): resolve track-edits.sh's PROJECT_DIR from the edited file…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-09T19:17:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5b1c5231d8f86477bc55f34d2d5ec40bae7f153e",
          "body": "…(#1980)\n\nfix(hooks): point update-graph.sh fallback build path at dist/cli.js\n\nNote: Pre-publish benchmark gate failed 3x on the known-flaky \"1-file rebuild\"\nmetric (117→176-207ns range, threshold 15%/50-75%), unrelated to this PR's\nchange (a one-line path fix in update-graph.sh). Verified locally via\nRUN_REGRESSION_GUARD=1 npm run test:regression-guard: 25/25 passed cleanly.\nMerging with --admin per the established flaky-benchmark-gate escalation path.",
          "is_bot": false,
          "headline": "fix(hooks): point update-graph.sh fallback build path at dist/cli.js …",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-09T15:51:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c3229c58738320bdebfe20db56e6c2457640d9de",
          "body": "…ses (#1978)\n\nPre-publish benchmark gate (\"1-file rebuild\") failed 3 consecutive times\n(original + 2 reruns) with the same known signature: stable baseline\n(112-117ms) vs an elevated measured value (178-208ms). Local\nRUN_REGRESSION_GUARD=1 run on non-shared hardware passed cleanly (25/25) —\nconfirms\n[…]\nessed 2 Greptile P1 findings (TYPESCRIPT_EXTENSIONS missing .mts/.cts\nin both engines) and fixed 2 silent-auto-merge duplicate-importNamePairs\nbugs during conflict resolution (same class as PR #1968).",
          "is_bot": false,
          "headline": "fix(exports): credit plain imports of TypeScript interfaces/type alia…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-09T14:50:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "54d8f1e2f94f40b7454ec0bf69198f797d1ac740",
          "body": "… tooling (#1977)\n\nPre-publish benchmark gate (\"1-file rebuild\") failed 3 consecutive times\n(original + 2 reruns) with the same known signature: stable baseline\n(112-117ms) vs an elevated measured value (176-204ms). Local\nRUN_REGRESSION_GUARD=1 run on non-shared hardware passed cleanly (25/25) —\ncon\n[…]\nptile P2 findings (tsup was never a repository dependency;\ngrammars/tree-sitter-erlang.wasm is a tracked .gitignore exception) and\nfixed a silent-auto-merge duplication bug in the conflict resolution.",
          "is_bot": false,
          "headline": "docs: refresh CONTRIBUTING.md for TypeScript architecture and current…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-09T13:16:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8d0416288db549a59d10990535bdc5d1e5b13485",
          "body": "…ies (#1974)\n\n* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\nfilter, so batch com\n[…]\n, hybridSearchData, withReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this wiring pass, both\ni…",
          "is_bot": false,
          "headline": "fix(exports): discriminate file-level from symbol-level consumer entr…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-09T11:35:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2dc26b3b2949293b1274653e643ebd0622822487",
          "body": "…#1972)\n\nPre-publish benchmark gate (\"1-file rebuild\") failed 3 consecutive times\n(original + 2 reruns) with the same known signature: stable baseline\n(112-117ms) vs an elevated measured value (176-203ms), spanning both\nnative/wasm and build/incremental variants. Local RUN_REGRESSION_GUARD=1\nrun on \n[…]\nirmed no live bug given the existing purge-before-insert\ndesign on both full-build and incremental fallback paths; filed the\nadjacent misleading-comment/missing-uniqueness-constraint finding as #2072.",
          "is_bot": false,
          "headline": "fix(native): propagate edge/node write failures out of run_pipeline (…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-09T11:02:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "11e372b128ecdb1e982d83bcb9bca7990687bd5e",
          "body": "… (#1971)\n\nPre-publish benchmark gate (\"1-file rebuild\") failed 3 consecutive times\n(original + 2 reruns) with the same signature: baseline 112-113ms rock-\nstable, measured value swinging 199-200ms (78-79% over the 75% threshold).\nLocal RUN_REGRESSION_GUARD=1 run on non-shared hardware passed cleanl\n[…]\n) — confirms CI-runner contention noise, not a real regression from\nthis PR's resolver de-aliasing change. Merging via admin override per the\nestablished escalation practice for this known-flaky gate.",
          "is_bot": false,
          "headline": "fix: resolve renamed-import receiver calls in qualified-method lookup…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-09T09:53:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "20caeb263e9dfaa59f8396782e3f2b345615493e",
          "body": "…1970)\n\n* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\nfilter, so batch complexit\n[…]\nidSearchData, withReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this wiring pass, both\nintenti…",
          "is_bot": false,
          "headline": "fix: record local alias for dynamic import() destructuring renames (#…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-09T08:23:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8470a0158da9593ceb8c60d7fae43d9cb1a35ab5",
          "body": "* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\nfilter, so batch complexity <file>\n[…]\nSearchData, withReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this wiring pass, both\nintention…",
          "is_bot": false,
          "headline": "fix: track barrel re-export renames (export { X as Y } from ...) (#1968)",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-09T07:05:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "aaf39d580f789cf01de5a69ff153d56967e1bbf8",
          "body": "…g (#1965)\n\n* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\nfilter, so batch compl\n[…]\nhybridSearchData, withReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this wiring pass, both\nint…",
          "is_bot": false,
          "headline": "fix: exclude PHP scalar type-hint/cast keywords from ast --kind strin…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-09T05:53:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "20556ef7cbdd73e25e18d1176864ecb362c596fc",
          "body": "…itializer shape (#1964)\n\n* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\nfilter, \n[…]\nanifestoData, hybridSearchData, withReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this wiring …",
          "is_bot": false,
          "headline": "fix(extractors): capture top-level const definitions regardless of in…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-09T05:05:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b3ff263d2de83bf96b0ed694ae4dd53b68c66035",
          "body": "…al methods (#1963)\n\n* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\nfilter, so ba\n[…]\nstoData, hybridSearchData, withReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this wiring pass,…",
          "is_bot": false,
          "headline": "fix(extractors): align native/WASM definitions order for object-liter…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-09T03:23:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "59e7d05c0fc7985216aa3c3d6eaf25486c89e7e4",
          "body": "* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\nfilter, so batch complexity <file>\n[…]\nearchData, withReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this wiring pass, both\nintentiona…",
          "is_bot": false,
          "headline": "fix(native): remove unused source param from get_first_call_arg (#1960)",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-09T00:55:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "40d6d1443097857f7754c8acbed11afd0cde81fe",
          "body": "…#1959)\n\n* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\nfilter, so batch complexi\n[…]\nridSearchData, withReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this wiring pass, both\nintent…",
          "is_bot": false,
          "headline": "fix(native): widen NativeRepository file filters to accept string[] (…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-09T00:06:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3aff0fb584f80f9d7cb4c57dfbc32c6fbc3ac53c",
          "body": "* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\nfilter, so batch complexity <file>\n[…]\nata, withReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this wiring pass, both\nintentionally ou…",
          "is_bot": false,
          "headline": "fix: track inline per-specifier type-only import modifier (#1958)",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-08T23:09:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d4736b0d695e97da345aa215af00b6047965fa24",
          "body": "…guage (#1957)\n\n* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\nfilter, so batch c\n[…]\nta, hybridSearchData, withReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this wiring pass, both…",
          "is_bot": false,
          "headline": "fix(resolver): scope extends/implements edges to same-file/import/lan…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-08T22:07:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1db2b86a6bffd17e47cb8f7d1a200188d9397758",
          "body": "…assification (#1956)\n\n* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\nfilter, so \n[…]\nfestoData, hybridSearchData, withReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this wiring pas…",
          "is_bot": false,
          "headline": "fix(roles): exclude genuine class/struct properties from dead-role cl…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-08T20:29:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "00d1dbe18c41dc474ed5a15f4d65537133aba4c4",
          "body": "…ind 'property' (#1955)\n\n* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\nfilter, s\n[…]\nnifestoData, hybridSearchData, withReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this wiring p…",
          "is_bot": false,
          "headline": "fix(extractors): label property_signature interface/type members as k…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-08T19:44:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e69fedc283932db2863595ac57bbb27155ffc54f",
          "body": "* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\nfilter, so batch complexity <file>\n[…]\nSearchData, withReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this wiring pass, both\nintention…",
          "is_bot": false,
          "headline": "fix(complexity): scope summary stats to file/target/kind filters (#1953)",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-08T18:29:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5ddbac7ed823bf98004665471c5225facab7f620",
          "body": "…ignatureChanges (#1939)\n\n* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\nfilter, \n[…]\nanifestoData, hybridSearchData, withReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this wiring …",
          "is_bot": false,
          "headline": "feat: detect exported-symbol loss from full file deletion in checkNoS…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-08T18:02:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0c59b0c32e2787be864dad0d54e0695beac9c562",
          "body": "…detection parity (#1937)\n\n* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\nfilter,\n[…]\nmanifestoData, hybridSearchData, withReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this wiring…",
          "is_bot": false,
          "headline": "fix: port Leiden algorithm to native Rust for cross-engine community-…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-08T17:20:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "997867832f39641ede58b1a55a26832d5d91bee8",
          "body": "…l sites (#1933)\n\n* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\nfilter, so batch\n[…]\nData, hybridSearchData, withReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this wiring pass, bo…",
          "is_bot": false,
          "headline": "refactor: widen outputResult signature, remove redundant casts at cal…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-08T16:45:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0bb6589018da656b7e2190cecba638b28a76f2ea",
          "body": "…on inputs (#1932)\n\n* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\nfilter, so bat\n[…]\ntoData, hybridSearchData, withReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this wiring pass, …",
          "is_bot": false,
          "headline": "fix: update automated-review workflow to use current claude-code-acti…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-08T16:16:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1bc594ec9a7efebd3230c78463fb2cb452ea6935",
          "body": "* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\nfilter, so batch complexity <file>\n[…]\nchData, withReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this wiring pass, both\nintentionally…",
          "is_bot": false,
          "headline": "fix: credit instanceof ClassName checks as exports consumers (#1930)",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-08T15:42:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "74e29d4fa591d1191b5f11438f7418c0cba1b29f",
          "body": "…s (#1928)\n\n* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\nfilter, so batch compl\n[…]\nhybridSearchData, withReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this wiring pass, both\nint…",
          "is_bot": false,
          "headline": "fix: scope global call-resolution fallback to same-language candidate…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-08T14:41:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "004cb3b896d63e092823efb19b60c597f3ad53b8",
          "body": "…#1924)\n\n* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\nfilter, so batch complexi\n[…]\nridSearchData, withReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this wiring pass, both\nintent…",
          "is_bot": false,
          "headline": "fix: recognize Lua function nodes in complexity metrics computation (…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-08T13:35:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f9a6eec1bf7b76b9c5ea8bc5aedbef5b7454d92c",
          "body": "…rs (#1921)\n\n* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\nfilter, so batch comp\n[…]\n hybridSearchData, withReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this wiring pass, both\nin…",
          "is_bot": false,
          "headline": "fix: credit destructured dynamic import() bindings as exports consume…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-08T13:00:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0670f5c80aba1565b0f884e2d787263ccdeea60b",
          "body": "…ls (#1919)\n\n* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\nfilter, so batch comp\n[…]\n hybridSearchData, withReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this wiring pass, both\nin…",
          "is_bot": false,
          "headline": "fix: restrict entry-role classification to function/method-kind symbo…",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-08T12:15:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9e418888ffa1e1e659bf42b81da1aff399c0d706",
          "body": "* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\nfilter, so batch complexity <file>\n[…]\nData, withReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this wiring pass, both\nintentionally o…",
          "is_bot": false,
          "headline": "fix: restore reflection dynamicKind for .call/.apply/.bind (#1917)",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-08T11:38:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "14357d0090f7bbfd8c4b3291d661c5c84e487cb7",
          "body": "* fix: scope codegraph batch complexity targets to file paths\n\nBATCH_COMMANDS entries with sig: 'dbOnly' (currently only complexity)\nalways wrote their target into opts.target. complexityData treats\nopts.target as a symbol-name filter and opts.file as the file-path\nfilter, so batch complexity <file>\n[…]\nata, withReadonlyDb),\nspying on Database.prototype.pragma to assert the configured value is\nactually applied.\n\nFiled two follow-ups discovered while completing this wiring pass, both\nintentionally ou…",
          "is_bot": false,
          "headline": "refactor: extract shared sedi() helper for tracer scripts (#1915)",
          "author_name": "carlos-alm",
          "author_login": "carlos-alm",
          "committed_at": "2026-07-08T11:07:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        }
      ],
      "releases_count": 53,
      "commits_last_year": 1891,
      "latest_release_at": "2026-07-21T06:31:10Z",
      "latest_release_tag": "dev-v3.16.1-dev.15",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 23,
      "days_since_latest_release": 5,
      "mean_days_between_releases": 5.8
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 87,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "@optave/codegraph",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [
            "codegraph",
            "dependency-graph",
            "code-analysis",
            "tree-sitter",
            "static-analysis",
            "call-graph",
            "impact-analysis",
            "mcp"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@optave/codegraph",
          "is_deprecated": false,
          "latest_version": "3.16.0",
          "repository_url": "https://github.com/optave/ops-codegraph-tool",
          "versions_count": 54,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 2784,
          "first_published_at": "2026-02-21T11:18:33Z",
          "latest_published_at": "2026-07-20T07:18:05.529000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 6
        }
      ]
    },
    "popularity": {
      "forks": 17,
      "stars": 81,
      "watchers": 1,
      "fork_history": {
        "days": [
          {
            "date": "2026-02-22",
            "count": 1
          },
          {
            "date": "2026-03-08",
            "count": 1
          },
          {
            "date": "2026-03-20",
            "count": 1
          },
          {
            "date": "2026-04-05",
            "count": 1
          },
          {
            "date": "2026-04-11",
            "count": 1
          },
          {
            "date": "2026-04-16",
            "count": 2
          },
          {
            "date": "2026-04-28",
            "count": 1
          },
          {
            "date": "2026-04-29",
            "count": 1
          },
          {
            "date": "2026-05-16",
            "count": 1
          },
          {
            "date": "2026-05-22",
            "count": 1
          },
          {
            "date": "2026-06-03",
            "count": 1
          },
          {
            "date": "2026-06-12",
            "count": 1
          },
          {
            "date": "2026-06-19",
            "count": 1
          },
          {
            "date": "2026-06-21",
            "count": 1
          },
          {
            "date": "2026-06-27",
            "count": 1
          },
          {
            "date": "2026-07-13",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 17,
        "total_forks": 17
      },
      "star_history": null,
      "open_issues_and_prs": 110
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "tests/benchmarks/resolution/fixtures/java/Makefile"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "tsconfig.json"
      ],
      "toolchain_manifests": [
        "Cargo.toml",
        "crates/codegraph-core/Cargo.toml"
      ],
      "largest_source_bytes": 329545,
      "source_files_sampled": 990,
      "oversized_source_files": 13,
      "agent_instruction_files": [
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 21129
    },
    "dependencies": {
      "manifests": [
        "Cargo.toml",
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [
          {
            "name": "@hono/node-server",
            "direct": false,
            "version": "1.19.15",
            "severity": "moderate",
            "ecosystem": "npm",
            "cvss_score": 5.9,
            "advisory_ids": [
              "GHSA-frvp-7c67-39w9"
            ],
            "fixed_version": "2.0.5",
            "advisory_count": 1,
            "oldest_advisory_days": 4
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "moderate": 1
        },
        "advisory_count": 1,
        "affected_count": 1,
        "assessed_count": 138,
        "malicious_count": 0,
        "assessed_package": "npm:@optave/codegraph@3.16.0",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "crates",
        "npm"
      ],
      "dependencies": [
        {
          "name": "better-sqlite3",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^12.6.2"
        },
        {
          "name": "commander",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^15.0.0"
        },
        {
          "name": "web-tree-sitter",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.26.5"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 5,
        "merged_prs": 1375,
        "open_issues": 105,
        "closed_ratio": 0.839,
        "closed_issues": 546,
        "closed_unmerged_prs": 123
      },
      "bus_factor": 1,
      "bot_contributors": 2,
      "top_contributors": [
        {
          "type": "User",
          "login": "carlos-alm",
          "commits": 1386,
          "avatar_url": "https://avatars.githubusercontent.com/u/127798846?v=4"
        },
        {
          "type": "User",
          "login": "kecsap",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/1132593?v=4"
        },
        {
          "type": "User",
          "login": "meirLixen",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/67314063?v=4"
        }
      ],
      "contributors_sampled": 3,
      "top_contributor_share": 0.999
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "benchmark.yml",
        "build-native-matrix.yml",
        "build-native.yml",
        "ci.yml",
        "cla.yml",
        "claude.yml",
        "codegraph-impact-comment.yml",
        "codegraph-impact.yml",
        "commitlint.yml",
        "embedding-regression.yml",
        "perf-canary.yml",
        "publish.yml",
        "shield-license-compliance.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        "biome.json"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "Cargo.lock",
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 9,
            "reason": "binaries present in source code",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 5,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/16 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 0,
            "reason": "dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "16 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "1687729db0c5c2aa331f591866097f7f76ec95eb",
        "ran_at": "2026-07-26T08:16:13Z",
        "aggregate_score": 3.5,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-26T06:02:32Z",
      "oldest_open_prs": [
        {
          "number": 2151,
          "created_at": "2026-07-25T10:22:20Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 2152,
          "created_at": "2026-07-25T10:22:23Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 2153,
          "created_at": "2026-07-25T10:22:41Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 2154,
          "created_at": "2026-07-25T10:23:00Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 2155,
          "created_at": "2026-07-25T10:23:14Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-20T23:37:31Z",
      "ci_last_conclusion": "SKIPPED",
      "oldest_open_issues": [
        {
          "number": 1763,
          "created_at": "2026-07-03T22:52:08Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1867,
          "created_at": "2026-07-06T09:49:33Z",
          "last_comment_at": "2026-07-08T08:05:39Z",
          "last_comment_author": "carlos-alm"
        },
        {
          "number": 1876,
          "created_at": "2026-07-06T11:29:34Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1888,
          "created_at": "2026-07-06T13:56:15Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1893,
          "created_at": "2026-07-06T14:46:19Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1901,
          "created_at": "2026-07-06T16:38:27Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1914,
          "created_at": "2026-07-06T18:03:55Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1923,
          "created_at": "2026-07-06T20:56:18Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1926,
          "created_at": "2026-07-06T21:29:55Z",
          "last_comment_at": "2026-07-08T20:11:31Z",
          "last_comment_author": "carlos-alm"
        },
        {
          "number": 1929,
          "created_at": "2026-07-06T21:51:29Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1936,
          "created_at": "2026-07-07T00:16:23Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1938,
          "created_at": "2026-07-07T00:52:10Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1941,
          "created_at": "2026-07-07T01:13:36Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1944,
          "created_at": "2026-07-07T03:23:36Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1946,
          "created_at": "2026-07-07T03:38:38Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1948,
          "created_at": "2026-07-07T04:21:42Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1949,
          "created_at": "2026-07-07T04:26:08Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1952,
          "created_at": "2026-07-07T04:52:37Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1961,
          "created_at": "2026-07-07T11:32:25Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1966,
          "created_at": "2026-07-07T16:40:49Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/optave/ops-codegraph-tool",
    "host": "github.com",
    "name": "ops-codegraph-tool",
    "owner": "optave"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 67,
      "inputs": {
        "security": 46,
        "vitality": 84,
        "community": 63,
        "governance": 54,
        "engineering": 84
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 84,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "commits_last_year": 1891,
              "human_commit_share": 0.85,
              "days_since_last_push": 0,
              "active_weeks_last_year": 23
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "23/52 weeks with commits",
                "points": 15.9,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 23
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "1891 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 1891
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 53,
              "latest_release_tag": "dev-v3.16.1-dev.15",
              "releases_from_tags": false,
              "days_since_latest_release": 5,
              "mean_days_between_releases": 5.8
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "53 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 53
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~5.8 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 5.8
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 63,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "at_risk",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 41,
            "inputs": {
              "forks": 17,
              "stars": 81,
              "watchers": 1,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "81 stars",
                "points": 30.9,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 81
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "17 forks",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 17
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "1 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 57,
            "inputs": {
              "packages": [
                "@optave/codegraph"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 2784
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "2,784 downloads/month across npm",
                "points": 45.9,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 2784,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 54,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 13,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 3,
              "top_contributor_share": 0.999
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "3 contributors",
                "points": 4.1,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 74,
            "inputs": {
              "merged_prs": 1375,
              "open_issues": 105,
              "closed_issues": 546,
              "issue_closed_ratio": 0.839,
              "closed_unmerged_prs": 123
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "84% of issues closed",
                "points": 39.2,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 84
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "1375/1498 decided PRs merged",
                "points": 35.1,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 1375,
                      "decided": 1498
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/16 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 46,
            "inputs": {
              "followers": 5,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "optave",
              "public_repos": 2,
              "account_age_days": 1275
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "5 followers of optave",
                "points": 5.6,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 5,
                      "login": "optave"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "2 public repos, account ~3 yr old",
                "points": 10.5,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 2
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 3
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "@optave/codegraph"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 6
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 6 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "54 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 54
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 84,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "13 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 13
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": "biome.json",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "biome.json"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "topics": [
                "ai-agents",
                "cli",
                "code-analysis",
                "dependency-graph",
                "impact-analysis",
                "incremental-builds",
                "mcp-server",
                "semantic-search",
                "sqlite",
                "static-analysis",
                "tree-sitter",
                "architecture",
                "ci-cd",
                "code-quality",
                "codeowners",
                "complexity-metrics"
              ],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "16 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 16
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 46,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Packaging. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "packaging"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 36,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 3.5
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "binaries present in source code",
                "points": 6.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 3.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/16 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "dangerous workflow patterns detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "16 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Matched the npm:@optave/codegraph@3.16.0 runtime dependency closure — what installing the published package pulls in — 138 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:@optave/codegraph@3.16.0",
                  "assessed": 138
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 88,
            "inputs": {
              "source": "osv",
              "advisories": 1,
              "affected_packages": 1,
              "assessed_packages": 138,
              "unassessed_packages": 0,
              "affected_by_severity": "moderate 1",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "1 affected: @hono/node-server 1.19.15 (moderate 5.9)",
                "points": 13.2,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 1,
                      "packages": "@hono/node-server 1.19.15 (moderate 5.9)"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory has been public longer than 90 days",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "advisories_none_stale",
                    "params": {
                      "days": 90
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 138,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 1
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 78,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 21129
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "85 of 85 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 85,
                      "sampled": 85
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "Cargo.lock",
                "package-lock.json"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [
                "tests/benchmarks/resolution/fixtures/java/Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "tsconfig.json"
              ],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "Cargo.toml",
                "crates/codegraph-core/Cargo.toml"
              ],
              "dependency_bot_commit_share": 0.13
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "tests/benchmarks/resolution/fixtures/java/Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "tests/benchmarks/resolution/fixtures/java/Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": "biome.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "biome.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "13 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 13,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 99,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 329545,
              "source_files_sampled": 990,
              "oversized_source_files": 13
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "13/990 source files over 60KB",
                "points": 54.3,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 990,
                      "oversized": 13
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-26T08:16:32.865850Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/o/optave/ops-codegraph-tool.svg",
  "full_name": "optave/ops-codegraph-tool",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsnpm.