Public record
Software health reportschema 0.27.0 · metrics 1.13.0 · 2026-07-27 03:49 UTC

quantakrypto / pqc-tools

Open-source post-quantum readiness tooling by quantakrypto

TypeScriptApache-2.0★ 9 stars⑂ 0 forkssince Jun 2026View on GitHub ↗

quantakrypto/pqc-tools holds a health index of 67 out of 100, placing it in the Moderate band. It scores highest on Engineering Quality (90/100) and lowest on Sustainability & Governance (43/100). It was last updated today. A single contributor accounts for most of its recent work.

67
overall / 100
Moderate

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

67
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

@QuantaKryptoOrganization
1 follower4 public repossince Jun 2026

This repository is backed by an organization — shared, accountable stewardship that can outlive any single maintainer.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publish
npm@quantakrypto/mcp0.5.22,087134 days ago
npm@quantakrypto/core0.5.02,041116 days ago
npm@quantakrypto/agent0.5.072566 days ago
npm@quantakrypto/qscan0.5.01,597116 days ago
npm@quantakrypto/sieve0.5.01,714116 days ago
npm@quantakrypto/qprobe0.5.031226 days ago

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

75Good · 22% of overall
How it's scored
36/36Push recency — last push 0 days ago
4.2/36Commit cadence — 6/52 weeks with commits
18/18Commit volume — 254 commits in the last year
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Inputs used
commits_last_year254
human_commit_share0.98
days_since_last_push0
active_weeks_last_year6

Release discipline

100Excellent
How it's scored
27/27Ships releases — 4 releases published
36/36Release recency — latest release 3 days ago
27/27Release cadence — a release every ~2.5 days
0/10OpenSSF Scorecard: Signed-Releases — no data
Inputs used
releases_count4
latest_release_tagv1
releases_from_tagsno
days_since_latest_release3
mean_days_between_releases2.5
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

55Moderate · 18% of overall
How it's scored
14.6/60Stars — 9 stars
0/25Forks — 0 forks
0/15Watchers — 0 watchers
Inputs used
forks0
stars9
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

Community health

92Excellent
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (Apache-2.0)
18/18CONTRIBUTING guide
13.5/13.5Code of conduct
0/7.2Issue template
6.3/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingyes
has_issue_templateno
has_code_of_conductyes
has_pull_request_templateyes
How it's scored
52.4/80Monthly downloads — 8,476 downloads/month across npm
0/20Registry dependents — not reported by this ecosystem
Inputs used
packages@quantakrypto/mcp, @quantakrypto/core, @quantakrypto/agent, @quantakrypto/qscan, @quantakrypto/sieve, @quantakrypto/qprobe
dependents
ecosystemsnpm
total_downloads
monthly_downloads8,476
Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

43At risk · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
0/22.5Commit distribution — top contributor authored 100% of commits
1.4/13.5Contributor breadth — 1 contributors
3/10OpenSSF Scorecard: Contributors — project has 1 contributing companies or organizations -- score normalized to 3
Inputs used
bus_factor1
contributors_sampled1
top_contributor_share1
How it's scored
0/46.8Issue resolution — no issues or no data
21/38.3PR acceptance — 17/31 decided PRs merged
0/15OpenSSF Scorecard: Code-Review — Found 0/25 approved changesets -- score normalized to 0
Inputs used
merged_prs17
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs14
Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.
How it's scored
30/30Ownership backing — organization-owned
0/20Verified domain
2.2/25Owner reach — 1 followers of quantakrypto
5.3/25Track record — 4 public repos, account ~0 yr old
Inputs used
followers1
owner_typeOrganization
is_verified
owner_loginquantakrypto
public_repos4
account_age_days34
How it's scored
25/25Published & resolvable — 6 package(s) on npm
35/35Publish recency — latest publish 4 days ago
20/20Version history — 13 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packages@quantakrypto/mcp, @quantakrypto/core, @quantakrypto/agent, @quantakrypto/qscan, @quantakrypto/sieve, @quantakrypto/qprobe
ecosystemsnpm
any_deprecatedno
min_days_since_publish4

Engineering Quality

Are baseline engineering and documentation practices in place?

90Excellent · 20% of overall
How it's scored
24/24CI workflows — 7 workflow(s)
24/24Tests present
16/16Linter config — eslint.config.js
0/9.6Pre-commit hooks
6.4/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 13 out of 13 merged PRs checked by a CI test -- score normalized to 10
Inputs used
has_ciyes
has_testsyes
has_editorconfigyes
has_linter_configyes
has_precommit_configno

Documentation

90Excellent
How it's scored
30/30README
25/25Documentation directory
15/15Documentation / homepage site — https://quantakrypto.com/tools
10/10Repository description
10/10Topics — 20 topics
0/10Wiki
Inputs used
topicscrypto-agility, cryptography, harvest-now-decrypt-later, infosec, post-quantum, pqc, pqc-migration, pqc-readiness, pqcrypto, q-day, quantum, quantum-readiness, security-training, encryption-strategy, pqc-certification, cbom, mcp, post-quantum-cryptography, sbom, nist
has_wikino
homepagehttps://quantakrypto.com/tools
has_readmeyes
has_docs_diryes
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

77Good · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — no data
2.5/2.5CI-Tests — 13 out of 13 merged PRs checked by a CI test -- score normalized to 10
1.2/2.5CII-Best-Practices — badge detected: Passing
0/7.5Code-Review — Found 0/25 approved changesets -- score normalized to 0
0.8/2.5Contributors — project has 1 contributing companies or organizations -- score normalized to 3
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
5/5Fuzzing — project is fuzzed
2.5/2.5License — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
5/5Packaging — packaging workflow detected
4.5/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 9
4.5/5SAST — SAST tool detected but not run on all commits
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — no data
7.5/7.5Token-Permissions — GitHub workflow tokens follow principle of least privilege
0/7.5Vulnerabilities — 52 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate7.1
Excluded from scoring (no data or not applicable): branch_protection, signed_releases. Remaining weights renormalized.
How it's scored
35/35Direct dependencies free of known advisories — no direct dependency carries a known advisory
25/25Indirect dependencies free of known advisories — no indirect dependency carries a known advisory
0/40No advisories left outstanding — no advisory carries a publication date
Inputs used
sourceosv
advisories0
affected_packages0
assessed_packages2
unassessed_packages0
affected_by_severitynone
direct_affected_packages0
Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:@quantakrypto/mcp@0.5.2 runtime dependency closure — what installing the published package pulls in — 2 packages. Reachability is not analyzed.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

70Good · 0% of overall
How it's scored
0/45Agent instructions — no CLAUDE.md / AGENTS.md / editor rules
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 90 of 98 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share0.918
agent_instruction_files
agent_instruction_max_bytes
How it's scored
12.6/18One-command bootstrap — packages/core/test/benchmark/recall/csharp/Acme.Signing.csproj, packages/core/test/benchmark/recall/go/go.mod, packages/core/test/benchmark/recall/java/pom.xml (toolchain convention, no task runner)
22/22Automated tests
11/11Lint / format config — eslint.config.js
11/11Static type checking — packages/action/tsconfig.json, packages/agent/tsconfig.json, packages/core/tsconfig.json, packages/mcp/tsconfig.json, packages/qprobe/tsconfig.json, packages/qscan/tsconfig.json, packages/sieve/tsconfig.json, tsconfig.json
10/10Reproducible environment — Dockerfile, lockfile
0/10Demonstrated agent practice — no agent-authored commits among the last 100
8/8Automated maintenance — 2 of the last 100 commits are automated dependency updates
9/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 9
Inputs used
has_nixno
has_testsyes
lockfilespackage-lock.json
has_dockerfileyes
typed_languageyes
bootstrap_files
has_devcontainerno
has_linter_configyes
typecheck_configspackages/action/tsconfig.json, packages/agent/tsconfig.json, packages/core/tsconfig.json, packages/mcp/tsconfig.json, packages/qprobe/tsconfig.json, packages/qscan/tsconfig.json, packages/sieve/tsconfig.json, tsconfig.json
agent_commit_share0
toolchain_manifestspackages/core/test/benchmark/recall/csharp/Acme.Signing.csproj, packages/core/test/benchmark/recall/go/go.mod, packages/core/test/benchmark/recall/java/pom.xml, packages/core/test/benchmark/recall/rust/Cargo.toml
dependency_bot_commit_share0.02
How it's scored
45/45Type-checkable code — TypeScript (statically typed)
55/55Manageable file sizes — 0/454 source files over 60KB
Inputs used
primary_languageTypeScript
largest_source_bytes59,062
source_files_sampled454
oversized_source_files0
How it's scored
0/40API schema (OpenAPI/GraphQL/proto)
20/20MCP server
40/40Runnable examples — examples
Inputs used
example_dirsexamples
has_mcp_signalyes
api_schema_files

Key facts

9GitHub stars
1contributors
254commits, last 12 months
0days since last push
4releases
1bus factor
0open issues
npmpackage ecosystems

Data collection warnings

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

More detail

OpenSSF Scorecard 7.1 / 10
7.1aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-27 03:49 UTC

10Binary-Artifactsno binaries found in the repo
n/aBranch-Protectioninternal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
10CI-Tests13 out of 13 merged PRs checked by a CI test -- score normalized to 10
5CII-Best-Practicesbadge detected: Passing
0Code-ReviewFound 0/25 approved changesets -- score normalized to 0
3Contributorsproject has 1 contributing companies or organizations -- score normalized to 3
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
10Fuzzingproject is fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
10Packagingpackaging workflow detected
9Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 9
9SASTSAST tool detected but not run on all commits
10Security-Policysecurity policy file detected
n/aSigned-Releasesno releases found
10Token-PermissionsGitHub workflow tokens follow principle of least privilege
0Vulnerabilities52 existing vulnerabilities detected
Direct dependencies 9
RegistryPackageVersion constraintManifest
npm@quantakrypto/core0.5.0packages/action/package.json
npm@quantakrypto/qscan0.5.0packages/action/package.json
npm@quantakrypto/core0.5.0packages/agent/package.json
npm@quantakrypto/core0.5.0packages/mcp/package.json
npm@quantakrypto/qprobe0.5.0packages/mcp/package.json
npm@quantakrypto/core0.5.0packages/qprobe/package.json
npm@quantakrypto/agent0.5.0packages/qscan/package.json
npm@quantakrypto/core0.5.0packages/qscan/package.json
npm@noble/post-quantum^0.4.0validation/sieve-real-sut/package.json
All dependencies 214

Full resolved dependency set from the GitHub dependency graph: 6 direct and 208 indirect (transitive) packages. The transitive closure is complete when the repository commits a lockfile.

RegistryPackageVersionRelation
npm@noble/post-quantum0.4.1direct
npm@noble/post-quantum0.6.1direct
npm@quantakrypto/agent0.5.0direct
npm@quantakrypto/core0.5.0direct
npm@quantakrypto/qprobe0.5.0direct
npm@quantakrypto/qscan0.5.0direct
crates.ioanyhowindirect
crates.ioed25519-dalekindirect
crates.iohexindirect
crates.ioopensslindirect
crates.iorsaindirect
crates.ioserdeindirect
crates.ioserde_jsonindirect
crates.iotokioindirect
crates.iotracingindirect
crates.iox25519-dalekindirect
Gogithub.com/cloudflare/circlv1.3.9indirect
Gogithub.com/decred/dcrd/dcrec/secp256k1/v4v4.3.0indirect
Gogithub.com/golang-jwt/jwt/v5v5.2.1indirect
Gogolang.org/x/cryptov0.24.0indirect
Gogolang.org/x/sysv0.21.0indirect
Gogolang.org/x/termv0.21.0indirect
Mavencom.fasterxml.jackson.core:jackson-databind2.17.1indirect
Mavenio.jsonwebtoken:jjwt-api0.11.5indirect
Mavenorg.bouncycastle:bcpkix-jdk18on1.78.1indirect
Mavenorg.bouncycastle:bcprov-jdk18on1.78.1indirect
npm@esbuild/aix-ppc640.28.1indirect
npm@esbuild/android-arm0.28.1indirect
npm@esbuild/android-arm640.28.1indirect
npm@esbuild/android-x640.28.1indirect
npm@esbuild/darwin-arm640.28.1indirect
npm@esbuild/darwin-x640.28.1indirect
npm@esbuild/freebsd-arm640.28.1indirect
npm@esbuild/freebsd-x640.28.1indirect
npm@esbuild/linux-arm0.28.1indirect
npm@esbuild/linux-arm640.28.1indirect
npm@esbuild/linux-ia320.28.1indirect
npm@esbuild/linux-loong640.28.1indirect
npm@esbuild/linux-mips64el0.28.1indirect
npm@esbuild/linux-ppc640.28.1indirect
npm@esbuild/linux-riscv640.28.1indirect
npm@esbuild/linux-s390x0.28.1indirect
npm@esbuild/linux-x640.28.1indirect
npm@esbuild/netbsd-arm640.28.1indirect
npm@esbuild/netbsd-x640.28.1indirect
npm@esbuild/openbsd-arm640.28.1indirect
npm@esbuild/openbsd-x640.28.1indirect
npm@esbuild/openharmony-arm640.28.1indirect
npm@esbuild/sunos-x640.28.1indirect
npm@esbuild/win32-arm640.28.1indirect
npm@esbuild/win32-ia320.28.1indirect
npm@esbuild/win32-x640.28.1indirect
npm@eslint-community/eslint-utils4.9.1indirect
npm@eslint-community/regexpp4.12.2indirect
npm@eslint/config-array0.21.2indirect
npm@eslint/config-helpers0.4.2indirect
npm@eslint/core0.17.0indirect
npm@eslint/eslintrc3.3.5indirect
npm@eslint/js9.39.4indirect
npm@eslint/object-schema2.1.7indirect
npm@eslint/plugin-kit0.4.1indirect
npm@humanfs/core0.19.2indirect
npm@humanfs/node0.16.8indirect
npm@humanfs/types0.15.0indirect
npm@humanwhocodes/module-importer1.0.1indirect
npm@humanwhocodes/retry0.4.3indirect
npm@noble/ciphers2.2.0indirect
npm@noble/curves2.2.0indirect
npm@noble/hashes1.8.0indirect
npm@noble/hashes2.2.0indirect
npm@quantakrypto/action0.5.0indirect
npm@quantakrypto/mcp0.5.2indirect
npm@quantakrypto/observatory0.0.0indirect
npm@quantakrypto/sieve0.5.0indirect
npm@types/estree1.0.9indirect
npm@types/json-schema7.0.15indirect
npm@types/node26.1.1indirect
npm@types/node^20.12.0indirect
npm@typescript-eslint/eslint-plugin8.61.0indirect
npm@typescript-eslint/parser8.61.0indirect
npm@typescript-eslint/project-service8.61.0indirect
npm@typescript-eslint/scope-manager8.61.0indirect
npm@typescript-eslint/tsconfig-utils8.61.0indirect
npm@typescript-eslint/type-utils8.61.0indirect
npm@typescript-eslint/types8.61.0indirect
npm@typescript-eslint/typescript-estree8.61.0indirect
npm@typescript-eslint/utils8.61.0indirect
npm@typescript-eslint/visitor-keys8.61.0indirect
npmacorn8.16.0indirect
npmacorn-jsx5.3.2indirect
npmajv6.15.0indirect
npmansi-styles4.3.0indirect
npmargparse2.0.1indirect
npmbalanced-match1.0.2indirect
npmbalanced-match4.0.4indirect
npmbrace-expansion1.1.16indirect
npmbrace-expansion5.0.7indirect
npmcallsites3.1.0indirect
npmchalk4.1.2indirect
npmcolor-convert2.0.1indirect
npmcolor-name1.1.4indirect
npmconcat-map0.0.1indirect
npmcross-spawn7.0.6indirect
npmdebug4.4.3indirect
npmdeep-is0.1.4indirect
npmelliptic^6.5.4indirect
npmelliptic^6.5.5indirect
npmesbuild0.28.1indirect
npmescape-string-regexp4.0.0indirect
npmeslint9.39.4indirect
npmeslint-scope8.4.0indirect
npmeslint-visitor-keys3.4.3indirect
npmeslint-visitor-keys4.2.1indirect
npmeslint-visitor-keys5.0.1indirect
npmespree10.4.0indirect
npmesquery1.7.0indirect
npmesrecurse4.3.0indirect
npmestraverse5.3.0indirect
npmesutils2.0.3indirect
npmexpress^4.18.0indirect
npmexpress^4.19.2indirect
npmfast-check4.9.0indirect
npmfast-deep-equal3.1.3indirect
npmfast-json-stable-stringify2.1.0indirect
npmfast-levenshtein2.0.6indirect
npmfdir6.5.0indirect
npmfile-entry-cache8.0.0indirect
npmfind-up5.0.0indirect
npmflat-cache4.0.1indirect
npmflatted3.4.2indirect
npmfsevents2.3.3indirect
npmglob-parent6.0.2indirect
npmglobals14.0.0indirect
npmhas-flag4.0.0indirect
npmignore5.3.2indirect
npmignore7.0.5indirect
npmimport-fresh3.3.1indirect
npmimurmurhash0.1.4indirect
npmis-extglob2.1.1indirect
npmis-glob4.0.3indirect
npmisexe2.0.0indirect
npmjs-yaml4.3.0indirect
npmjson-buffer3.0.1indirect
npmjson-schema-traverse0.4.1indirect
npmjson-stable-stringify-without-jsonify1.0.1indirect
npmjsonwebtoken^9.0.0indirect
npmjsonwebtoken^9.0.2indirect
npmkeyv4.5.4indirect
npmlevn0.4.1indirect
npmlocate-path6.0.0indirect
npmlodash^4.17.21indirect
npmlodash.merge4.6.2indirect
npmminimatch10.2.5indirect
npmminimatch3.1.5indirect
npmms2.1.3indirect
npmnatural-compare1.4.0indirect
npmnode-forge^1.3.1indirect
npmoptionator0.9.4indirect
npmp-limit3.1.0indirect
npmp-locate5.0.0indirect
npmparent-module1.0.1indirect
npmpath-exists4.0.0indirect
npmpath-key3.1.1indirect
npmpicomatch4.0.4indirect
npmpino^9.2.0indirect
npmprelude-ls1.2.1indirect
npmprettier3.8.3indirect
npmpunycode2.3.1indirect
npmpure-rand8.4.2indirect
npmresolve-from4.0.0indirect
npmsemver7.8.3indirect
npmshebang-command2.0.0indirect
npmshebang-regex3.0.0indirect
npmstrip-json-comments3.1.1indirect
npmsupports-color7.2.0indirect
npmtinyglobby0.2.17indirect
npmts-api-utils2.5.0indirect
npmtsx4.23.1indirect
npmtype-check0.4.0indirect
npmtypescript5.9.3indirect
npmtypescript^5.4.5indirect
npmtypescript-eslint8.61.0indirect
npmundici-types8.3.0indirect
npmuri-js4.4.1indirect
npmwhich2.0.2indirect
npmword-wrap1.2.5indirect
npmyocto-queue0.1.0indirect
NuGetBouncyCastle.Cryptography2.4.0indirect
NuGetNewtonsoft.Json13.0.3indirect
NuGetSystem.IdentityModel.Tokens.Jwt7.5.1indirect
PyPIcryptographyindirect
PyPIcryptography49.0.0indirect
PyPIfastapi0.110.1indirect
PyPIparamikoindirect
PyPIprometheus-client0.20.0indirect
PyPIpycryptodome3.20.0indirect
PyPIpycryptodome3.23.0indirect
PyPIpydantic-settings2.2.1indirect
PyPIpyjwtindirect
PyPIpyopensslindirect
PyPIpython-dotenv1.0.1indirect
PyPIrequestsindirect
PyPIrequests2.34.2indirect
PyPIstructlog24.1.0indirect
PyPIuvicorn0.29.0indirect
RubyGemsed25519indirect
RubyGemsjwtindirect
RubyGemsnet-sshindirect
RubyGemspgindirect
RubyGemspumaindirect
RubyGemsrailsindirect
RubyGemsrbnaclindirect
RubyGemsrspec-railsindirect
RubyGemsrubocopindirect
Dependency advisories 0

Installing npm:@quantakrypto/mcp@0.5.2 pulls in 2 packages, direct and transitive: 0 carry known advisories, of which 0 are direct dependencies.

No known advisories affect the assessed dependencies.

An advisory means the version recorded in the dependency graph falls inside an advisory’s affected range. Reachability is not analysed, and the graph includes development and test pins — a finding may concern tooling rather than shipped software.

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [
        "crypto-agility",
        "cryptography",
        "harvest-now-decrypt-later",
        "infosec",
        "post-quantum",
        "pqc",
        "pqc-migration",
        "pqc-readiness",
        "pqcrypto",
        "q-day",
        "quantum",
        "quantum-readiness",
        "security-training",
        "encryption-strategy",
        "pqc-certification",
        "cbom",
        "mcp",
        "post-quantum-cryptography",
        "sbom",
        "nist"
      ],
      "is_fork": false,
      "size_kb": 2378,
      "has_wiki": false,
      "homepage": "https://quantakrypto.com/tools",
      "languages": {
        "C": 11808,
        "C#": 13339,
        "Go": 13560,
        "HCL": 448,
        "PHP": 259,
        "Java": 9201,
        "Ruby": 9206,
        "Rust": 11638,
        "Bicep": 214,
        "Shell": 1100,
        "Swift": 110,
        "Kotlin": 2093,
        "Python": 18432,
        "Dockerfile": 1319,
        "JavaScript": 146066,
        "TypeScript": 1911224
      },
      "pushed_at": "2026-07-26T17:47:28Z",
      "created_at": "2026-06-09T04:17:00Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-26T17:47:47Z",
      "description": "Open-source post-quantum readiness tooling by quantakrypto",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": "https://quantakrypto.com",
      "name": "@QuantaKrypto",
      "type": "Organization",
      "login": "quantakrypto",
      "company": null,
      "location": "Switzerland",
      "followers": 1,
      "avatar_url": "https://avatars.githubusercontent.com/u/295786989?v=4",
      "created_at": "2026-06-22T08:34:25Z",
      "is_verified": null,
      "public_repos": 4,
      "account_age_days": 34
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v1",
          "kind": "other",
          "published_at": "2026-07-23T05:57:13Z"
        },
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2026-07-20T15:46:31Z"
        },
        {
          "tag": "v0.4.4",
          "kind": "patch",
          "published_at": "2026-07-19T08:10:54Z"
        },
        {
          "tag": "v0.4.3",
          "kind": "patch",
          "published_at": "2026-07-15T18:46:08Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "409726240647384572233737a78f2a66bd9854d1",
          "body": "…lockfile depth, parallel double-stat) (#38)\n\nFour post-1.0-roadmap detection items on the benchmark-guarded surface.\nThe F1 = 1.000 precision/recall benchmark is unchanged (zero FP, zero FN).\n\n- PHP composer.json / composer.lock dependency scanning: add `composer` to\n  DependencyEcosystem, a curate\n[…]\nrf; file set and detection output are byte-identical.\n\nRebuilds the action bundle. Full gate green (test, typecheck, lint, api:check,\nformat:check).\n\nCo-authored-by: León Acosta <laion.cj91@gmail.com>",
          "is_bot": false,
          "headline": "feat(core): detection quick-wins (PHP composer, JS recall edges, npm …",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-26T17:47:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9a8b0e6f5f620a4aebcc1a18e1766355189b0802",
          "body": "…(#37)\n\nQuantify harvest-now-decrypt-later exposure so the migration backlog ranks by\nreal risk instead of finding counts. Exposure per finding =\ncrypto-vulnerability x data-sensitivity x Mosca-factor (retention + secrecy\nlifetime vs the quantum-threat horizon; Mosca's inequality made concrete).\n\nco\n[…]\nrprintFinding().\n\nSemVer: minor (additive API + CLI). Tests: parser, glob, binding, Mosca math,\nsummary, scaffold, CLI wiring. api:docs regenerated.\n\nCo-authored-by: León Acosta <laion.cj91@gmail.com>",
          "is_bot": false,
          "headline": "feat(hndl): data-risk quantifier (hndl.yml, qscan --hndl, hndl init) …",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-26T17:27:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dcaf36631a8664ef3ad03fd1b6e542a46b9d6bdf",
          "body": "Every finding in the qScan --format json output now carries a top-level\nfingerprint field, and each SARIF result mirrors it in properties.fingerprint\nalongside the existing partialFingerprints. The value reuses the baseline\nidentity fingerprintFinding: sha256(ruleId | normalized POSIX repo-relative\n\n[…]\ntinctness across rule/path/\ncontext, the rule+path fallback, cross-format equality (JSON = SARIF =\nbaseline), and stability under snippet redaction.\n\nCo-authored-by: León Acosta <laion.cj91@gmail.com>",
          "is_bot": false,
          "headline": "core: stable finding fingerprints in JSON and SARIF output (#36)",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-26T17:22:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9e73eb43a2fafd1922746309b664a5d0afdd5277",
          "body": "…m the scan\n\nmanifests were exempt from the file-size cap entirely; a hostile or broken\nlockfile could be read unbounded. give them a generous 16 MiB ceiling instead\n(real monorepo lockfiles are well under it). pure size logic, no detection change.",
          "is_bot": false,
          "headline": "fix(core): cap manifest read size so a pathological lockfile can't oo…",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-26T15:45:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2c4dc93b0637a2f9d252c6e318863bcd976ed230",
          "body": "everything the backlogs tracked as P0/P1 has shipped (0.5.x: 52 detectors,\n14 languages, qprobe, openvex, standards profiles, frozen api). what's left is\naccuracy nice-to-haves, the declarative detector factory, perf, and a golden-file\ncorpus. reconciled against the code 2026-07-26.",
          "is_bot": false,
          "headline": "docs: reconciled post-1.0 roadmap (supersedes the old audit backlogs)",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-26T15:45:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c68538aad98554ccd772906da533063ed2e14162",
          "body": null,
          "is_bot": false,
          "headline": "docs: version-support policy for the 0.5.x packages + the v1 action tag",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-26T15:45:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a4b5f48fa7eabd291dfac2cdeb054188184eb7ad",
          "body": "…ity vs cryptodeps\n\nadds tink across com.google.crypto.tink (maven), tink-crypto/tink-go +\ngoogle/tink/go (go), and pypi tink. flagged as rsa/ecdsa/eddsa signatures\nplus ecies hybrid, so hndl-exposed. catalog now 81 entries.\n\ncrypto-js stays out on purpose: it is symmetric/hash/hmac/pbkdf2 only, no\nasymmetric public-key surface, same scope boundary as the password kdfs.\ncomparison doc updated to reflect full parity on the pubkey packages\ncryptodeps documents. re-bundled the action dist.",
          "is_bot": false,
          "headline": "feat(core): catalog google tink (maven/go/pypi); note full pubkey par…",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-26T15:44:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0bd18cb4d42fb129aa3dd8f3f37a0dbf7da9712d",
          "body": "two head-to-head comparisons with verified coverage: algorithm matrix,\necosystem/package parity, extras and honest gaps vs cryptodeps, plus the\nfips 203/204/205, sp 800-208, cnsa 2.0 and ir 8547 mapping vs nist.\ncounts verified against the built registry and dep catalog, not prose.",
          "is_bot": false,
          "headline": "docs: add comparison vs qramm/cryptodeps and vs nist",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-26T15:44:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1a0aac3fc77fcf9520a27e4f7c51f5f9f0640655",
          "body": "* docs: fix dead links, stale versioning note, and API-reference doc extraction\n\n- SUPPLY-CHAIN.md: repair the broken COMPLIANCE.md §5 link and an unfinished sentence\n- ADRs 0003/0005: point OBJECTIVES.md links at ../OBJECTIVES.md so they resolve\n- VERSIONING.md: drop the specific stale version numb\n[…]\nlve re-exported symbols' kind/summary from\n  their source module. Regenerated API.md (276/331 summaries now correct; surface\n  snapshot unchanged).\n\n* docs: fix unfinished 'See and' phrase in ADR 0005",
          "is_bot": false,
          "headline": "docs: fix unfinished 'See and' phrase in ADR 0005 (#35)",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-26T15:42:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "27ad3e3f10f339545be148d4244a7a8e84d9cf44",
          "body": "…traction (#34)\n\n- SUPPLY-CHAIN.md: repair the broken COMPLIANCE.md §5 link and an unfinished sentence\n- ADRs 0003/0005: point OBJECTIVES.md links at ../OBJECTIVES.md so they resolve\n- VERSIONING.md: drop the specific stale version numbers (pre-1.0, 0.x range)\n- gen-api-reference.mjs: anchor doc sum\n[…]\nolve re-exported symbols' kind/summary from\n  their source module. Regenerated API.md (276/331 summaries now correct; surface\n  snapshot unchanged).\n\nCo-authored-by: León Acosta <laion.cj91@gmail.com>",
          "is_bot": false,
          "headline": "docs: fix dead links, stale versioning note, and API-reference doc ex…",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-26T15:37:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a921a52c6e6a8d6cb9382a711b6573156ef33068",
          "body": "chore: move the observatory worker to its own repository",
          "is_bot": false,
          "headline": "Merge pull request #33 from quantakrypto/chore/remove-observatory",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-25T03:26:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "74cec18da463e58ed805258009103b469c8f57fd",
          "body": "The PQC observatory worker now lives at github.com/quantakrypto/pqc-observatory,\na self-contained repo that probes public hosts via openssl (it must not depend on\nqProbe, which is ownership-gated for endpoints you control). Removed from here:\npackages/observatory, ADR 0007, the root observatory script, and the pg devDep.",
          "is_bot": false,
          "headline": "chore: move the observatory worker to its own repository",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-25T03:15:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e7d35f4f5b15252f45e217a05eb15fbd6da50a0e",
          "body": "Observatory: internal PQC-readiness probe worker (ADR 0007)",
          "is_bot": false,
          "headline": "Merge pull request #32 from quantakrypto/feat/observatory-worker",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-25T02:44:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ba8063706e85acc49fdb268b81af3d18fe21976d",
          "body": null,
          "is_bot": false,
          "headline": "docs: OpenSSF Best Practices pre-filled answers",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-25T02:37:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c0f88aeeae962a56770bc0420d02cc1eccb7224c",
          "body": "Adds packages/observatory (private, unpublished): a monthly worker that probes a\nfixed panel of public hosts for PQC-hybrid key exchange (X25519MLKEM768) and\ncertificate posture, writing idempotent per-month results and a rollup to\nPostgres for the site's public /observatory page.\n\nReuses qProbe's u\n[…]\n. See docs/adr/0007.\n\nThe published packages are untouched: qprobe unchanged, zero-runtime-dependency\nand offline-boundary invariants still hold. pg is a devDependency of the\nobservatory package only.",
          "is_bot": false,
          "headline": "feat(observatory): internal PQC-readiness probe worker + ADR 0007",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-25T02:37:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "008333afb319a993c8b0f9d16c2277ae1b8da3dd",
          "body": null,
          "is_bot": false,
          "headline": "docs: add OpenSSF Best Practices passing badge (#31)",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-24T02:18:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e68ab13934111dfc9c7fa5ee8ee5669979103093",
          "body": "- qprobe/mlkem768: replace biased modulo sampling with unbiased rejection\n  sampling for the throwaway probe key (js/biased-cryptographic-random)\n- sieve/protocol fromB64: replace the /=+$/ trailing-trim (O(n^2) on the\n  untrusted SUT response) with a linear scan (js/polynomial-redos)\n- mcp/http: di\n[…]\nests pass, including the property-based fuzz tests on the patched\nparsers. Trailing-slash trims on trusted config input (walk globs, agent\nbaseURL) are dismissed separately as not attacker-controlled.",
          "is_bot": false,
          "headline": "fix(security): resolve CodeQL findings in untrusted-input paths (#30)",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T10:44:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1e2991cc568d1225ae134a323a5dd68b8f731841",
          "body": "Add fast-check (dev-only) property tests that fuzz the parsers that consume\nattacker-controlled bytes: qProbe's TLS ServerHello / record / SSH KEXINIT /\nX.509 OID decoders, and Sieve's SUT response decoder. Each runs thousands of\nrandom inputs asserting the robustness contract (safe wrappers never t\n[…]\nhrow only their typed error, never a raw crash). All green,\nso the parsers hold; the tests stand as a regression guard and satisfy the\nOpenSSF Scorecard fuzzing criterion. No runtime dependency added.",
          "is_bot": false,
          "headline": "test: property-based fuzzing of the untrusted-input parsers (#29)",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T10:17:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e769591f56bef2b4bb30401d7c29836b9b7cd7a5",
          "body": "* ci: add CodeQL SAST workflow (pinned)\n\n* ci: move packages:write to job scope (least-privilege top level)",
          "is_bot": false,
          "headline": "ci: add CodeQL SAST workflow (#28)",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T08:51:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b346991abc40eef0fa3d13f84e5ba1b7d714bec4",
          "body": "Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 1.1.15 to 1.1.16.\n- [Release notes](https://github.com/juliangruber/brace-expansion/releases)\n- [Commits](https://github.com/juliangruber/brace-expansion/compare/v1.1.15...v1.1.16)\n\n---\nupdated-dependencies:\n- dependency-n\n[…]\non\n  dependency-version: 1.1.16\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "deps: bump brace-expansion from 1.1.15 to 1.1.16 (#26)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-23T08:27:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c6822434ebae7fcb5f96a416d96b3b5ae93e89f0",
          "body": "Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.2.0 to 4.3.0.\n- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)\n- [Commits](https://github.com/nodeca/js-yaml/compare/4.2.0...4.3.0)\n\n---\nupdated-dependencies:\n- dependency-name: js-yaml\n  dependency-version: 4.3.0\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "deps: bump js-yaml from 4.2.0 to 4.3.0 (#20)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-23T08:27:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7918654d8e3073d5c90fbd44a22e06f2533ffe67",
          "body": "…thub.com)",
          "is_bot": false,
          "headline": "mirror container + npm packages to github packages (ghcr + npm.pkg.gi…",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T06:33:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7f18694debd4960bfb23da4bc2d37aebed4c52ff",
          "body": null,
          "is_bot": false,
          "headline": "bump docker image to @quantakrypto/mcp 0.5.2",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T06:12:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7e67f89ca3f6145968b281c9e5c0b61ec4b97bf6",
          "body": null,
          "is_bot": false,
          "headline": "make mcp-registry publish idempotent (skip already-published version)",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T06:01:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4c6acc5d7ad2adc95434585c352818ec915af533",
          "body": "… em dash",
          "is_bot": false,
          "headline": "shorten root action description under 125 chars for marketplace, drop…",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T05:31:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3ac2632582f46ef0bd7e7bd118d7dbdc3632c178",
          "body": null,
          "is_bot": false,
          "headline": "add root action.yml so the action can list on the github marketplace",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T05:18:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bc6f17d4e5de400c2534d595886273c850eedcf8",
          "body": null,
          "is_bot": false,
          "headline": "add 400x400 logo for marketplace/directory listings",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T05:15:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "192dd4c4153d21e79929d234b246198b855e62ce",
          "body": "…rver",
          "is_bot": false,
          "headline": "add root .mcp.json so cursor / open-plugins clients can import the se…",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T03:58:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6264359813afcda7eb217ceca17e10130cba0414",
          "body": null,
          "is_bot": false,
          "headline": "shorten server.json description to fit the registry 100-char limit",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T03:38:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f134a0efdc802e5d96cce9717c9e86b2fc4bde1a",
          "body": "runs mcp-publisher with github-oidc auth, so the io.github.quantakrypto namespace\nis authorized by the org's own actions token. no keys, no interactive login.",
          "is_bot": false,
          "headline": "add workflow to publish server.json to the mcp registry via oidc",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T03:36:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6147d56bb6432648d494e1243ccad09bbe765c56",
          "body": "the mcp registry verifies npm ownership by reading an mcpName field from the\nPUBLISHED package.json, so we ship a tiny 0.5.2 that adds it plus a server.json\n(namespace io.github.quantakrypto/pqc-tools, npm stdio package + the hosted\nstreamable-http remote). metadata only, no code change. after this publishes,\nlisting on the registry is just: mcp-publisher login github && mcp-publisher publish.",
          "is_bot": false,
          "headline": "mcp 0.5.2: add mcpName + server.json for the official mcp registry",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T03:32:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4dbf1446a1f4afaf6f8183cffebb8a9736899a5d",
          "body": "- tool input schemas: every array field (findings/verdicts, score_delta\n  before/after) now has an 'items' object schema instead of a bare type:array.\n  mcp inspectors flag the bare form ('missing items definition') and it drags\n  the tool-definition-quality score.\n- bump @quantakrypto/mcp to 0.5.1 + changelog. pairs with the already-landed\n  resources/templates/list fix (ed6ecfd). package-only patch — core/qscan/etc\n  stay 0.5.0 (unreleased work still parked under [Unreleased]).",
          "is_bot": false,
          "headline": "mcp 0.5.1: describe tool array items, cut patch release",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T02:24:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ed6ecfdf3452c0563624a260f2dd42ad784f851a",
          "body": "the server advertises the 'resources' capability, so spec-compliant clients\n(and mcp directory health checks like glama's inspector) call\nresources/templates/list during discovery. we only expose fixed-uri resources,\nno uri templates — but we were falling through to -32601 method-not-found, which\ntrips those clients. return an empty { resourceTemplates: [] } instead.\n\nadded a test asserting it succeeds empty rather than erroring.",
          "is_bot": false,
          "headline": "handle resources/templates/list instead of 404ing discovery",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T01:31:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7c58bc376dd6bd3ac7bf54d9f04018b428b3863c",
          "body": "the recall/corpus benchmark ships fake dependency manifests (pom.xml, go.mod,\ncargo.toml, requirements.txt, csproj, gemfile, package.json...) with pinned deps\non purpose — thats the test data for crypto-dependency detection. when one of\nthose pinned versions gets a security advisory (jackson-databin\n[…]\ncore).\n\nscope each fixture ecosystem under packages/core/test/benchmark/** with\nlimit 0 + ignore '*' so dependabot leaves the test corpus alone. real dev deps\n(npm at /) and action SHAs are untouched.",
          "is_bot": false,
          "headline": "stop dependabot from failing on scanner test fixtures",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-23T00:47:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "33b823beb2e8dbdce12efe3eef7f17de3f9ce252",
          "body": "glama (and other mcp hosts) sandbox the server: they run initialize +\ntools/list over stdio and expect a valid reply. this image installs the\npublished @quantakrypto/mcp and starts the stdio transport, so that check\npasses. base image + package are both pinned; glama.json claims the listing.\nbump both pins on release.",
          "is_bot": false,
          "headline": "add dockerfile + glama.json for mcp directory listing",
          "author_name": "Leon Acosta",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-22T17:16:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e6cca652a7e4f929c7d81b31501bcf3a72690295",
          "body": "the hosted MCP gateway described as future work in HOSTING.md now exists and runs in\nproduction (quantakrypto/mcp-gateway, live at mcp.quantakrypto.com). add:\n- HOSTING.md: a reference-implementation callout up top + note on §3 that oauth 2.1 is\n  what the gateway implements (better-auth, 30-day tok\n[…]\nant to use it?\" callout with the `claude mcp add --transport http` command,\n  the content-only tool surface (fs/network tools withheld), and the gateway repo link.\ndocs only; no code/behaviour change.",
          "is_bot": false,
          "headline": "docs(mcp): point HOSTING + README at the now-live hosted gateway",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-22T04:12:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a895f0a8b4e125f8df672a3d9e5e22b58d8ca612",
          "body": "…e dir as a module\n\n`node --test scripts/test/` (a directory arg) runs the tests on node 20, but on node\n21+ the runner resolves the path as a module and fails with \"Cannot find module\n.../scripts/test\", reddening build+test on the node 22 matrix leg. use\n`scripts/test/*.test.mjs` — shell-expanded to the literal file, exactly like the\nper-workspace `test/*.test.ts` scripts already do — which both node versions run.",
          "is_bot": false,
          "headline": "fix(test): explicit glob for test:scripts so node 22 doesn't treat th…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-21T03:42:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fb3eecc23f4e8bba6916fbe8f29e843e28acb2ac",
          "body": "… EPIPE\n\nthe evidence signer (--sign/--timestamp) shells out via spawnSync with the payload on\nstdin. a command that exits before draining stdin (e.g. `false`) makes spawnSync\nsurface an EPIPE in res.error on linux — not macos — even though the child ran and\nreturned an exit status. the old code che\n[…]\nt a non-zero exit status (or terminating signal) FIRST; only fall back to\nres.error for a genuine spawn failure (e.g. ENOENT). deterministic across platforms.\naction dist re-bundled (it embeds qscan).",
          "is_bot": false,
          "headline": "fix(sign): report a signer's non-zero exit before an incidental stdin…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-21T03:38:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e397c9e6f06f7c6e190bcbd5857fea0e18907880",
          "body": null,
          "is_bot": false,
          "headline": "chore(action): re-bundle dist for the 0.5.0 release",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T15:46:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d7917f17c20ee7287a9427f03eaf3a30e449e11b",
          "body": null,
          "is_bot": false,
          "headline": "docs: design for hosted OAuth-gated multi-tenant MCP gateway",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T14:27:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ede29ffa0abc3c385a2ff18b246875433e7a9775",
          "body": "Per the cleanup request: remove point-in-time audit process artifacts and\nplanning docs, keep the enduring standards/reference/decision documentation, and\nadd a clear statement of what each library is for and what we're building toward.\n\nRemoved (in the previous commit): docs/audits/, docs/AUDIT.md,\n[…]\nMODEL (§8 controls table + the agent-line note refreshed to\nthe completed/fixed status), COMPLIANCE, CONFIG, SECURITY, CONTRIBUTING, and the\nGitHub templates — no broken links to removed files remain.",
          "is_bot": false,
          "headline": "docs: prune audit logs & plans; add OBJECTIVES; fix cross-references",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T12:54:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b2d28b1b7a8290bf8271ff5e7074949e5f75bd0d",
          "body": "…leanup\n\nDetector fixes (each with a regression test; suite 1118 -> 1123):\n- proxy (H1/H2/L1/L2): the global marker gate was too narrow, silently dropping\n  canonical HAProxy (bind ssl crt, no crt-store) and Traefik (certFile/keyFile,\n  no certResolver) configs. Replaced with per-rule self-gating; E\n[…]\n, plans, and 0.4 runbook (docs/audits/,\nAUDIT.md, ROADMAP.md, how-to-test-0.4.md, superpowers/) — the enduring 'why' is\nin the ADRs; the new OBJECTIVES.md + index rewrite land in the follow-up commit.",
          "is_bot": false,
          "headline": "fix: adversarial-audit findings in the 5 new detectors + begin docs c…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T12:48:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a36bd28b8537e7f6a5970afb5ef52124d4e5faf3",
          "body": "…/gRPC TLS, code-signing, weak-hash\n\nFresh coverage-gap research (3 Fable agents: assess + 2 web-research passes)\nidentified high-value PQC surfaces the scanner missed. Adds 5 detectors\n(47->52 detectors, 277->297 rules), scope kept to PQC + quantum-adjacent:\n\n- solidity: 14th source language pack (\n[…]\nassword hashing.\n\nEach with self-contained tests; benchmark F1=1.000, zero FP held. Wired into\nregistry + coverage constants + comment table; docs/README/ROADMAP/CHANGELOG\nupdated. Suite 1065 -> 1118.",
          "is_bot": false,
          "headline": "feat: 5 new detection surfaces — Solidity/blockchain, WebAuthn, proxy…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T12:33:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a17925014e030608025c7c20cabd453b0f736f65",
          "body": "…ant test\n\nAssessment (Fable) found two of my new packs under-reported HNDL, re-introducing\naudit bug P0-4: objc-seckey-ec and Dart ECKeyGenerator classified ambiguous EC\nkeygen as signature/ECDSA/hndl:false, while the whole fleet (java/python/c/swift/\ncloud-kms/ruby EC keygen) uses the HNDL-safe ke\n[…]\ns JWT coverage (added to JWT_HOST_EXTENSIONS); cloud-kms\nmasks comments so a commented-out YAML/JSON KeySpec can't fire; fixed the stale\n'JS/TS, Python, Go, Java' analyzable-languages doc in types.ts.",
          "is_bot": false,
          "headline": "fix: restore fleet HNDL convention for EC keygen + add catalog invari…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T12:22:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8a1912474845689e60b42fe989db0b697d630c08",
          "body": "…n barrel\n\nstandardsReviewStatus is exported by standards.ts but NOT re-exported by the\npublic index.js barrel, so standards-check.mjs crashed on import ('does not\nprovide an export'). Because the standards-currency step is advisory\n(continue-on-error), the crash went unnoticed in CI. Import both symbols from\nthe standards.js subpath. Add a build-aware smoke test to the guard suite so an\nimport regression can't silently break this advisory gate again.",
          "is_bot": false,
          "headline": "fix(standards-check): import from standards.js subpath, not the froze…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T09:28:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0f029ee1b20c3aa7ceb39ed62417f634b5d4076d",
          "body": "… + counts\n\n- ADR-0005 + THREAT-MODEL: F1 (blast-radius gate), F2 (system-role instruction/\n  data separation), F3 (--max-findings spend cap) are fixed in code — mark them\n  resolved instead of open, consistent with ROADMAP §1 (verified in loop.ts,\n  remediate-pipeline.ts, triage-run.ts).\n- COMPLIAN\n[…]\nd; 0.4.4 published) across COMPLIANCE,\n  VERSIONING, AUDIT, SUPPLY-CHAIN; test-count and 'supported vs benchmark-corpus\n  languages' wording refreshed; CHANGELOG Fixed section for the audit hardening.",
          "is_bot": false,
          "headline": "docs: reconcile ADR-0005/THREAT-MODEL (F1-F3 fixed), refresh versions…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T09:26:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "adaaa20f803d3dbc7544f867636a133723cc2cf4",
          "body": "Detectors:\n- ssh-ca: add ssh-ca-config rule for TrustedUserCAKeys/HostCertificate/ssh-keygen\n  -s — the canonical CA deployment previously yielded ZERO findings (H6); stop\n  firing on program SOURCE files, so a vendored SSH lib's cert-type constant is\n  not flagged as live config (M4).\n- spire: matc\n[…]\n (file:src/a.ts#L3) (M7); the @id digest\n  includes triage status_notes so triaged/untriaged exports get distinct ids (L1).\n\nAll with regression tests. Suite 1052 -> 1063; benchmark F1=1.000, zero FP.",
          "is_bot": false,
          "headline": "fix: adversarial-audit findings in detectors, CBOM, and VEX",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T09:21:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9dc164c054073ff4e842c9c0b662a87cb8afd244",
          "body": "…3, M6)\n\nThe line-by-line + sequential-regex guard was bypassable by ORDINARY code, so\nADR-0005's 'enforced by CI' claim was false. Rewrite with a single-pass lexer\n(code/string/comment classification, recursing into template ${…} as code) and\nwhole-file scanning with index->line mapping:\n- C1: Pret\n[…]\n: auto-merge runs on comment-stripped text, so a // gh pr merge note no\n  longer false-positives; real exec('gh pr merge') strings still fire.\nRegression tests pin every bypass. Real repo stays clean.",
          "is_bot": false,
          "headline": "fix(guard): make offline-boundary bypass-resistant (audit C1-C3, H1-H…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T09:09:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f550df96e8091c3cfc0e60aad84039f8991ad156",
          "body": "ADR-0005's no-auto-merge rule covers workflows, not just package source. Extend\nthe guard to scan .github/workflows/*.yml for gh-pr-merge/--admin, with a\nknown-bad-fixture test. Workflows are currently clean.",
          "is_bot": false,
          "headline": "test: offline-boundary guard also scans workflows for auto-merge",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T08:57:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4f206c81f351977ad552485b798cc645c743a7c7",
          "body": "Closes the post-1.0 coverage gaps:\n- objc-crypto (.m/.mm): Apple Security-framework SecKey* RSA/EC keygen, RSA/ECDSA\n  signing, RSA encryption, ECDH — gated off .h to avoid C/C++ overlap.\n- dart-crypto (.dart): pointycastle + package:cryptography RSA/ECDSA/ECDH/Ed25519/X25519.\n- dkim-crypto: classic\n[…]\n1.000, zero FP). Repointed the coverage-honesty tests\noff .m/.dart (now supported) to genuinely-unsupported Lua/Perl. Docs updated\n(core README language table, ROADMAP, CHANGELOG). Suite 1002 -> 1052.",
          "is_bot": false,
          "headline": "feat: coverage packs — Objective-C, Dart, DKIM, SSH-CA, SPIFFE/SPIRE",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T08:54:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d4a660c018f4ca964b0479c7b57cc04abedfece4",
          "body": "Adds scripts/check-offline-boundary.mjs — the gate ADR-0005 called for but that\n'did not exist yet'. It enforces the two-plane split by masked source scan:\ncore/mcp/sieve import no @quantakrypto/agent, make no outbound fetch/WebSocket/XHR\ncall, and read no LLM API key; qscan reaches the agent ONLY v\n[…]\n\n(e.g. core's redaction patterns). Wired into ci.yml + supply-chain-audit.yml;\nreject logic covered by known-bad fixtures in guards.test.mjs. ADR-0005 +\nROADMAP updated to reflect the gate now exists.",
          "is_bot": false,
          "headline": "feat: CI-enforce the ADR-0005 offline/agent boundary",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T08:38:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6511bcba849a3680b5720293ed71ecd9e612c59c",
          "body": "The CycloneDX CBOM labelled every asset 'algorithm'. Now each finding is\nclassified into its proper CycloneDX 1.6 assetType: X.509 findings ->\ncertificate; private/public key material -> related-crypto-material (typed\nprivate-key/public-key); TLS -> protocol (protocolProperties.type tls);\neverything\n[…]\nhanged algorithmProperties. Every asset\nstill carries quantumVulnerable/harvestNowDecryptLater. Completes the refinement\nthe CBOM audit deferred. Grouping is now (assetType, algorithm, discriminator).",
          "is_bot": false,
          "headline": "feat: refine CBOM assetType (certificate / key-material / protocol)",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T08:32:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "691d02c5e8123ca734cf582d1b679e26dbcb50c2",
          "body": "Emit the quantum-readiness posture as an OpenVEX 0.2.0 document so it flows into\nthe same supply-chain pipeline that already ingests CVE-based VEX. One statement\nper rule (synthetic QK-<ruleId> vulnerability, since PQC findings have no CVE),\nevery affected file:line product, status 'affected', the r\n[…]\nnly an operator can attest a mitigation). Deterministic output.\n\nNew core API toOpenVex + OpenVex* types; qScan --format vex / renderVex; help,\nqscan README, and CHANGELOG updated. Surface 326 -> 331.",
          "is_bot": false,
          "headline": "feat: OpenVEX 0.2.0 export (--format vex)",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T08:28:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4c03731db39cbb43d8a91dc0b7ec1fcade55f747",
          "body": "Records the toolkit-export decision the audit flagged: the frozen external\nplugin point is the public Detector interface + scan({detectors}) / RuleMeta /\nFinding types; the lexical helpers (findingFromRule, eachMatch, comment maskers)\nstay INTERNAL so their signatures aren't frozen at 1.0 (exporting later is\nadditive). Clarifies the 'Adding a detector' guide is for in-repo contributors,\nresolving the read that external authors should import findingFromRule.",
          "is_bot": false,
          "headline": "docs: settle the detector plugin surface for the 1.0 freeze",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T08:13:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9dc5241fdc20fdbb701c7939dce7b90e5f9dde79",
          "body": "… A.8.24\n\nROADMAP current-status count ~930 -> ~985 (historical audit figures left as-is).\nAdds a note to the A.8.24 evidence doc that verifyReadinessReport recomputes the\nintegrity hash to detect body tampering independently of the external signature.",
          "is_bot": false,
          "headline": "docs: refresh current test count + document verifyReadinessReport for…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T08:12:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0143fc1c1d9aa17d93a1eb66fa146aa91320db67",
          "body": null,
          "is_bot": false,
          "headline": "docs(changelog): note verifyReadinessReport API + test-hardening pass",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T08:05:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c4b541845dbed7653698d6405588f6744e1ad32e",
          "body": "The anthropic/openai adapters had happy-path + one HTTP-error test but nothing\nfor the transport failure modes a BYOK integration actually hits. Add, to both:\na timeout that aborts a hung request via the AbortSignal, a propagated network\n(fetch-rejection) error, and — the load-bearing BYOK security \n[…]\n that\nthe API key travels ONLY in its auth header (x-api-key / Bearer) and never\nleaks into the request URL or body. Also gives the openai adapter the HTTP-error\ntest it was missing. Suite 979 -> 986.",
          "is_bot": false,
          "headline": "test: agent BYOK adapter error paths + API-key-only-in-header invariant",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T08:05:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "60d7d6a188b1244701529bc2d1d8b6c5b2d5020d",
          "body": "The supply-chain / output guards (check-zero-deps, check-action-pins,\nvalidate-sarif) run as standalone CI steps, so nothing proved their FAILURE\npath still works — a guard whose reject logic silently broke would leave CI\ngreen while the invariant eroded. Add scripts/test/guards.test.mjs with\nknown-\n[…]\nd it\nto match check-action-pins.mjs; the CLI behaviour is unchanged.\n\nWired via a new root `test:scripts` (node --test), chained into `npm test` so\nCI's existing test step covers it. Suite 951 -> 979.",
          "is_bot": false,
          "headline": "test: cover the CI guard scripts + fix validate-sarif import side effect",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T08:01:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8d1e160d62558fc9b7f83a8e510e9c36c7eabb37",
          "body": "stateful-hbs was the only built-in detector with no dedicated unit test. Add\none covering each distinctive token (LMS/HSS/pyhsslms/XMSS/XMSSMT/xmss_keypair),\nthe SP 800-208 SHAKE256 + 192-bit parameter variants, the XMSS-vs-XMSSMT\nno-double-count boundary, the bare-word negative cases, and the load-bearing\ninvariant that these approved-but-stateful schemes are signature/medium and\nNEVER hndl:true (they are a state-management hazard, not broken crypto).",
          "is_bot": false,
          "headline": "test: unit-test the stateful-HBS detector (SP 800-208)",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T07:56:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "efc2dbdcef08ad212358bec2fc05ff285cda93fe",
          "body": "…eport\n\nSieve runner: add tests for the failure paths that had none — a SUT that never\nanswers rejects with TimeoutError (carrying request + timeoutMs); a SUT that\nexits mid-request, or fails to spawn, rejects the in-flight send with a\nSutCrashError that attaches the exit reason and captured stderr;\n[…]\nlicy verdicts, subject/tool metadata)\nwhile ignoring the excluded scan time / CBOM envelope / attestation block. Tests\ncover the classic 'edit the evidence' downgrade. Additive API surface (324->326).",
          "is_bot": false,
          "headline": "test: sieve runner crash/timeout coverage + evidence verifyReadinessR…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T07:55:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4c69941bd3474c5d6a8ae4051fbbf2328128bbd5",
          "body": "The qscan CLI and MCP tool tests were written when core.scan was a stub and\ntolerated every exit code (`[OK, FINDINGS, ERROR].includes(code)`) or both\nbranches of an if/else. core is fully implemented and main()/scan_path drive\nthe genuine detector pipeline, so these now assert deterministic outcome\n[…]\nl temp fixtures: clean dir -> 0, RSA keygen -> 1/real finding,\nbaseline written, explain_finding returns real PQC remediation.\n\nAlso drops a stray U+200B from the maskBlockComments doc comment (lint).",
          "is_bot": false,
          "headline": "test: de-stub tautological CLI/MCP tests against the real scanner",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T07:51:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c0850f29d8420de99e0162e38d235792aad984ea",
          "body": "…/Azure KMS\n\nFrom the pre-1.0 audit's detection-gap list:\n\n- New xmldsig detector: classical XML-DSig / XML-Enc algorithm URIs (SAML SSO,\n  WS-Security) — rsa-sha*/dsa-sha*/ecdsa-sha* signatures and rsa-oaep key transport.\n- New pkcs11 detector: classical keys behind a PKCS#11 HSM/token — pkcs11-too\n[…]\ns. Messages/ids made cloud-generic.\n\nTwo new detectors registered (35 total). Regression tests (positives, negatives,\ndoc-suppression) throughout. Suite: 951 passing; all gates clean; benchmark 1.000.",
          "is_bot": false,
          "headline": "detectors: close coverage gaps — SAML/XML-DSig, PKCS#11, TDE, CDK/GCP…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T07:18:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5f08bd446459fec5fadc1b66a23326be4f116bd5",
          "body": "The detector matched only the quoted-value SDK/JSON form (`KeySpec: \"RSA_2048\"`), so\nAWS CDK's enum-member form (`kms.KeySpec.RSA_2048`, `acm.KeyAlgorithm.EC_prime256v1`)\nand Pulumi's camelCase props (`customerMasterKeySpec: \"RSA_2048\"`) produced ZERO\nfindings — the dominant IaC idioms at AWS-heavy \n[…]\nth cases; also cover ACM `KeyAlgorithm`. The fast-reject\ngate is now case-insensitive. Terraform's snake_case spec still never double-counts\n(the regex has no underscore form). Regression tests added.",
          "is_bot": false,
          "headline": "cloud-kms: cover AWS CDK enum forms + Pulumi/camelCase key specs",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T07:08:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "204e89b43d5601bcb36688e258b5c7a4527ea816",
          "body": "…NCSC\n\nCloses the audit's #1 gap: the tool was hardcoded to a NIST/CNSA worldview, and its\n\"hybrids optional\" guidance was regime-WRONG for ANSSI/BSI (where hybridization is\nrequired), with no way to choose otherwise.\n\n- New core `StandardsProfile` layer (standards-profiles.ts): five cited, dated\n  \n[…]\ntionForProfile, formatProfileGuidance (frozen in the surface). A drift test\n  keeps profile params aligned with PQC_STANDARDS.\n\nDocs: CHANGELOG, ROADMAP, CLI help. Suite: 936 passing; all gates clean.",
          "is_bot": false,
          "headline": "feat: selectable standards regimes (--profile) — NIST/CNSA/BSI/ANSSI/…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T07:01:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3cd17e3e04536d9daac70069d441a52e5826da8b",
          "body": "…E, ROADMAP)\n\n- CONFIG.md §5 was materially wrong: it implied the Action and MCP honor a\n  discovered config. Neither does (verified) — and that's deliberate: both run over\n  operator-uncontrolled trees, so a discovered config there would be a scan-integrity\n  bypass. Documented the trusted-local-op\n[…]\n/ 593 tests / 9 langs / 5\n  packages). Updated to v0.5.0 / ~930 tests / 11 langs / 7 packages, added qprobe,\n  and led with both benchmark numbers (curated 1.000 + real-world recall 0.84).\n\nDocs only.",
          "is_bot": false,
          "headline": "docs: correct drift the audit flagged (CONFIG security posture, READM…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T06:43:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fe7869d5f84ab86a16113d399c66fa7520203d36",
          "body": "Nine symbols with zero cross-package consumers were being SemVer-frozen by accident\n— un-export them from @quantakrypto/core's index (they stay exported from their own\nmodules, so core's own tests still import them via ../src/): the parallel-scan\nchunk/merge helpers (mergeChunkResults, chunkByBytes)\n[…]\niewStatus, and isGeneratedPath. Public surface 324 → 315 symbols\n(core 139 → 130). Also refreshed the stale builtinDetectors doc comment (it\ndescribed ~10 detectors; there are 33). No behavior change.",
          "is_bot": false,
          "headline": "freeze-safety: trim internal plumbing from the public API surface",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T06:42:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "26f4c7d57ff97958659fca364cf04db12e51c3c3",
          "body": "Two better-before-the-1.0-API-freeze items from the audit.\n\n- Block comments now mask correctly. `maskCommentLines` is line-only, so an\n  HCL/Bicep resource wrapped in `/* … */` had its inner lines left live (verified\n  FP: bicep-keyvault-rsa / tf-rsa-key fired inside a block comment). New\n  offset-\n[…]\nderReport` into async `runQscan`; the sync `commandSigner` still satisfies the\n  wider type. Added an async-signer test.\n\nRegression tests added. Suite: 928 passing; all gates clean (incl. api-check).",
          "is_bot": false,
          "headline": "freeze-safety: block-comment masking + async-capable EvidenceSigner",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T05:55:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f10745a5ceb62aa36fd94b73fc39a4a12cf0ca84",
          "body": "…rity drift\n\nConfirmed, low-risk findings from the pre-1.0 four-lens audit.\n\nSecurity:\n- An AUTO-DISCOVERED quantakrypto.config.json can come from the scanned tree, so a\n  hostile repo could silently WEAKEN its own scan (disable rules, raise the\n  severity-threshold, exclude files → flip exit 1→0). \n[…]\n9/X448 low→medium (aligns with node/rust/go) — the same\n  primitive must not flip CI exit codes based on which surface uses it.\n\nRegression tests added throughout. Suite: 925 passing; all gates clean.",
          "is_bot": false,
          "headline": "audit fixes: config-trust warning, verified FPs, Swift coverage, seve…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T05:32:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dc942ea12abfb232859dc81d3a782d2bde8e1a59",
          "body": "… were missing\n\nThe generator's declaration regexes didn't allow an `async` modifier, so\n`export async function` was skipped: runQscan, runSieve, runProbe (the main public\nentry points of qscan/sieve/qprobe) were absent from the frozen surface\n(docs/api-surface.json + API.md), and since `--check` sh\n[…]\nmplete freeze. Widen the modifier prefix to\n`(?:(?:declare|async|abstract)\\s+)*` in both collectExports regexes and docFor, and\nregenerate: 318 → 324 symbols.\n\nFound by the pre-1.0 test-quality audit.",
          "is_bot": false,
          "headline": "fix(api-gen): capture `export async function` — flagship entry points…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T05:20:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3ac14568839a1dd17270a7472371ed2729127cde",
          "body": "Completes the A.8.24 evidence chain per ADR-0004: the tool orchestrates a signer,\nit implements no cryptography.\n\n- `qscan --format evidence --sign <cmd>` / `--timestamp <cmd>` pipe the report's\n  deterministic contentHash to an operator-provided external signer (openssl /\n  cosign / an RFC-3161 TSA\n[…]\ney.\n\nDocs: A.8.24 evidence doc §3.1 (interface + examples + verify recipe), ROADMAP,\nCHANGELOG. New public exports frozen in the API surface. Suite: 922 passing;\nlint/format/zero-deps/api-check clean.",
          "is_bot": false,
          "headline": "qscan: orchestrate external evidence signing (--sign / --timestamp)",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T04:58:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9b26eeed47f8420b8197ed0dfd91f4757f0a39d7",
          "body": "Promote the roadmap's i18n YAGNI note to a load-bearing Architecture Decision\nRecord: the human-facing report ships no message catalogs or locale machinery, and\nthe structured JSON/SARIF/CBOM output is the locale-neutral integration surface for\nany consumer that needs localized presentation. Framed as a YAGNI deferral, not a\npermanent refusal — reopening requires a new ADR with a concrete localized-consumer\nneed. Indexed in docs/adr/README.md and cross-linked from ROADMAP.md.",
          "is_bot": false,
          "headline": "docs: record report-is-English-only (no i18n) as ADR-0006",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T04:48:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2241e0ce3c675f512409caa3beb4563f916b8de8",
          "body": "…gate)\n\nCloses the VERSIONING.md 1.0 requirement of \"a documented, frozen public API\nsurface + a generated API reference\".\n\n- scripts/gen-api-reference.mjs (zero-dep) reads each package's public entry point\n  (following a single `export * from` hop) and emits docs/API.md (human reference)\n  and docs\n[…]\ngate bites: exit 1 on a dropped/added symbol, 0 when clean.\n- Documented the closed gate in VERSIONING.md, ROADMAP.md §1, and CHANGELOG.\n\nSuite: 916 passing; lint/format/zero-deps/api-check all clean.",
          "is_bot": false,
          "headline": "docs: freeze the public API surface + generate an API reference (1.0 …",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T04:42:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "32f90adc35068db7f330c1dbc27f061ad4aa962a",
          "body": "Bump every @quantakrypto/* package 0.4.4 → 0.5.0 (and the cross-package core/\nqprobe/qscan/agent pins + the two version.ts constants), and date the CHANGELOG\n[Unreleased] → [0.5.0].\n\nMinor bump under 0.x: this line adds new backward-compatible detector surfaces\n(Azure Bicep, Swift/CryptoKit, Pulumi)\n[…]\ntop of the round 3/4/5 detection-accuracy\nand engine-correctness fixes and the dead-code/API-surface cleanup. Suite at 916\npassing; precision/recall gates and the zero-FP negative set held throughout.",
          "is_bot": false,
          "headline": "release: v0.5.0",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T04:35:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3a84af29921dea8a22a4d2a9ea292d6e861e3cab",
          "body": "Document the detector-precision hardening (comment/prose masking, cross-detector\ndouble-count deferrals, per-language FP/FN fixes), the engine correctness fixes\n(triage cap, CBOM merge/serial, readiness ordering, CLI ENOENT/--merge, sieve KAT\nskips), the dead-code removal and API-surface narrowing, the three new detector\nsurfaces (Azure Bicep, Swift/CryptoKit, Pulumi), and the real-repo validation +\ncorpus expansion. No previously-documented entries changed.",
          "is_bot": false,
          "headline": "docs: bring CHANGELOG [Unreleased] current through rounds 3–5",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T04:31:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "89dc0598aa850fc1abdc0faade4e74c7d1d997c1",
          "body": "Three new detector surfaces (#5), each registered, unit-tested, and pinned by the\nbenchmark corpus:\n\n- bicep: Azure-native IaC (.bicep) — Microsoft.KeyVault `kty: 'RSA'/'EC'` keys\n  (gated to the Key Vault marker) and legacy `minimumTlsVersion: 'TLS1_0'/'TLS1_1'`.\n  Complements the existing ARM/Clou\n[…]\nhe `algorithm` value (RSA/ECDSA/ED25519).\n\nValidated against real OSS repos (gin, mux, flask, terraform-aws-eks, express,\nhelm/charts): zero false positives from the new detectors. Suite: 916 passing.",
          "is_bot": false,
          "headline": "detectors: add Azure Bicep, Swift/CryptoKit, and Pulumi coverage",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T04:27:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "877319c024ada9a572206b21d631e7e735e5a6db",
          "body": "Add 7 labeled corpus cases so the new coverage is pinned by the precision/recall\ngates (was invisible to the benchmark before):\n\nPositives:\n- GCP service-account JSON with a single-line \\n-escaped PKCS#8 key\n  (pem-pkcs8-private-key)\n- Terraform tls_private_key ED25519 (tf-ed25519-key)\n- Ansible com\n[…]\nide a Terraform description string\n- a PEM parser's paired header/footer string constants\n- commented-out PHP openssl crypto\n\nBenchmark: recall perfect, negative set strict (0 FP). Suite: 899 passing.",
          "is_bot": false,
          "headline": "benchmark: expand corpus for the round 3/4/5 detector surfaces",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T04:18:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "173d388feb0909804020bd84b4cfc5e14fa16bf5",
          "body": "Empirical validation (scanning real OSS repos — gin, flask, terraform-aws-eks,\nhelm/charts, express, gorilla/mux) surfaced one false-positive class: the\nssh-kex-classical / tls-classical-kex token rules fired on classical algorithm\nnames LISTED inside a Terraform/Packer `description = \"…\"` string (\"\n[…]\n is unaffected.\n\nThe rest of the sweep (~82 findings across 6 repos) was legitimate: real embedded\ntest certs/keys, real InsecureSkipVerify, and intentional classical-crypto deps.\n\nSuite: 899 passing.",
          "is_bot": false,
          "headline": "source: don't fire transport-KEX rules on algorithm names in a doc field",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T04:15:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5560caa06ce10bd7549191f63e322e85da7b595c",
          "body": null,
          "is_bot": false,
          "headline": "test: cover cosign sign-blob subcommand",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T03:44:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dd2d584af6bebd42d5c95c1dfd1aba61db40b80a",
          "body": "Un-export 71 symbols across the workspace that are referenced only within their\nown declaring file — helpers, config/option interfaces, and protocol member types\nthat are not part of any package's public API (none re-exported by an index, none\nimported by another module or test). The build (declarat\n[…]\nrms nothing outside each file used them. Also delete mcp's JsonValue type,\nwhich turned out to be unused in-file once un-exported.\n\nNo behavior change. Suite: 894 passing; lint/format/zero-deps clean.",
          "is_bot": false,
          "headline": "narrow visibility of internal-only symbols; drop dead JsonValue type",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T03:43:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ee573f43af9d63f682362c952fb06c4ce6c008df",
          "body": "- Delete three symbols with zero references anywhere: mcp `ToolInputSchema` (and\n  the now-unused JsonSchema import it existed to reference), sieve `SuccessResponse`,\n  and mcp `writeLine` (a redundant helper — runStdioServer writes inline).\n- cicd: reorder the cosign subcommand alternation so `sign\n[…]\nhortening its matchLength).\n- cloud-kms: drop the redundant `CustomerMasterKeySpec` fast-reject conjunct — the\n  string contains `KeySpec`, so the earlier check already covers it.\n\nSuite: 894 passing.",
          "is_bot": false,
          "headline": "remove dead code: unused exports, redundant helper, unreachable branches",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T03:40:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "88e41c5b8c2bcf3b1229272ac8638c5592b610b8",
          "body": "- ansible: an openssl_privatekey `type: X448` now reports algorithm X448 instead\n  of the shared XDH rule's default X25519 label.\n- database: the sslmode prefilter now also admits the `ssl_mode` (underscore) form\n  the RE_WEAK_SSLMODE regex already matches — previously the gate silently blocked\n  every underscore-only file, making that regex branch dead.\n\nSuite: 894 passing.",
          "is_bot": false,
          "headline": "ansible/database: correct X448 label and align the sslmode prefilter",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T03:27:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e97bc430284bbee36af0972ac10e55788f7a3487",
          "body": "An adversarial verification pass over the round 3 diff surfaced six regressions —\ninputs the test suite didn't cover. All fixed and pinned with tests.\n\n- pem: a long single-line, `\\n`-escaped key body (GCP service-account JSON,\n  `PRIVATE_KEY=\"…\\n…\"`) pushed the -----END marker past the 800-char win\n[…]\ny checked the immediate preceding\n  char, so a hardened full-suite exclusion (`HIGH:!ECDHE-RSA-RC4-SHA`) false-\n  positived. The lookbehind now walks back to the element boundary.\n\nSuite: 893 passing.",
          "is_bot": false,
          "headline": "fix regressions from the round 3 detector changes (verification pass)",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T03:18:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5ea64d43ce303938ecc04944562b4cbb461c0bb0",
          "body": "…m ids\n\n- c: the TLS-version rule now also matches TLSv1_1_method, the _client/_server\n  method variants, and SSLv2_method (previously only TLSv1_method/SSLv3_method).\n- openpgp: map the RFC 9580 (crypto-refresh) v6 public-key algorithm ids —\n  25 X25519, 26 X448 (key agreement, HNDL), 27 Ed25519, 28 Ed448 (signatures) —\n  so v6 keys classify precisely instead of falling back to a generic finding.\n\nSuite: 887 passing.",
          "is_bot": false,
          "headline": "c/openpgp: widen legacy TLS method forms and map RFC 9580 v6 algorith…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T02:59:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cd436ab7aa4747d339a1378f1a837b8d78d3a3c6",
          "body": "…AT skips\n\nRound 3 audit follow-up on the non-detector engine (crashes, misleading output,\nsilent data loss).\n\n- triage: when capping to --max-findings, select the TOP by SEVERITY, not by\n  file-path order — a critical in a late-sorting file was dropped from triage and\n  sunk to the bottom of the re\n[…]\nT: an unverifiable vector (no seed/coins) is a SKIP, not a match — it no\n  longer inflates the \"N/N matched\" count into a false conformance pass.\n\nAdds regression tests throughout. Suite: 887 passing.",
          "is_bot": false,
          "headline": "engine: fix triage cap, CBOM merge crashes/serial, readiness order, K…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T02:57:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1384375b74d6a4cf3b88bccc48f95be282a877b9",
          "body": "Round 3 audit follow-up on the language packs.\n\nDouble-counts (deferrals added to jwtDetector, mirroring jose.ts):\n- A JWK object inlined in JS/TS/Py source no longer fires BOTH jwk-* and\n  jwt-classical-alg: jwtDetector skips alg tokens whose enclosing object has a\n  `\"kty\"` (jwk owns it).\n- A quot\n[…]\nx448::Secret`.\n- elixir: `:crypto.compute_key` (the (EC)DH agreement op); JOSE OKP X25519/X448 is\n  key agreement (HNDL), not an EdDSA signature.\n\nAdds regression tests throughout. Suite: 881 passing.",
          "is_bot": false,
          "headline": "source/language detectors: dedup double-counts and close FP/FN gaps",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T02:48:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9a06ef9988a41ad4fd1d160e61d0270dbc3490bb",
          "body": "Round 3 audit follow-up on the infrastructure/config detectors. Root cause of the\nfalse positives: commentStyleForFile covers no config extension, so any config\ndetector that skipped maskCommentLines had zero comment protection.\n\nFalse positives (comment masking added; offsets preserved):\n- mesh, dn\n[…]\nno `\"` between the markers. This closes a self-regression where a PEM\nparser's paired header/footer string constants were accepted as a real key.\n\nAdds regression tests throughout. Suite: 870 passing.",
          "is_bot": false,
          "headline": "config detectors: comment masking for config formats, plus FN/FP fixes",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T02:35:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "99bdda97910f2a88d165573caf6d42cafc3cc709",
          "body": "… scoping\n\nRound 3 correctness pass. Fixes three P0 false-positive classes plus two\nregressions from the Round 2 JWK/JOSE work, and makes the shared object-scoping\nhelper string-aware.\n\n- comments: add PHP/.phtml/Scala (`.scala`/`.sc`) to the C-style comment table\n  and Ruby/Elixir (`.rb`/`.ex`/`.ex\n[…]\nlt marker.\n- keystore: accept BER indefinite-length PKCS#12 (0x80), emitted by NSS/Firefox\n  .p12 exports, alongside the long-form DER lengths.\n\nAdds regression tests for each fix. Suite: 862 passing.",
          "is_bot": false,
          "headline": "core: eliminate P0 false-positive classes and harden per-key JWK/JOSE…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-20T02:19:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4894d5ec21b5754b9fef379e7d2a6f167ec4d0d5",
          "body": "Binary pipeline (from the binary-audit): detect PKCS#12-format keystores named\n.jks/.keystore (keytool default since Java 9) and the 30 81 / 30 83 DER length\nforms; count latin1 keystore bytes at on-disk size (serial/parallel budget parity);\nisKeystorePath uses endsWith so bare dotfiles agree with t\n[…]\nssaging keeps only static-RSA\n(ECDHE owned by source); secrets defers PGP MESSAGE to pem; cfn ARM kty requires a\nMicrosoft.KeyVault marker. qprobe upgrade drops stale net listeners. Regression-tested.",
          "is_bot": false,
          "headline": "audit round 1 fixes: binary keystore/openpgp + detector precision",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-19T17:43:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "787b69f4e235f2268d6f2372e4915cd7d9781a51",
          "body": "…y_share\n\nThe TLS probe now sends a valid X25519MLKEM768 key_share (real X25519 public from\nnode:crypto + a valid-range ML-KEM-768 encapsulation key, ek||x25519 per\ndraft-ietf-tls-ecdhe-mlkem), so a supporting server selects 0x11EC directly in its\nServerHello — catching support-but-don't-prefer serv\n[…]\ntes the handshake): a ByteEncode12\nof in-range coefficients passes the encaps modulus check; the throwaway secret is\nnever computed. New mlkem768.ts, pure + unit-tested; fallback to x25519/HRR intact.",
          "is_bot": false,
          "headline": "qprobe: definitive hybrid negotiation via a well-formed ML-KEM-768 ke…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-19T17:19:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b1b0489d303f601b19ae20e3ca43b656825d09cc",
          "body": "Extend qprobe beyond TLS/SSH/SMTP to the other 'communication between things'\nendpoints, auto-selected by well-known port:\n- imap (:143) / pop3 (:110): line-based STARTTLS/STLS upgrade (generic\n  probeLineStartTls helper), then the same negotiated-parameter inspection.\n- postgres (:5432): send the 8\n[…]\n853) and IMAPS (:993) already work as direct-TLS probes.\nAll reuse the clean-close hang guard and cert/KEX classification. Pure builders +\nmock-server dance tested; postgres upgrade path e2e-verified.",
          "is_bot": false,
          "headline": "qprobe: add IMAP/POP3 STARTTLS and PostgreSQL SSLRequest probes",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-19T17:12:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "eab2897929c9c017cac4fc0bcad02bab6e79eabd",
          "body": "Single-source ownership for overlapping surfaces (audit precision findings):\n- source.ts owns SSH KexAlgorithms + ECDHE cipher tokens; removed the redundant\n  vpn net-sshd-classical-kex and mesh mesh-istio-classical-cipher rules.\n- cloudformation.ts owns crypto inside CFN/ARM templates: jwk + cloud-\n[…]\ntensions; usage-aware — a signing RSA/EC JWK is a signature\n  (hndl:false), encryption keys stay hndl:true.\n- jose: defer to jwk when the alg is inside a JWK object.\nRegression-tested; 837 tests pass.",
          "is_bot": false,
          "headline": "detectors: fix cross-detector double-counts + jwk sig/enc classification",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-19T17:05:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "caddec1ebc12b0afb5d24e180b86eb9fdf9912c2",
          "body": "Building on the byte-preserving binary read (keystore pipeline), extend it to\nOpenPGP keyrings (.gpg/.pgp/.kbx) and add an openpgp detector that parses packet\ntags: committed SECRET keys (sensitive; the sharp finding — a private key in a\nrepo), public keys, binary PGP-encrypted messages (PKESK → HND\n[…]\nPG\nkeyboxes. The public-key algorithm (RSA/DSA/ElGamal/ECDSA/EdDSA/ECDH) is read from\nthe packet body. Bounds-checked, fuzz-tested, pipeline-tested. Armored blocks stay\nwith the PEM/secrets detectors.",
          "is_bot": false,
          "headline": "detect binary OpenPGP key material and GnuPG keyboxes",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-19T16:46:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4d78c7dc8da074ebbed1e048fa318dc293b7a19c",
          "body": "Previously the networked probe_endpoint tool was refused unconditionally on the\nHTTP transport. Mirror the allowFs pattern instead: it is OFF by default on HTTP\nbut a trusted operator can enable it via QUANTAKRYPTO_MCP_ALLOW_NETWORK=1 (or the\nallowNetwork option). Threaded through HttpServerOptions/\n[…]\nlowFs, allowNetwork); startup banner shows probe:on/off.\nThe per-call ownership attestation and range refusal still apply on every transport.\nstdio (local, trusted) is unchanged. Docs + tests updated.",
          "is_bot": false,
          "headline": "mcp: make HTTP exposure of probe_endpoint an opt-in parameter",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-19T16:19:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a3f4017158dde01b2ba766b8f4d68809fc8b2be3",
          "body": "The scan pipeline hard-skipped binary files, so keystores (private key material)\nwere invisible. Add a keystore extension set (walk.ts isKeystorePath); the serial\nand parallel scan paths now read those extensions byte-preserving (latin1) and\nexempt them from the minified skip, so a new keystore dete\n[…]\nppet dropped). Other binaries stay skipped.\nPipeline-tested end to end. Also records this session's platform work (qscan\n--cbom --merge, MCP probe_endpoint, infra Action recipe, detector-audit fixes).",
          "is_bot": false,
          "headline": "detect committed cryptographic keystores (JKS/JCEKS/PKCS12/BKS)",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-19T16:13:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a8f882d02dcd2c65f7d7d2672fb603411d5b78b0",
          "body": "Exposes qProbe's live-endpoint probing to AI agents. The qprobe plane is loaded via\ndynamic import so the server stays offline until the tool is invoked, and the\nownership attestation is enforced: probe_endpoint refuses unless i_own_this=true and\nrefuses CIDR/ranges (helpful message). Errored/unreac\n[…]\nRefused UNCONDITIONALLY on the HTTP\ntransport (new NETWORK_TOOL_NAMES) — a hosted MCP must not be an arbitrary-host\nprobing oracle. mcp now depends on @quantakrypto/qprobe (internal, zero-dep intact).",
          "is_bot": false,
          "headline": "mcp: add gated probe_endpoint tool (the only networked MCP tool)",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-19T16:06:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "033ef7175b340a5f9d04ffdc0eb7dcfc7d8e2321",
          "body": "…+ combined CBOM)\n\nNew example workflow showing the infra line end to end: qScan gates code + IaC on\nevery change, a weekly scheduled job probes owned TLS/SSH endpoints with qProbe\n(behind a committed ownership manifest), and 'qscan --cbom --merge' fuses the scan\nand endpoint CBOMs into one combined code + infrastructure + wire bill of materials.\nAdds an owned-hosts.example.txt manifest template.",
          "is_bot": false,
          "headline": "action: infrastructure readiness recipe (IaC scan + scheduled qprobe …",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-19T15:22:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d7547aaa27f7d9b0bf665a3ae9e4028c9267a379",
          "body": "… CBOM\n\nThe mergeCboms engine (core/cbom-merge.ts) existed but was unwired. Add a\nrepeatable --merge <cbom.json> flag: with --cbom it reads external CBOMs (e.g. a\nqprobe endpoint CBOM) and merges them with the scan CBOM via CycloneDX, producing\none combined code + infrastructure bill of materials. Errors (missing file, non-\nJSON, non-CycloneDX) exit 2 with a clear message. Unit + e2e tested.",
          "is_bot": false,
          "headline": "qscan: wire mergeCboms — qscan --cbom --merge for combined code+infra…",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-19T15:20:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4b54926228119bb179b99de832497e133fb68e28",
          "body": "…(audit)\n\nAddresses infra config-detector audit findings (my detectors):\n- ReDoS: bound the unbounded [^\\n]* / [^\\n&|;]*? spans in messaging (ssl.protocol,\n  ssl.cipher.suites) and cicd (gpg, codesign) — they blew the repo's 2s budget on\n  adversarial input. Add config-detector inputs to redos.test.\n[…]\n(the cipher rule reports the KEX harvest).\n\n(vpn sshd double-count and the cross-detector / other-agent-owned findings are left\nfor coordination — the other agent is actively remediating those files.)",
          "is_bot": false,
          "headline": "detectors: fix ReDoS, comment-masking FPs, and cipher classification …",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-19T15:12:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "febabf20e71da5450bee9ea810081ee43a7c23da",
          "body": "Two new config-scope detectors closing audited gaps:\n- supply-chain: Docker Content Trust (Notary v1), CNCF Notation, in-toto signing\n  (signature-side, gated to CI/Dockerfile/shell, comment-masked)\n- vault: native HashiCorp Vault HCL transit key types (rsa-*/ecdsa-p*/ed25519) and\n  pki role key_type; gated to .hcl + a transit/pki marker so it never overlaps the\n  terraform detector (.tf)\n\nAlso records the ansible/age detectors and the qprobe hang fix in CHANGELOG.",
          "is_bot": false,
          "headline": "detect supply-chain signing and native vault hcl crypto",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-19T14:03:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4e9b4012b750a45f42998065c8852ac112d00198",
          "body": "Two new config-scope detectors closing audited gaps:\n- ansible: community.crypto openssl_privatekey/csr type RSA/ECC (comment-masked, gated)\n- age: committed AGE-SECRET-KEY-1 identity (X25519 private key) — worse than a\n  recipient; sensitive so the snippet is dropped. Closes the secrets-detector FN.",
          "is_bot": false,
          "headline": "detect ansible community.crypto keys and committed age identity keys",
          "author_name": "Leon Acosta @ Dandelion Labs",
          "author_login": "leonacostaok",
          "committed_at": "2026-07-19T13:58:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 4,
      "commits_last_year": 254,
      "latest_release_at": "2026-07-23T05:57:13Z",
      "latest_release_tag": "v1",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 6,
      "days_since_latest_release": 3,
      "mean_days_between_releases": 2.5
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 87,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "@quantakrypto/mcp",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@quantakrypto/mcp",
          "is_deprecated": false,
          "latest_version": "0.5.2",
          "repository_url": "https://github.com/quantakrypto/pqc-tools",
          "versions_count": 13,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 2087,
          "first_published_at": "2026-06-22T13:45:51.286000Z",
          "latest_published_at": "2026-07-23T03:34:07.172000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 4
        },
        {
          "name": "@quantakrypto/core",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@quantakrypto/core",
          "is_deprecated": false,
          "latest_version": "0.5.0",
          "repository_url": "https://github.com/quantakrypto/pqc-tools",
          "versions_count": 11,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 2041,
          "first_published_at": "2026-06-22T13:45:42.443000Z",
          "latest_published_at": "2026-07-20T15:48:15.033000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 6
        },
        {
          "name": "@quantakrypto/agent",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@quantakrypto/agent",
          "is_deprecated": false,
          "latest_version": "0.5.0",
          "repository_url": "https://github.com/quantakrypto/pqc-tools",
          "versions_count": 6,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 725,
          "first_published_at": "2026-07-03T12:32:08.324000Z",
          "latest_published_at": "2026-07-20T15:48:11.055000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 6
        },
        {
          "name": "@quantakrypto/qscan",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@quantakrypto/qscan",
          "is_deprecated": false,
          "latest_version": "0.5.0",
          "repository_url": "https://github.com/quantakrypto/pqc-tools",
          "versions_count": 11,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 1597,
          "first_published_at": "2026-06-22T13:45:48.337000Z",
          "latest_published_at": "2026-07-20T15:48:26.187000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 6
        },
        {
          "name": "@quantakrypto/sieve",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@quantakrypto/sieve",
          "is_deprecated": false,
          "latest_version": "0.5.0",
          "repository_url": "https://github.com/quantakrypto/pqc-tools",
          "versions_count": 11,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 1714,
          "first_published_at": "2026-06-22T13:45:45.289000Z",
          "latest_published_at": "2026-07-20T15:48:29.507000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 6
        },
        {
          "name": "@quantakrypto/qprobe",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@quantakrypto/qprobe",
          "is_deprecated": false,
          "latest_version": "0.5.0",
          "repository_url": "https://github.com/quantakrypto/pqc-tools",
          "versions_count": 2,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 312,
          "first_published_at": "2026-07-19T08:12:24.768000Z",
          "latest_published_at": "2026-07-20T15:48:22.571000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 6
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 9,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": null,
      "open_issues_and_prs": 7
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": true,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "packages/action/tsconfig.json",
        "packages/agent/tsconfig.json",
        "packages/core/tsconfig.json",
        "packages/mcp/tsconfig.json",
        "packages/qprobe/tsconfig.json",
        "packages/qscan/tsconfig.json",
        "packages/sieve/tsconfig.json",
        "tsconfig.json"
      ],
      "toolchain_manifests": [
        "packages/core/test/benchmark/recall/csharp/Acme.Signing.csproj",
        "packages/core/test/benchmark/recall/go/go.mod",
        "packages/core/test/benchmark/recall/java/pom.xml",
        "packages/core/test/benchmark/recall/rust/Cargo.toml"
      ],
      "largest_source_bytes": 59062,
      "source_files_sampled": 454,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 2,
        "malicious_count": 0,
        "assessed_package": "npm:@quantakrypto/mcp@0.5.2",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "@quantakrypto/core",
          "manifest": "packages/action/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.5.0"
        },
        {
          "name": "@quantakrypto/qscan",
          "manifest": "packages/action/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.5.0"
        },
        {
          "name": "@quantakrypto/core",
          "manifest": "packages/agent/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.5.0"
        },
        {
          "name": "@quantakrypto/core",
          "manifest": "packages/mcp/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.5.0"
        },
        {
          "name": "@quantakrypto/qprobe",
          "manifest": "packages/mcp/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.5.0"
        },
        {
          "name": "@quantakrypto/core",
          "manifest": "packages/qprobe/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.5.0"
        },
        {
          "name": "@quantakrypto/agent",
          "manifest": "packages/qscan/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.5.0"
        },
        {
          "name": "@quantakrypto/core",
          "manifest": "packages/qscan/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.5.0"
        },
        {
          "name": "@noble/post-quantum",
          "manifest": "validation/sieve-real-sut/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.4.0"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "@noble/post-quantum",
            "direct": true,
            "version": "0.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "@noble/post-quantum",
            "direct": true,
            "version": "0.6.1",
            "ecosystem": "npm"
          },
          {
            "name": "@quantakrypto/agent",
            "direct": true,
            "version": "0.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "@quantakrypto/core",
            "direct": true,
            "version": "0.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "@quantakrypto/qprobe",
            "direct": true,
            "version": "0.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "@quantakrypto/qscan",
            "direct": true,
            "version": "0.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "anyhow",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "ed25519-dalek",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "hex",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "openssl",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "rsa",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "serde",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "serde_json",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "tokio",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "tracing",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "x25519-dalek",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "github.com/cloudflare/circl",
            "direct": false,
            "version": "v1.3.9",
            "ecosystem": "go"
          },
          {
            "name": "github.com/decred/dcrd/dcrec/secp256k1/v4",
            "direct": false,
            "version": "v4.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/golang-jwt/jwt/v5",
            "direct": false,
            "version": "v5.2.1",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/crypto",
            "direct": false,
            "version": "v0.24.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sys",
            "direct": false,
            "version": "v0.21.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/term",
            "direct": false,
            "version": "v0.21.0",
            "ecosystem": "go"
          },
          {
            "name": "com.fasterxml.jackson.core:jackson-databind",
            "direct": false,
            "version": "2.17.1",
            "ecosystem": "maven"
          },
          {
            "name": "io.jsonwebtoken:jjwt-api",
            "direct": false,
            "version": "0.11.5",
            "ecosystem": "maven"
          },
          {
            "name": "org.bouncycastle:bcpkix-jdk18on",
            "direct": false,
            "version": "1.78.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.bouncycastle:bcprov-jdk18on",
            "direct": false,
            "version": "1.78.1",
            "ecosystem": "maven"
          },
          {
            "name": "@esbuild/aix-ppc64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-arm",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/darwin-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/darwin-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/freebsd-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/freebsd-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-arm",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-ia32",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-loong64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-mips64el",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-ppc64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-riscv64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-s390x",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/netbsd-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/netbsd-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openbsd-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openbsd-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openharmony-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/sunos-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-ia32",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint-community/eslint-utils",
            "direct": false,
            "version": "4.9.1",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint-community/regexpp",
            "direct": false,
            "version": "4.12.2",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/config-array",
            "direct": false,
            "version": "0.21.2",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/config-helpers",
            "direct": false,
            "version": "0.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/core",
            "direct": false,
            "version": "0.17.0",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/eslintrc",
            "direct": false,
            "version": "3.3.5",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/js",
            "direct": false,
            "version": "9.39.4",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/object-schema",
            "direct": false,
            "version": "2.1.7",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/plugin-kit",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "@humanfs/core",
            "direct": false,
            "version": "0.19.2",
            "ecosystem": "npm"
          },
          {
            "name": "@humanfs/node",
            "direct": false,
            "version": "0.16.8",
            "ecosystem": "npm"
          },
          {
            "name": "@humanfs/types",
            "direct": false,
            "version": "0.15.0",
            "ecosystem": "npm"
          },
          {
            "name": "@humanwhocodes/module-importer",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "@humanwhocodes/retry",
            "direct": false,
            "version": "0.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "@noble/ciphers",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@noble/curves",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@noble/hashes",
            "direct": false,
            "version": "1.8.0",
            "ecosystem": "npm"
          },
          {
            "name": "@noble/hashes",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@quantakrypto/action",
            "direct": false,
            "version": "0.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "@quantakrypto/mcp",
            "direct": false,
            "version": "0.5.2",
            "ecosystem": "npm"
          },
          {
            "name": "@quantakrypto/observatory",
            "direct": false,
            "version": "0.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@quantakrypto/sieve",
            "direct": false,
            "version": "0.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "@types/estree",
            "direct": false,
            "version": "1.0.9",
            "ecosystem": "npm"
          },
          {
            "name": "@types/json-schema",
            "direct": false,
            "version": "7.0.15",
            "ecosystem": "npm"
          },
          {
            "name": "@types/node",
            "direct": false,
            "version": "26.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "@types/node",
            "direct": false,
            "version": "^20.12.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/eslint-plugin",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/parser",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/project-service",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/scope-manager",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/tsconfig-utils",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/type-utils",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/types",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/typescript-estree",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/utils",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/visitor-keys",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "acorn",
            "direct": false,
            "version": "8.16.0",
            "ecosystem": "npm"
          },
          {
            "name": "acorn-jsx",
            "direct": false,
            "version": "5.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "ajv",
            "direct": false,
            "version": "6.15.0",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-styles",
            "direct": false,
            "version": "4.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "argparse",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "balanced-match",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "balanced-match",
            "direct": false,
            "version": "4.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "1.1.16",
            "ecosystem": "npm"
          },
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "5.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "callsites",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "chalk",
            "direct": false,
            "version": "4.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "color-convert",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "color-name",
            "direct": false,
            "version": "1.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "concat-map",
            "direct": false,
            "version": "0.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "cross-spawn",
            "direct": false,
            "version": "7.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "debug",
            "direct": false,
            "version": "4.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "deep-is",
            "direct": false,
            "version": "0.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "elliptic",
            "direct": false,
            "version": "^6.5.4",
            "ecosystem": "npm"
          },
          {
            "name": "elliptic",
            "direct": false,
            "version": "^6.5.5",
            "ecosystem": "npm"
          },
          {
            "name": "esbuild",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "escape-string-regexp",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "eslint",
            "direct": false,
            "version": "9.39.4",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-scope",
            "direct": false,
            "version": "8.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-visitor-keys",
            "direct": false,
            "version": "3.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-visitor-keys",
            "direct": false,
            "version": "4.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-visitor-keys",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "espree",
            "direct": false,
            "version": "10.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "esquery",
            "direct": false,
            "version": "1.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "esrecurse",
            "direct": false,
            "version": "4.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "estraverse",
            "direct": false,
            "version": "5.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "esutils",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "express",
            "direct": false,
            "version": "^4.18.0",
            "ecosystem": "npm"
          },
          {
            "name": "express",
            "direct": false,
            "version": "^4.19.2",
            "ecosystem": "npm"
          },
          {
            "name": "fast-check",
            "direct": false,
            "version": "4.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "fast-deep-equal",
            "direct": false,
            "version": "3.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "fast-json-stable-stringify",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "fast-levenshtein",
            "direct": false,
            "version": "2.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "fdir",
            "direct": false,
            "version": "6.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "file-entry-cache",
            "direct": false,
            "version": "8.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "find-up",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "flat-cache",
            "direct": false,
            "version": "4.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "flatted",
            "direct": false,
            "version": "3.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "fsevents",
            "direct": false,
            "version": "2.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "glob-parent",
            "direct": false,
            "version": "6.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "globals",
            "direct": false,
            "version": "14.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "has-flag",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "ignore",
            "direct": false,
            "version": "5.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "ignore",
            "direct": false,
            "version": "7.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "import-fresh",
            "direct": false,
            "version": "3.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "imurmurhash",
            "direct": false,
            "version": "0.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "is-extglob",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-glob",
            "direct": false,
            "version": "4.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "isexe",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "js-yaml",
            "direct": false,
            "version": "4.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "json-buffer",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "json-schema-traverse",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "json-stable-stringify-without-jsonify",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "jsonwebtoken",
            "direct": false,
            "version": "^9.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "jsonwebtoken",
            "direct": false,
            "version": "^9.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "keyv",
            "direct": false,
            "version": "4.5.4",
            "ecosystem": "npm"
          },
          {
            "name": "levn",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "locate-path",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "lodash",
            "direct": false,
            "version": "^4.17.21",
            "ecosystem": "npm"
          },
          {
            "name": "lodash.merge",
            "direct": false,
            "version": "4.6.2",
            "ecosystem": "npm"
          },
          {
            "name": "minimatch",
            "direct": false,
            "version": "10.2.5",
            "ecosystem": "npm"
          },
          {
            "name": "minimatch",
            "direct": false,
            "version": "3.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "ms",
            "direct": false,
            "version": "2.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "natural-compare",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "node-forge",
            "direct": false,
            "version": "^1.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "optionator",
            "direct": false,
            "version": "0.9.4",
            "ecosystem": "npm"
          },
          {
            "name": "p-limit",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "p-locate",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "parent-module",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "path-exists",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "path-key",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "picomatch",
            "direct": false,
            "version": "4.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "pino",
            "direct": false,
            "version": "^9.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "prelude-ls",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "prettier",
            "direct": false,
            "version": "3.8.3",
            "ecosystem": "npm"
          },
          {
            "name": "punycode",
            "direct": false,
            "version": "2.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "pure-rand",
            "direct": false,
            "version": "8.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "resolve-from",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "semver",
            "direct": false,
            "version": "7.8.3",
            "ecosystem": "npm"
          },
          {
            "name": "shebang-command",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "shebang-regex",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "strip-json-comments",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "supports-color",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "tinyglobby",
            "direct": false,
            "version": "0.2.17",
            "ecosystem": "npm"
          },
          {
            "name": "ts-api-utils",
            "direct": false,
            "version": "2.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "tsx",
            "direct": false,
            "version": "4.23.1",
            "ecosystem": "npm"
          },
          {
            "name": "type-check",
            "direct": false,
            "version": "0.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "typescript",
            "direct": false,
            "version": "5.9.3",
            "ecosystem": "npm"
          },
          {
            "name": "typescript",
            "direct": false,
            "version": "^5.4.5",
            "ecosystem": "npm"
          },
          {
            "name": "typescript-eslint",
            "direct": false,
            "version": "8.61.0",
            "ecosystem": "npm"
          },
          {
            "name": "undici-types",
            "direct": false,
            "version": "8.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "uri-js",
            "direct": false,
            "version": "4.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "which",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "word-wrap",
            "direct": false,
            "version": "1.2.5",
            "ecosystem": "npm"
          },
          {
            "name": "yocto-queue",
            "direct": false,
            "version": "0.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "BouncyCastle.Cryptography",
            "direct": false,
            "version": "2.4.0",
            "ecosystem": "nuget"
          },
          {
            "name": "Newtonsoft.Json",
            "direct": false,
            "version": "13.0.3",
            "ecosystem": "nuget"
          },
          {
            "name": "System.IdentityModel.Tokens.Jwt",
            "direct": false,
            "version": "7.5.1",
            "ecosystem": "nuget"
          },
          {
            "name": "cryptography",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "cryptography",
            "direct": false,
            "version": "49.0.0",
            "ecosystem": "pypi"
          },
          {
            "name": "fastapi",
            "direct": false,
            "version": "0.110.1",
            "ecosystem": "pypi"
          },
          {
            "name": "paramiko",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "prometheus-client",
            "direct": false,
            "version": "0.20.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pycryptodome",
            "direct": false,
            "version": "3.20.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pycryptodome",
            "direct": false,
            "version": "3.23.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pydantic-settings",
            "direct": false,
            "version": "2.2.1",
            "ecosystem": "pypi"
          },
          {
            "name": "pyjwt",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "pyopenssl",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "python-dotenv",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "pypi"
          },
          {
            "name": "requests",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "requests",
            "direct": false,
            "version": "2.34.2",
            "ecosystem": "pypi"
          },
          {
            "name": "structlog",
            "direct": false,
            "version": "24.1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "uvicorn",
            "direct": false,
            "version": "0.29.0",
            "ecosystem": "pypi"
          },
          {
            "name": "ed25519",
            "direct": false,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "jwt",
            "direct": false,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "net-ssh",
            "direct": false,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "pg",
            "direct": false,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "puma",
            "direct": false,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "rails",
            "direct": false,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "rbnacl",
            "direct": false,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "rspec-rails",
            "direct": false,
            "version": null,
            "ecosystem": "rubygems"
          },
          {
            "name": "rubocop",
            "direct": false,
            "version": null,
            "ecosystem": "rubygems"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 214,
        "direct_count": 6,
        "indirect_count": 208
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 7,
        "merged_prs": 17,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 14
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "leonacostaok",
          "commits": 248,
          "avatar_url": "https://avatars.githubusercontent.com/u/7293791?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "codeql.yml",
        "github-packages.yml",
        "mcp-registry.yml",
        "release.yml",
        "scorecard.yml",
        "supply-chain-audit.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        "eslint.config.js"
      ],
      "has_editorconfig": true,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": null,
            "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "13 out of 13 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 5,
            "reason": "badge detected: Passing",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/25 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 3,
            "reason": "project has 1 contributing companies or organizations -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 10,
            "reason": "project is fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 9,
            "reason": "dependency not pinned by hash detected -- score normalized to 9",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 9,
            "reason": "SAST tool detected but not run on all commits",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 10,
            "reason": "GitHub workflow tokens follow principle of least privilege",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "52 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "409726240647384572233737a78f2a66bd9854d1",
        "ran_at": "2026-07-27T03:49:10Z",
        "aggregate_score": 7.1,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": true,
      "has_security_policy": true,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-26T17:49:06Z",
      "oldest_open_prs": [
        {
          "number": 6,
          "created_at": "2026-07-15T07:31:01Z",
          "last_comment_at": "2026-07-23T10:16:56Z",
          "last_comment_author": "leonacostaok"
        },
        {
          "number": 7,
          "created_at": "2026-07-15T07:31:03Z",
          "last_comment_at": "2026-07-23T10:16:58Z",
          "last_comment_author": "leonacostaok"
        },
        {
          "number": 22,
          "created_at": "2026-07-21T13:54:49Z",
          "last_comment_at": "2026-07-23T10:17:00Z",
          "last_comment_author": "leonacostaok"
        },
        {
          "number": 23,
          "created_at": "2026-07-21T13:54:51Z",
          "last_comment_at": "2026-07-23T10:17:01Z",
          "last_comment_author": "leonacostaok"
        },
        {
          "number": 24,
          "created_at": "2026-07-21T13:54:52Z",
          "last_comment_at": "2026-07-23T10:17:03Z",
          "last_comment_author": "leonacostaok"
        },
        {
          "number": 25,
          "created_at": "2026-07-21T13:55:04Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 27,
          "created_at": "2026-07-23T00:48:07Z",
          "last_comment_at": "2026-07-23T10:17:05Z",
          "last_comment_author": "leonacostaok"
        }
      ],
      "last_merged_pr_at": "2026-07-26T17:47:26Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/quantakrypto/pqc-tools",
    "host": "github.com",
    "name": "pqc-tools",
    "owner": "quantakrypto"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 67,
      "inputs": {
        "security": 77,
        "vitality": 75,
        "community": 55,
        "governance": 43,
        "engineering": 90
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 75,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 58,
            "inputs": {
              "commits_last_year": 254,
              "human_commit_share": 0.98,
              "days_since_last_push": 0,
              "active_weeks_last_year": 6
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "6/52 weeks with commits",
                "points": 4.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 6
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "254 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 254
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 4,
              "latest_release_tag": "v1",
              "releases_from_tags": false,
              "days_since_latest_release": 3,
              "mean_days_between_releases": 2.5
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "4 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 3 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 3
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~2.5 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 2.5
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 55,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 15,
            "inputs": {
              "forks": 0,
              "stars": 9,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "9 stars",
                "points": 14.6,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 9
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 66,
            "inputs": {
              "packages": [
                "@quantakrypto/mcp",
                "@quantakrypto/core",
                "@quantakrypto/agent",
                "@quantakrypto/qscan",
                "@quantakrypto/sieve",
                "@quantakrypto/qprobe"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 8476
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "8,476 downloads/month across npm",
                "points": 52.4,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 8476,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 43,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 13,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "at_risk",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 39,
            "inputs": {
              "merged_prs": 17,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 14
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "17/31 decided PRs merged",
                "points": 21,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 17,
                      "decided": 31
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/25 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 38,
            "inputs": {
              "followers": 1,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "quantakrypto",
              "public_repos": 4,
              "account_age_days": 34
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "1 followers of quantakrypto",
                "points": 2.2,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 1,
                      "login": "quantakrypto"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "4 public repos, account ~0 yr old",
                "points": 5.3,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 4
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "@quantakrypto/mcp",
                "@quantakrypto/core",
                "@quantakrypto/agent",
                "@quantakrypto/qscan",
                "@quantakrypto/sieve",
                "@quantakrypto/qprobe"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 4
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "6 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 6,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 4 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 4
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "13 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 13
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "excellent",
        "name": "Engineering Quality",
        "value": 90,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "excellent",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": true,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "7 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": "eslint.config.js",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.js"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 6.4,
                "status": "met",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "13 out of 13 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "topics": [
                "crypto-agility",
                "cryptography",
                "harvest-now-decrypt-later",
                "infosec",
                "post-quantum",
                "pqc",
                "pqc-migration",
                "pqc-readiness",
                "pqcrypto",
                "q-day",
                "quantum",
                "quantum-readiness",
                "security-training",
                "encryption-strategy",
                "pqc-certification",
                "cbom",
                "mcp",
                "post-quantum-cryptography",
                "sbom",
                "nist"
              ],
              "has_wiki": false,
              "homepage": "https://quantakrypto.com/tools",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://quantakrypto.com/tools",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "20 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 20
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "good",
        "name": "Security",
        "value": 77,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "good",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Branch-Protection, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "branch_protection",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 71,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 7.1
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "13 out of 13 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "badge detected: Passing",
                "points": 1.2,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/25 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is fuzzed",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 9",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool detected but not run on all commits",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "GitHub workflow tokens follow principle of least privilege",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "52 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:@quantakrypto/mcp@0.5.2 runtime dependency closure — what installing the published package pulls in — 2 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:@quantakrypto/mcp@0.5.2",
                  "assessed": 2
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 0,
              "affected_packages": 0,
              "assessed_packages": 2,
              "unassessed_packages": 0,
              "affected_by_severity": "none",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "no indirect dependency carries a known advisory",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "no_indirect_advisories",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 2,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 1
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 70,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.918,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "90 of 98 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 90,
                      "sampled": 98
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "package-lock.json"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "packages/action/tsconfig.json",
                "packages/agent/tsconfig.json",
                "packages/core/tsconfig.json",
                "packages/mcp/tsconfig.json",
                "packages/qprobe/tsconfig.json",
                "packages/qscan/tsconfig.json",
                "packages/sieve/tsconfig.json",
                "tsconfig.json"
              ],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "packages/core/test/benchmark/recall/csharp/Acme.Signing.csproj",
                "packages/core/test/benchmark/recall/go/go.mod",
                "packages/core/test/benchmark/recall/java/pom.xml",
                "packages/core/test/benchmark/recall/rust/Cargo.toml"
              ],
              "dependency_bot_commit_share": 0.02
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "packages/core/test/benchmark/recall/csharp/Acme.Signing.csproj, packages/core/test/benchmark/recall/go/go.mod, packages/core/test/benchmark/recall/java/pom.xml (toolchain convention, no task runner)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "toolchain_convention",
                    "params": {
                      "files": "packages/core/test/benchmark/recall/csharp/Acme.Signing.csproj, packages/core/test/benchmark/recall/go/go.mod, packages/core/test/benchmark/recall/java/pom.xml"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": "eslint.config.js",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.js"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "packages/action/tsconfig.json, packages/agent/tsconfig.json, packages/core/tsconfig.json, packages/mcp/tsconfig.json, packages/qprobe/tsconfig.json, packages/qscan/tsconfig.json, packages/sieve/tsconfig.json, tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "packages/action/tsconfig.json, packages/agent/tsconfig.json, packages/core/tsconfig.json, packages/mcp/tsconfig.json, packages/qprobe/tsconfig.json, packages/qscan/tsconfig.json, packages/sieve/tsconfig.json, tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "2 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 2,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 9",
                "points": 9,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 59062,
              "source_files_sampled": 454,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/454 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 454,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "moderate",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": true,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-27T03:49:20.509862Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/q/quantakrypto/pqc-tools.svg",
  "full_name": "quantakrypto/pqc-tools",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsnpm.