Raw JSON report machine-readable
{
"data": {
"repo": {
"topics": [
"crypto-agility",
"cryptography",
"harvest-now-decrypt-later",
"infosec",
"post-quantum",
"pqc",
"pqc-migration",
"pqc-readiness",
"pqcrypto",
"q-day",
"quantum",
"quantum-readiness",
"security-training",
"encryption-strategy",
"pqc-certification",
"cbom",
"mcp",
"post-quantum-cryptography",
"sbom",
"nist"
],
"is_fork": false,
"size_kb": 2378,
"has_wiki": false,
"homepage": "https://quantakrypto.com/tools",
"languages": {
"C": 11808,
"C#": 13339,
"Go": 13560,
"HCL": 448,
"PHP": 259,
"Java": 9201,
"Ruby": 9206,
"Rust": 11638,
"Bicep": 214,
"Shell": 1100,
"Swift": 110,
"Kotlin": 2093,
"Python": 18432,
"Dockerfile": 1319,
"JavaScript": 146066,
"TypeScript": 1911224
},
"pushed_at": "2026-07-26T17:47:28Z",
"created_at": "2026-06-09T04:17:00Z",
"owner_type": "Organization",
"updated_at": "2026-07-26T17:47:47Z",
"description": "Open-source post-quantum readiness tooling by quantakrypto",
"is_archived": false,
"is_disabled": false,
"license_spdx": "Apache-2.0",
"default_branch": "main",
"license_spdx_raw": "Apache-2.0",
"primary_language": "TypeScript",
"significant_languages": [
"TypeScript"
]
},
"owner": {
"blog": "https://quantakrypto.com",
"name": "@QuantaKrypto",
"type": "Organization",
"login": "quantakrypto",
"company": null,
"location": "Switzerland",
"followers": 1,
"avatar_url": "https://avatars.githubusercontent.com/u/295786989?v=4",
"created_at": "2026-06-22T08:34:25Z",
"is_verified": null,
"public_repos": 4,
"account_age_days": 34
},
"license": {
"state": "standard",
"spdx_id": "Apache-2.0",
"raw_spdx": "Apache-2.0",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v1",
"kind": "other",
"published_at": "2026-07-23T05:57:13Z"
},
{
"tag": "v0.5.0",
"kind": "minor",
"published_at": "2026-07-20T15:46:31Z"
},
{
"tag": "v0.4.4",
"kind": "patch",
"published_at": "2026-07-19T08:10:54Z"
},
{
"tag": "v0.4.3",
"kind": "patch",
"published_at": "2026-07-15T18:46:08Z"
}
],
"recent_commits": [
{
"oid": "409726240647384572233737a78f2a66bd9854d1",
"body": "…lockfile depth, parallel double-stat) (#38)\n\nFour post-1.0-roadmap detection items on the benchmark-guarded surface.\nThe F1 = 1.000 precision/recall benchmark is unchanged (zero FP, zero FN).\n\n- PHP composer.json / composer.lock dependency scanning: add `composer` to\n DependencyEcosystem, a curate\n[…]\nrf; file set and detection output are byte-identical.\n\nRebuilds the action bundle. Full gate green (test, typecheck, lint, api:check,\nformat:check).\n\nCo-authored-by: León Acosta <laion.cj91@gmail.com>",
"is_bot": false,
"headline": "feat(core): detection quick-wins (PHP composer, JS recall edges, npm …",
"author_name": "Leon Acosta",
"author_login": "leonacostaok",
"committed_at": "2026-07-26T17:47:26Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9a8b0e6f5f620a4aebcc1a18e1766355189b0802",
"body": "…(#37)\n\nQuantify harvest-now-decrypt-later exposure so the migration backlog ranks by\nreal risk instead of finding counts. Exposure per finding =\ncrypto-vulnerability x data-sensitivity x Mosca-factor (retention + secrecy\nlifetime vs the quantum-threat horizon; Mosca's inequality made concrete).\n\nco\n[…]\nrprintFinding().\n\nSemVer: minor (additive API + CLI). Tests: parser, glob, binding, Mosca math,\nsummary, scaffold, CLI wiring. api:docs regenerated.\n\nCo-authored-by: León Acosta <laion.cj91@gmail.com>",
"is_bot": false,
"headline": "feat(hndl): data-risk quantifier (hndl.yml, qscan --hndl, hndl init) …",
"author_name": "Leon Acosta",
"author_login": "leonacostaok",
"committed_at": "2026-07-26T17:27:43Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "dcaf36631a8664ef3ad03fd1b6e542a46b9d6bdf",
"body": "Every finding in the qScan --format json output now carries a top-level\nfingerprint field, and each SARIF result mirrors it in properties.fingerprint\nalongside the existing partialFingerprints. The value reuses the baseline\nidentity fingerprintFinding: sha256(ruleId | normalized POSIX repo-relative\n\n[…]\ntinctness across rule/path/\ncontext, the rule+path fallback, cross-format equality (JSON = SARIF =\nbaseline), and stability under snippet redaction.\n\nCo-authored-by: León Acosta <laion.cj91@gmail.com>",
"is_bot": false,
"headline": "core: stable finding fingerprints in JSON and SARIF output (#36)",
"author_name": "Leon Acosta",
"author_login": "leonacostaok",
"committed_at": "2026-07-26T17:22:32Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9e73eb43a2fafd1922746309b664a5d0afdd5277",
"body": "…m the scan\n\nmanifests were exempt from the file-size cap entirely; a hostile or broken\nlockfile could be read unbounded. give them a generous 16 MiB ceiling instead\n(real monorepo lockfiles are well under it). pure size logic, no detection change.",
"is_bot": false,
"headline": "fix(core): cap manifest read size so a pathological lockfile can't oo…",
"author_name": "Leon Acosta",
"author_login": "leonacostaok",
"committed_at": "2026-07-26T15:45:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2c4dc93b0637a2f9d252c6e318863bcd976ed230",
"body": "everything the backlogs tracked as P0/P1 has shipped (0.5.x: 52 detectors,\n14 languages, qprobe, openvex, standards profiles, frozen api). what's left is\naccuracy nice-to-haves, the declarative detector factory, perf, and a golden-file\ncorpus. reconciled against the code 2026-07-26.",
"is_bot": false,
"headline": "docs: reconciled post-1.0 roadmap (supersedes the old audit backlogs)",
"author_name": "Leon Acosta",
"author_login": "leonacostaok",
"committed_at": "2026-07-26T15:45:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c68538aad98554ccd772906da533063ed2e14162",
"body": null,
"is_bot": false,
"headline": "docs: version-support policy for the 0.5.x packages + the v1 action tag",
"author_name": "Leon Acosta",
"author_login": "leonacostaok",
"committed_at": "2026-07-26T15:45:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a4b5f48fa7eabd291dfac2cdeb054188184eb7ad",
"body": "…ity vs cryptodeps\n\nadds tink across com.google.crypto.tink (maven), tink-crypto/tink-go +\ngoogle/tink/go (go), and pypi tink. flagged as rsa/ecdsa/eddsa signatures\nplus ecies hybrid, so hndl-exposed. catalog now 81 entries.\n\ncrypto-js stays out on purpose: it is symmetric/hash/hmac/pbkdf2 only, no\nasymmetric public-key surface, same scope boundary as the password kdfs.\ncomparison doc updated to reflect full parity on the pubkey packages\ncryptodeps documents. re-bundled the action dist.",
"is_bot": false,
"headline": "feat(core): catalog google tink (maven/go/pypi); note full pubkey par…",
"author_name": "Leon Acosta",
"author_login": "leonacostaok",
"committed_at": "2026-07-26T15:44:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0bd18cb4d42fb129aa3dd8f3f37a0dbf7da9712d",
"body": "two head-to-head comparisons with verified coverage: algorithm matrix,\necosystem/package parity, extras and honest gaps vs cryptodeps, plus the\nfips 203/204/205, sp 800-208, cnsa 2.0 and ir 8547 mapping vs nist.\ncounts verified against the built registry and dep catalog, not prose.",
"is_bot": false,
"headline": "docs: add comparison vs qramm/cryptodeps and vs nist",
"author_name": "Leon Acosta",
"author_login": "leonacostaok",
"committed_at": "2026-07-26T15:44:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1a0aac3fc77fcf9520a27e4f7c51f5f9f0640655",
"body": "* docs: fix dead links, stale versioning note, and API-reference doc extraction\n\n- SUPPLY-CHAIN.md: repair the broken COMPLIANCE.md §5 link and an unfinished sentence\n- ADRs 0003/0005: point OBJECTIVES.md links at ../OBJECTIVES.md so they resolve\n- VERSIONING.md: drop the specific stale version numb\n[…]\nlve re-exported symbols' kind/summary from\n their source module. Regenerated API.md (276/331 summaries now correct; surface\n snapshot unchanged).\n\n* docs: fix unfinished 'See and' phrase in ADR 0005",
"is_bot": false,
"headline": "docs: fix unfinished 'See and' phrase in ADR 0005 (#35)",
"author_name": "Leon Acosta",
"author_login": "leonacostaok",
"committed_at": "2026-07-26T15:42:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "27ad3e3f10f339545be148d4244a7a8e84d9cf44",
"body": "…traction (#34)\n\n- SUPPLY-CHAIN.md: repair the broken COMPLIANCE.md §5 link and an unfinished sentence\n- ADRs 0003/0005: point OBJECTIVES.md links at ../OBJECTIVES.md so they resolve\n- VERSIONING.md: drop the specific stale version numbers (pre-1.0, 0.x range)\n- gen-api-reference.mjs: anchor doc sum\n[…]\nolve re-exported symbols' kind/summary from\n their source module. Regenerated API.md (276/331 summaries now correct; surface\n snapshot unchanged).\n\nCo-authored-by: León Acosta <laion.cj91@gmail.com>",
"is_bot": false,
"headline": "docs: fix dead links, stale versioning note, and API-reference doc ex…",
"author_name": "Leon Acosta",
"author_login": "leonacostaok",
"committed_at": "2026-07-26T15:37:15Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a921a52c6e6a8d6cb9382a711b6573156ef33068",
"body": "chore: move the observatory worker to its own repository",
"is_bot": false,
"headline": "Merge pull request #33 from quantakrypto/chore/remove-observatory",
"author_name": "Leon Acosta",
"author_login": "leonacostaok",
"committed_at": "2026-07-25T03:26:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "74cec18da463e58ed805258009103b469c8f57fd",
"body": "The PQC observatory worker now lives at github.com/quantakrypto/pqc-observatory,\na self-contained repo that probes public hosts via openssl (it must not depend on\nqProbe, which is ownership-gated for endpoints you control). Removed from here:\npackages/observatory, ADR 0007, the root observatory script, and the pg devDep.",
"is_bot": false,
"headline": "chore: move the observatory worker to its own repository",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-25T03:15:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e7d35f4f5b15252f45e217a05eb15fbd6da50a0e",
"body": "Observatory: internal PQC-readiness probe worker (ADR 0007)",
"is_bot": false,
"headline": "Merge pull request #32 from quantakrypto/feat/observatory-worker",
"author_name": "Leon Acosta",
"author_login": "leonacostaok",
"committed_at": "2026-07-25T02:44:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ba8063706e85acc49fdb268b81af3d18fe21976d",
"body": null,
"is_bot": false,
"headline": "docs: OpenSSF Best Practices pre-filled answers",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-25T02:37:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c0f88aeeae962a56770bc0420d02cc1eccb7224c",
"body": "Adds packages/observatory (private, unpublished): a monthly worker that probes a\nfixed panel of public hosts for PQC-hybrid key exchange (X25519MLKEM768) and\ncertificate posture, writing idempotent per-month results and a rollup to\nPostgres for the site's public /observatory page.\n\nReuses qProbe's u\n[…]\n. See docs/adr/0007.\n\nThe published packages are untouched: qprobe unchanged, zero-runtime-dependency\nand offline-boundary invariants still hold. pg is a devDependency of the\nobservatory package only.",
"is_bot": false,
"headline": "feat(observatory): internal PQC-readiness probe worker + ADR 0007",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-25T02:37:50Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "008333afb319a993c8b0f9d16c2277ae1b8da3dd",
"body": null,
"is_bot": false,
"headline": "docs: add OpenSSF Best Practices passing badge (#31)",
"author_name": "Leon Acosta",
"author_login": "leonacostaok",
"committed_at": "2026-07-24T02:18:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e68ab13934111dfc9c7fa5ee8ee5669979103093",
"body": "- qprobe/mlkem768: replace biased modulo sampling with unbiased rejection\n sampling for the throwaway probe key (js/biased-cryptographic-random)\n- sieve/protocol fromB64: replace the /=+$/ trailing-trim (O(n^2) on the\n untrusted SUT response) with a linear scan (js/polynomial-redos)\n- mcp/http: di\n[…]\nests pass, including the property-based fuzz tests on the patched\nparsers. Trailing-slash trims on trusted config input (walk globs, agent\nbaseURL) are dismissed separately as not attacker-controlled.",
"is_bot": false,
"headline": "fix(security): resolve CodeQL findings in untrusted-input paths (#30)",
"author_name": "Leon Acosta",
"author_login": "leonacostaok",
"committed_at": "2026-07-23T10:44:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1e2991cc568d1225ae134a323a5dd68b8f731841",
"body": "Add fast-check (dev-only) property tests that fuzz the parsers that consume\nattacker-controlled bytes: qProbe's TLS ServerHello / record / SSH KEXINIT /\nX.509 OID decoders, and Sieve's SUT response decoder. Each runs thousands of\nrandom inputs asserting the robustness contract (safe wrappers never t\n[…]\nhrow only their typed error, never a raw crash). All green,\nso the parsers hold; the tests stand as a regression guard and satisfy the\nOpenSSF Scorecard fuzzing criterion. No runtime dependency added.",
"is_bot": false,
"headline": "test: property-based fuzzing of the untrusted-input parsers (#29)",
"author_name": "Leon Acosta",
"author_login": "leonacostaok",
"committed_at": "2026-07-23T10:17:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e769591f56bef2b4bb30401d7c29836b9b7cd7a5",
"body": "* ci: add CodeQL SAST workflow (pinned)\n\n* ci: move packages:write to job scope (least-privilege top level)",
"is_bot": false,
"headline": "ci: add CodeQL SAST workflow (#28)",
"author_name": "Leon Acosta",
"author_login": "leonacostaok",
"committed_at": "2026-07-23T08:51:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b346991abc40eef0fa3d13f84e5ba1b7d714bec4",
"body": "Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 1.1.15 to 1.1.16.\n- [Release notes](https://github.com/juliangruber/brace-expansion/releases)\n- [Commits](https://github.com/juliangruber/brace-expansion/compare/v1.1.15...v1.1.16)\n\n---\nupdated-dependencies:\n- dependency-n\n[…]\non\n dependency-version: 1.1.16\n dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "deps: bump brace-expansion from 1.1.15 to 1.1.16 (#26)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-23T08:27:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c6822434ebae7fcb5f96a416d96b3b5ae93e89f0",
"body": "Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.2.0 to 4.3.0.\n- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)\n- [Commits](https://github.com/nodeca/js-yaml/compare/4.2.0...4.3.0)\n\n---\nupdated-dependencies:\n- dependency-name: js-yaml\n dependency-version: 4.3.0\n dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "deps: bump js-yaml from 4.2.0 to 4.3.0 (#20)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-23T08:27:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7918654d8e3073d5c90fbd44a22e06f2533ffe67",
"body": "…thub.com)",
"is_bot": false,
"headline": "mirror container + npm packages to github packages (ghcr + npm.pkg.gi…",
"author_name": "Leon Acosta",
"author_login": "leonacostaok",
"committed_at": "2026-07-23T06:33:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7f18694debd4960bfb23da4bc2d37aebed4c52ff",
"body": null,
"is_bot": false,
"headline": "bump docker image to @quantakrypto/mcp 0.5.2",
"author_name": "Leon Acosta",
"author_login": "leonacostaok",
"committed_at": "2026-07-23T06:12:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7e67f89ca3f6145968b281c9e5c0b61ec4b97bf6",
"body": null,
"is_bot": false,
"headline": "make mcp-registry publish idempotent (skip already-published version)",
"author_name": "Leon Acosta",
"author_login": "leonacostaok",
"committed_at": "2026-07-23T06:01:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4c6acc5d7ad2adc95434585c352818ec915af533",
"body": "… em dash",
"is_bot": false,
"headline": "shorten root action description under 125 chars for marketplace, drop…",
"author_name": "Leon Acosta",
"author_login": "leonacostaok",
"committed_at": "2026-07-23T05:31:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3ac2632582f46ef0bd7e7bd118d7dbdc3632c178",
"body": null,
"is_bot": false,
"headline": "add root action.yml so the action can list on the github marketplace",
"author_name": "Leon Acosta",
"author_login": "leonacostaok",
"committed_at": "2026-07-23T05:18:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bc6f17d4e5de400c2534d595886273c850eedcf8",
"body": null,
"is_bot": false,
"headline": "add 400x400 logo for marketplace/directory listings",
"author_name": "Leon Acosta",
"author_login": "leonacostaok",
"committed_at": "2026-07-23T05:15:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "192dd4c4153d21e79929d234b246198b855e62ce",
"body": "…rver",
"is_bot": false,
"headline": "add root .mcp.json so cursor / open-plugins clients can import the se…",
"author_name": "Leon Acosta",
"author_login": "leonacostaok",
"committed_at": "2026-07-23T03:58:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6264359813afcda7eb217ceca17e10130cba0414",
"body": null,
"is_bot": false,
"headline": "shorten server.json description to fit the registry 100-char limit",
"author_name": "Leon Acosta",
"author_login": "leonacostaok",
"committed_at": "2026-07-23T03:38:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f134a0efdc802e5d96cce9717c9e86b2fc4bde1a",
"body": "runs mcp-publisher with github-oidc auth, so the io.github.quantakrypto namespace\nis authorized by the org's own actions token. no keys, no interactive login.",
"is_bot": false,
"headline": "add workflow to publish server.json to the mcp registry via oidc",
"author_name": "Leon Acosta",
"author_login": "leonacostaok",
"committed_at": "2026-07-23T03:36:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6147d56bb6432648d494e1243ccad09bbe765c56",
"body": "the mcp registry verifies npm ownership by reading an mcpName field from the\nPUBLISHED package.json, so we ship a tiny 0.5.2 that adds it plus a server.json\n(namespace io.github.quantakrypto/pqc-tools, npm stdio package + the hosted\nstreamable-http remote). metadata only, no code change. after this publishes,\nlisting on the registry is just: mcp-publisher login github && mcp-publisher publish.",
"is_bot": false,
"headline": "mcp 0.5.2: add mcpName + server.json for the official mcp registry",
"author_name": "Leon Acosta",
"author_login": "leonacostaok",
"committed_at": "2026-07-23T03:32:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4dbf1446a1f4afaf6f8183cffebb8a9736899a5d",
"body": "- tool input schemas: every array field (findings/verdicts, score_delta\n before/after) now has an 'items' object schema instead of a bare type:array.\n mcp inspectors flag the bare form ('missing items definition') and it drags\n the tool-definition-quality score.\n- bump @quantakrypto/mcp to 0.5.1 + changelog. pairs with the already-landed\n resources/templates/list fix (ed6ecfd). package-only patch — core/qscan/etc\n stay 0.5.0 (unreleased work still parked under [Unreleased]).",
"is_bot": false,
"headline": "mcp 0.5.1: describe tool array items, cut patch release",
"author_name": "Leon Acosta",
"author_login": "leonacostaok",
"committed_at": "2026-07-23T02:24:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ed6ecfdf3452c0563624a260f2dd42ad784f851a",
"body": "the server advertises the 'resources' capability, so spec-compliant clients\n(and mcp directory health checks like glama's inspector) call\nresources/templates/list during discovery. we only expose fixed-uri resources,\nno uri templates — but we were falling through to -32601 method-not-found, which\ntrips those clients. return an empty { resourceTemplates: [] } instead.\n\nadded a test asserting it succeeds empty rather than erroring.",
"is_bot": false,
"headline": "handle resources/templates/list instead of 404ing discovery",
"author_name": "Leon Acosta",
"author_login": "leonacostaok",
"committed_at": "2026-07-23T01:31:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7c58bc376dd6bd3ac7bf54d9f04018b428b3863c",
"body": "the recall/corpus benchmark ships fake dependency manifests (pom.xml, go.mod,\ncargo.toml, requirements.txt, csproj, gemfile, package.json...) with pinned deps\non purpose — thats the test data for crypto-dependency detection. when one of\nthose pinned versions gets a security advisory (jackson-databin\n[…]\ncore).\n\nscope each fixture ecosystem under packages/core/test/benchmark/** with\nlimit 0 + ignore '*' so dependabot leaves the test corpus alone. real dev deps\n(npm at /) and action SHAs are untouched.",
"is_bot": false,
"headline": "stop dependabot from failing on scanner test fixtures",
"author_name": "Leon Acosta",
"author_login": "leonacostaok",
"committed_at": "2026-07-23T00:47:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "33b823beb2e8dbdce12efe3eef7f17de3f9ce252",
"body": "glama (and other mcp hosts) sandbox the server: they run initialize +\ntools/list over stdio and expect a valid reply. this image installs the\npublished @quantakrypto/mcp and starts the stdio transport, so that check\npasses. base image + package are both pinned; glama.json claims the listing.\nbump both pins on release.",
"is_bot": false,
"headline": "add dockerfile + glama.json for mcp directory listing",
"author_name": "Leon Acosta",
"author_login": "leonacostaok",
"committed_at": "2026-07-22T17:16:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e6cca652a7e4f929c7d81b31501bcf3a72690295",
"body": "the hosted MCP gateway described as future work in HOSTING.md now exists and runs in\nproduction (quantakrypto/mcp-gateway, live at mcp.quantakrypto.com). add:\n- HOSTING.md: a reference-implementation callout up top + note on §3 that oauth 2.1 is\n what the gateway implements (better-auth, 30-day tok\n[…]\nant to use it?\" callout with the `claude mcp add --transport http` command,\n the content-only tool surface (fs/network tools withheld), and the gateway repo link.\ndocs only; no code/behaviour change.",
"is_bot": false,
"headline": "docs(mcp): point HOSTING + README at the now-live hosted gateway",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-22T04:12:51Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a895f0a8b4e125f8df672a3d9e5e22b58d8ca612",
"body": "…e dir as a module\n\n`node --test scripts/test/` (a directory arg) runs the tests on node 20, but on node\n21+ the runner resolves the path as a module and fails with \"Cannot find module\n.../scripts/test\", reddening build+test on the node 22 matrix leg. use\n`scripts/test/*.test.mjs` — shell-expanded to the literal file, exactly like the\nper-workspace `test/*.test.ts` scripts already do — which both node versions run.",
"is_bot": false,
"headline": "fix(test): explicit glob for test:scripts so node 22 doesn't treat th…",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-21T03:42:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fb3eecc23f4e8bba6916fbe8f29e843e28acb2ac",
"body": "… EPIPE\n\nthe evidence signer (--sign/--timestamp) shells out via spawnSync with the payload on\nstdin. a command that exits before draining stdin (e.g. `false`) makes spawnSync\nsurface an EPIPE in res.error on linux — not macos — even though the child ran and\nreturned an exit status. the old code che\n[…]\nt a non-zero exit status (or terminating signal) FIRST; only fall back to\nres.error for a genuine spawn failure (e.g. ENOENT). deterministic across platforms.\naction dist re-bundled (it embeds qscan).",
"is_bot": false,
"headline": "fix(sign): report a signer's non-zero exit before an incidental stdin…",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-21T03:38:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e397c9e6f06f7c6e190bcbd5857fea0e18907880",
"body": null,
"is_bot": false,
"headline": "chore(action): re-bundle dist for the 0.5.0 release",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T15:46:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d7917f17c20ee7287a9427f03eaf3a30e449e11b",
"body": null,
"is_bot": false,
"headline": "docs: design for hosted OAuth-gated multi-tenant MCP gateway",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T14:27:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ede29ffa0abc3c385a2ff18b246875433e7a9775",
"body": "Per the cleanup request: remove point-in-time audit process artifacts and\nplanning docs, keep the enduring standards/reference/decision documentation, and\nadd a clear statement of what each library is for and what we're building toward.\n\nRemoved (in the previous commit): docs/audits/, docs/AUDIT.md,\n[…]\nMODEL (§8 controls table + the agent-line note refreshed to\nthe completed/fixed status), COMPLIANCE, CONFIG, SECURITY, CONTRIBUTING, and the\nGitHub templates — no broken links to removed files remain.",
"is_bot": false,
"headline": "docs: prune audit logs & plans; add OBJECTIVES; fix cross-references",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T12:54:32Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b2d28b1b7a8290bf8271ff5e7074949e5f75bd0d",
"body": "…leanup\n\nDetector fixes (each with a regression test; suite 1118 -> 1123):\n- proxy (H1/H2/L1/L2): the global marker gate was too narrow, silently dropping\n canonical HAProxy (bind ssl crt, no crt-store) and Traefik (certFile/keyFile,\n no certResolver) configs. Replaced with per-rule self-gating; E\n[…]\n, plans, and 0.4 runbook (docs/audits/,\nAUDIT.md, ROADMAP.md, how-to-test-0.4.md, superpowers/) — the enduring 'why' is\nin the ADRs; the new OBJECTIVES.md + index rewrite land in the follow-up commit.",
"is_bot": false,
"headline": "fix: adversarial-audit findings in the 5 new detectors + begin docs c…",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T12:48:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a36bd28b8537e7f6a5970afb5ef52124d4e5faf3",
"body": "…/gRPC TLS, code-signing, weak-hash\n\nFresh coverage-gap research (3 Fable agents: assess + 2 web-research passes)\nidentified high-value PQC surfaces the scanner missed. Adds 5 detectors\n(47->52 detectors, 277->297 rules), scope kept to PQC + quantum-adjacent:\n\n- solidity: 14th source language pack (\n[…]\nassword hashing.\n\nEach with self-contained tests; benchmark F1=1.000, zero FP held. Wired into\nregistry + coverage constants + comment table; docs/README/ROADMAP/CHANGELOG\nupdated. Suite 1065 -> 1118.",
"is_bot": false,
"headline": "feat: 5 new detection surfaces — Solidity/blockchain, WebAuthn, proxy…",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T12:33:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a17925014e030608025c7c20cabd453b0f736f65",
"body": "…ant test\n\nAssessment (Fable) found two of my new packs under-reported HNDL, re-introducing\naudit bug P0-4: objc-seckey-ec and Dart ECKeyGenerator classified ambiguous EC\nkeygen as signature/ECDSA/hndl:false, while the whole fleet (java/python/c/swift/\ncloud-kms/ruby EC keygen) uses the HNDL-safe ke\n[…]\ns JWT coverage (added to JWT_HOST_EXTENSIONS); cloud-kms\nmasks comments so a commented-out YAML/JSON KeySpec can't fire; fixed the stale\n'JS/TS, Python, Go, Java' analyzable-languages doc in types.ts.",
"is_bot": false,
"headline": "fix: restore fleet HNDL convention for EC keygen + add catalog invari…",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T12:22:59Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8a1912474845689e60b42fe989db0b697d630c08",
"body": "…n barrel\n\nstandardsReviewStatus is exported by standards.ts but NOT re-exported by the\npublic index.js barrel, so standards-check.mjs crashed on import ('does not\nprovide an export'). Because the standards-currency step is advisory\n(continue-on-error), the crash went unnoticed in CI. Import both symbols from\nthe standards.js subpath. Add a build-aware smoke test to the guard suite so an\nimport regression can't silently break this advisory gate again.",
"is_bot": false,
"headline": "fix(standards-check): import from standards.js subpath, not the froze…",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T09:28:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0f029ee1b20c3aa7ceb39ed62417f634b5d4076d",
"body": "… + counts\n\n- ADR-0005 + THREAT-MODEL: F1 (blast-radius gate), F2 (system-role instruction/\n data separation), F3 (--max-findings spend cap) are fixed in code — mark them\n resolved instead of open, consistent with ROADMAP §1 (verified in loop.ts,\n remediate-pipeline.ts, triage-run.ts).\n- COMPLIAN\n[…]\nd; 0.4.4 published) across COMPLIANCE,\n VERSIONING, AUDIT, SUPPLY-CHAIN; test-count and 'supported vs benchmark-corpus\n languages' wording refreshed; CHANGELOG Fixed section for the audit hardening.",
"is_bot": false,
"headline": "docs: reconcile ADR-0005/THREAT-MODEL (F1-F3 fixed), refresh versions…",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T09:26:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "adaaa20f803d3dbc7544f867636a133723cc2cf4",
"body": "Detectors:\n- ssh-ca: add ssh-ca-config rule for TrustedUserCAKeys/HostCertificate/ssh-keygen\n -s — the canonical CA deployment previously yielded ZERO findings (H6); stop\n firing on program SOURCE files, so a vendored SSH lib's cert-type constant is\n not flagged as live config (M4).\n- spire: matc\n[…]\n (file:src/a.ts#L3) (M7); the @id digest\n includes triage status_notes so triaged/untriaged exports get distinct ids (L1).\n\nAll with regression tests. Suite 1052 -> 1063; benchmark F1=1.000, zero FP.",
"is_bot": false,
"headline": "fix: adversarial-audit findings in detectors, CBOM, and VEX",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T09:21:50Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9dc164c054073ff4e842c9c0b662a87cb8afd244",
"body": "…3, M6)\n\nThe line-by-line + sequential-regex guard was bypassable by ORDINARY code, so\nADR-0005's 'enforced by CI' claim was false. Rewrite with a single-pass lexer\n(code/string/comment classification, recursing into template ${…} as code) and\nwhole-file scanning with index->line mapping:\n- C1: Pret\n[…]\n: auto-merge runs on comment-stripped text, so a // gh pr merge note no\n longer false-positives; real exec('gh pr merge') strings still fire.\nRegression tests pin every bypass. Real repo stays clean.",
"is_bot": false,
"headline": "fix(guard): make offline-boundary bypass-resistant (audit C1-C3, H1-H…",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T09:09:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f550df96e8091c3cfc0e60aad84039f8991ad156",
"body": "ADR-0005's no-auto-merge rule covers workflows, not just package source. Extend\nthe guard to scan .github/workflows/*.yml for gh-pr-merge/--admin, with a\nknown-bad-fixture test. Workflows are currently clean.",
"is_bot": false,
"headline": "test: offline-boundary guard also scans workflows for auto-merge",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T08:57:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4f206c81f351977ad552485b798cc645c743a7c7",
"body": "Closes the post-1.0 coverage gaps:\n- objc-crypto (.m/.mm): Apple Security-framework SecKey* RSA/EC keygen, RSA/ECDSA\n signing, RSA encryption, ECDH — gated off .h to avoid C/C++ overlap.\n- dart-crypto (.dart): pointycastle + package:cryptography RSA/ECDSA/ECDH/Ed25519/X25519.\n- dkim-crypto: classic\n[…]\n1.000, zero FP). Repointed the coverage-honesty tests\noff .m/.dart (now supported) to genuinely-unsupported Lua/Perl. Docs updated\n(core README language table, ROADMAP, CHANGELOG). Suite 1002 -> 1052.",
"is_bot": false,
"headline": "feat: coverage packs — Objective-C, Dart, DKIM, SSH-CA, SPIFFE/SPIRE",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T08:54:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d4a660c018f4ca964b0479c7b57cc04abedfece4",
"body": "Adds scripts/check-offline-boundary.mjs — the gate ADR-0005 called for but that\n'did not exist yet'. It enforces the two-plane split by masked source scan:\ncore/mcp/sieve import no @quantakrypto/agent, make no outbound fetch/WebSocket/XHR\ncall, and read no LLM API key; qscan reaches the agent ONLY v\n[…]\n\n(e.g. core's redaction patterns). Wired into ci.yml + supply-chain-audit.yml;\nreject logic covered by known-bad fixtures in guards.test.mjs. ADR-0005 +\nROADMAP updated to reflect the gate now exists.",
"is_bot": false,
"headline": "feat: CI-enforce the ADR-0005 offline/agent boundary",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T08:38:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6511bcba849a3680b5720293ed71ecd9e612c59c",
"body": "The CycloneDX CBOM labelled every asset 'algorithm'. Now each finding is\nclassified into its proper CycloneDX 1.6 assetType: X.509 findings ->\ncertificate; private/public key material -> related-crypto-material (typed\nprivate-key/public-key); TLS -> protocol (protocolProperties.type tls);\neverything\n[…]\nhanged algorithmProperties. Every asset\nstill carries quantumVulnerable/harvestNowDecryptLater. Completes the refinement\nthe CBOM audit deferred. Grouping is now (assetType, algorithm, discriminator).",
"is_bot": false,
"headline": "feat: refine CBOM assetType (certificate / key-material / protocol)",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T08:32:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "691d02c5e8123ca734cf582d1b679e26dbcb50c2",
"body": "Emit the quantum-readiness posture as an OpenVEX 0.2.0 document so it flows into\nthe same supply-chain pipeline that already ingests CVE-based VEX. One statement\nper rule (synthetic QK-<ruleId> vulnerability, since PQC findings have no CVE),\nevery affected file:line product, status 'affected', the r\n[…]\nnly an operator can attest a mitigation). Deterministic output.\n\nNew core API toOpenVex + OpenVex* types; qScan --format vex / renderVex; help,\nqscan README, and CHANGELOG updated. Surface 326 -> 331.",
"is_bot": false,
"headline": "feat: OpenVEX 0.2.0 export (--format vex)",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T08:28:52Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4c03731db39cbb43d8a91dc0b7ec1fcade55f747",
"body": "Records the toolkit-export decision the audit flagged: the frozen external\nplugin point is the public Detector interface + scan({detectors}) / RuleMeta /\nFinding types; the lexical helpers (findingFromRule, eachMatch, comment maskers)\nstay INTERNAL so their signatures aren't frozen at 1.0 (exporting later is\nadditive). Clarifies the 'Adding a detector' guide is for in-repo contributors,\nresolving the read that external authors should import findingFromRule.",
"is_bot": false,
"headline": "docs: settle the detector plugin surface for the 1.0 freeze",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T08:13:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9dc5241fdc20fdbb701c7939dce7b90e5f9dde79",
"body": "… A.8.24\n\nROADMAP current-status count ~930 -> ~985 (historical audit figures left as-is).\nAdds a note to the A.8.24 evidence doc that verifyReadinessReport recomputes the\nintegrity hash to detect body tampering independently of the external signature.",
"is_bot": false,
"headline": "docs: refresh current test count + document verifyReadinessReport for…",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T08:12:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0143fc1c1d9aa17d93a1eb66fa146aa91320db67",
"body": null,
"is_bot": false,
"headline": "docs(changelog): note verifyReadinessReport API + test-hardening pass",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T08:05:38Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c4b541845dbed7653698d6405588f6744e1ad32e",
"body": "The anthropic/openai adapters had happy-path + one HTTP-error test but nothing\nfor the transport failure modes a BYOK integration actually hits. Add, to both:\na timeout that aborts a hung request via the AbortSignal, a propagated network\n(fetch-rejection) error, and — the load-bearing BYOK security \n[…]\n that\nthe API key travels ONLY in its auth header (x-api-key / Bearer) and never\nleaks into the request URL or body. Also gives the openai adapter the HTTP-error\ntest it was missing. Suite 979 -> 986.",
"is_bot": false,
"headline": "test: agent BYOK adapter error paths + API-key-only-in-header invariant",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T08:05:03Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "60d7d6a188b1244701529bc2d1d8b6c5b2d5020d",
"body": "The supply-chain / output guards (check-zero-deps, check-action-pins,\nvalidate-sarif) run as standalone CI steps, so nothing proved their FAILURE\npath still works — a guard whose reject logic silently broke would leave CI\ngreen while the invariant eroded. Add scripts/test/guards.test.mjs with\nknown-\n[…]\nd it\nto match check-action-pins.mjs; the CLI behaviour is unchanged.\n\nWired via a new root `test:scripts` (node --test), chained into `npm test` so\nCI's existing test step covers it. Suite 951 -> 979.",
"is_bot": false,
"headline": "test: cover the CI guard scripts + fix validate-sarif import side effect",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T08:01:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8d1e160d62558fc9b7f83a8e510e9c36c7eabb37",
"body": "stateful-hbs was the only built-in detector with no dedicated unit test. Add\none covering each distinctive token (LMS/HSS/pyhsslms/XMSS/XMSSMT/xmss_keypair),\nthe SP 800-208 SHAKE256 + 192-bit parameter variants, the XMSS-vs-XMSSMT\nno-double-count boundary, the bare-word negative cases, and the load-bearing\ninvariant that these approved-but-stateful schemes are signature/medium and\nNEVER hndl:true (they are a state-management hazard, not broken crypto).",
"is_bot": false,
"headline": "test: unit-test the stateful-HBS detector (SP 800-208)",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T07:56:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "efc2dbdcef08ad212358bec2fc05ff285cda93fe",
"body": "…eport\n\nSieve runner: add tests for the failure paths that had none — a SUT that never\nanswers rejects with TimeoutError (carrying request + timeoutMs); a SUT that\nexits mid-request, or fails to spawn, rejects the in-flight send with a\nSutCrashError that attaches the exit reason and captured stderr;\n[…]\nlicy verdicts, subject/tool metadata)\nwhile ignoring the excluded scan time / CBOM envelope / attestation block. Tests\ncover the classic 'edit the evidence' downgrade. Additive API surface (324->326).",
"is_bot": false,
"headline": "test: sieve runner crash/timeout coverage + evidence verifyReadinessR…",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T07:55:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4c69941bd3474c5d6a8ae4051fbbf2328128bbd5",
"body": "The qscan CLI and MCP tool tests were written when core.scan was a stub and\ntolerated every exit code (`[OK, FINDINGS, ERROR].includes(code)`) or both\nbranches of an if/else. core is fully implemented and main()/scan_path drive\nthe genuine detector pipeline, so these now assert deterministic outcome\n[…]\nl temp fixtures: clean dir -> 0, RSA keygen -> 1/real finding,\nbaseline written, explain_finding returns real PQC remediation.\n\nAlso drops a stray U+200B from the maskBlockComments doc comment (lint).",
"is_bot": false,
"headline": "test: de-stub tautological CLI/MCP tests against the real scanner",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T07:51:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c0850f29d8420de99e0162e38d235792aad984ea",
"body": "…/Azure KMS\n\nFrom the pre-1.0 audit's detection-gap list:\n\n- New xmldsig detector: classical XML-DSig / XML-Enc algorithm URIs (SAML SSO,\n WS-Security) — rsa-sha*/dsa-sha*/ecdsa-sha* signatures and rsa-oaep key transport.\n- New pkcs11 detector: classical keys behind a PKCS#11 HSM/token — pkcs11-too\n[…]\ns. Messages/ids made cloud-generic.\n\nTwo new detectors registered (35 total). Regression tests (positives, negatives,\ndoc-suppression) throughout. Suite: 951 passing; all gates clean; benchmark 1.000.",
"is_bot": false,
"headline": "detectors: close coverage gaps — SAML/XML-DSig, PKCS#11, TDE, CDK/GCP…",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T07:18:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5f08bd446459fec5fadc1b66a23326be4f116bd5",
"body": "The detector matched only the quoted-value SDK/JSON form (`KeySpec: \"RSA_2048\"`), so\nAWS CDK's enum-member form (`kms.KeySpec.RSA_2048`, `acm.KeyAlgorithm.EC_prime256v1`)\nand Pulumi's camelCase props (`customerMasterKeySpec: \"RSA_2048\"`) produced ZERO\nfindings — the dominant IaC idioms at AWS-heavy \n[…]\nth cases; also cover ACM `KeyAlgorithm`. The fast-reject\ngate is now case-insensitive. Terraform's snake_case spec still never double-counts\n(the regex has no underscore form). Regression tests added.",
"is_bot": false,
"headline": "cloud-kms: cover AWS CDK enum forms + Pulumi/camelCase key specs",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T07:08:30Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "204e89b43d5601bcb36688e258b5c7a4527ea816",
"body": "…NCSC\n\nCloses the audit's #1 gap: the tool was hardcoded to a NIST/CNSA worldview, and its\n\"hybrids optional\" guidance was regime-WRONG for ANSSI/BSI (where hybridization is\nrequired), with no way to choose otherwise.\n\n- New core `StandardsProfile` layer (standards-profiles.ts): five cited, dated\n \n[…]\ntionForProfile, formatProfileGuidance (frozen in the surface). A drift test\n keeps profile params aligned with PQC_STANDARDS.\n\nDocs: CHANGELOG, ROADMAP, CLI help. Suite: 936 passing; all gates clean.",
"is_bot": false,
"headline": "feat: selectable standards regimes (--profile) — NIST/CNSA/BSI/ANSSI/…",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T07:01:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3cd17e3e04536d9daac70069d441a52e5826da8b",
"body": "…E, ROADMAP)\n\n- CONFIG.md §5 was materially wrong: it implied the Action and MCP honor a\n discovered config. Neither does (verified) — and that's deliberate: both run over\n operator-uncontrolled trees, so a discovered config there would be a scan-integrity\n bypass. Documented the trusted-local-op\n[…]\n/ 593 tests / 9 langs / 5\n packages). Updated to v0.5.0 / ~930 tests / 11 langs / 7 packages, added qprobe,\n and led with both benchmark numbers (curated 1.000 + real-world recall 0.84).\n\nDocs only.",
"is_bot": false,
"headline": "docs: correct drift the audit flagged (CONFIG security posture, READM…",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T06:43:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fe7869d5f84ab86a16113d399c66fa7520203d36",
"body": "Nine symbols with zero cross-package consumers were being SemVer-frozen by accident\n— un-export them from @quantakrypto/core's index (they stay exported from their own\nmodules, so core's own tests still import them via ../src/): the parallel-scan\nchunk/merge helpers (mergeChunkResults, chunkByBytes)\n[…]\niewStatus, and isGeneratedPath. Public surface 324 → 315 symbols\n(core 139 → 130). Also refreshed the stale builtinDetectors doc comment (it\ndescribed ~10 detectors; there are 33). No behavior change.",
"is_bot": false,
"headline": "freeze-safety: trim internal plumbing from the public API surface",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T06:42:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "26f4c7d57ff97958659fca364cf04db12e51c3c3",
"body": "Two better-before-the-1.0-API-freeze items from the audit.\n\n- Block comments now mask correctly. `maskCommentLines` is line-only, so an\n HCL/Bicep resource wrapped in `/* … */` had its inner lines left live (verified\n FP: bicep-keyvault-rsa / tf-rsa-key fired inside a block comment). New\n offset-\n[…]\nderReport` into async `runQscan`; the sync `commandSigner` still satisfies the\n wider type. Added an async-signer test.\n\nRegression tests added. Suite: 928 passing; all gates clean (incl. api-check).",
"is_bot": false,
"headline": "freeze-safety: block-comment masking + async-capable EvidenceSigner",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T05:55:41Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f10745a5ceb62aa36fd94b73fc39a4a12cf0ca84",
"body": "…rity drift\n\nConfirmed, low-risk findings from the pre-1.0 four-lens audit.\n\nSecurity:\n- An AUTO-DISCOVERED quantakrypto.config.json can come from the scanned tree, so a\n hostile repo could silently WEAKEN its own scan (disable rules, raise the\n severity-threshold, exclude files → flip exit 1→0). \n[…]\n9/X448 low→medium (aligns with node/rust/go) — the same\n primitive must not flip CI exit codes based on which surface uses it.\n\nRegression tests added throughout. Suite: 925 passing; all gates clean.",
"is_bot": false,
"headline": "audit fixes: config-trust warning, verified FPs, Swift coverage, seve…",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T05:32:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "dc942ea12abfb232859dc81d3a782d2bde8e1a59",
"body": "… were missing\n\nThe generator's declaration regexes didn't allow an `async` modifier, so\n`export async function` was skipped: runQscan, runSieve, runProbe (the main public\nentry points of qscan/sieve/qprobe) were absent from the frozen surface\n(docs/api-surface.json + API.md), and since `--check` sh\n[…]\nmplete freeze. Widen the modifier prefix to\n`(?:(?:declare|async|abstract)\\s+)*` in both collectExports regexes and docFor, and\nregenerate: 318 → 324 symbols.\n\nFound by the pre-1.0 test-quality audit.",
"is_bot": false,
"headline": "fix(api-gen): capture `export async function` — flagship entry points…",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T05:20:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3ac14568839a1dd17270a7472371ed2729127cde",
"body": "Completes the A.8.24 evidence chain per ADR-0004: the tool orchestrates a signer,\nit implements no cryptography.\n\n- `qscan --format evidence --sign <cmd>` / `--timestamp <cmd>` pipe the report's\n deterministic contentHash to an operator-provided external signer (openssl /\n cosign / an RFC-3161 TSA\n[…]\ney.\n\nDocs: A.8.24 evidence doc §3.1 (interface + examples + verify recipe), ROADMAP,\nCHANGELOG. New public exports frozen in the API surface. Suite: 922 passing;\nlint/format/zero-deps/api-check clean.",
"is_bot": false,
"headline": "qscan: orchestrate external evidence signing (--sign / --timestamp)",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T04:58:13Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9b26eeed47f8420b8197ed0dfd91f4757f0a39d7",
"body": "Promote the roadmap's i18n YAGNI note to a load-bearing Architecture Decision\nRecord: the human-facing report ships no message catalogs or locale machinery, and\nthe structured JSON/SARIF/CBOM output is the locale-neutral integration surface for\nany consumer that needs localized presentation. Framed as a YAGNI deferral, not a\npermanent refusal — reopening requires a new ADR with a concrete localized-consumer\nneed. Indexed in docs/adr/README.md and cross-linked from ROADMAP.md.",
"is_bot": false,
"headline": "docs: record report-is-English-only (no i18n) as ADR-0006",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T04:48:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2241e0ce3c675f512409caa3beb4563f916b8de8",
"body": "…gate)\n\nCloses the VERSIONING.md 1.0 requirement of \"a documented, frozen public API\nsurface + a generated API reference\".\n\n- scripts/gen-api-reference.mjs (zero-dep) reads each package's public entry point\n (following a single `export * from` hop) and emits docs/API.md (human reference)\n and docs\n[…]\ngate bites: exit 1 on a dropped/added symbol, 0 when clean.\n- Documented the closed gate in VERSIONING.md, ROADMAP.md §1, and CHANGELOG.\n\nSuite: 916 passing; lint/format/zero-deps/api-check all clean.",
"is_bot": false,
"headline": "docs: freeze the public API surface + generate an API reference (1.0 …",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T04:42:59Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "32f90adc35068db7f330c1dbc27f061ad4aa962a",
"body": "Bump every @quantakrypto/* package 0.4.4 → 0.5.0 (and the cross-package core/\nqprobe/qscan/agent pins + the two version.ts constants), and date the CHANGELOG\n[Unreleased] → [0.5.0].\n\nMinor bump under 0.x: this line adds new backward-compatible detector surfaces\n(Azure Bicep, Swift/CryptoKit, Pulumi)\n[…]\ntop of the round 3/4/5 detection-accuracy\nand engine-correctness fixes and the dead-code/API-surface cleanup. Suite at 916\npassing; precision/recall gates and the zero-FP negative set held throughout.",
"is_bot": false,
"headline": "release: v0.5.0",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T04:35:16Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3a84af29921dea8a22a4d2a9ea292d6e861e3cab",
"body": "Document the detector-precision hardening (comment/prose masking, cross-detector\ndouble-count deferrals, per-language FP/FN fixes), the engine correctness fixes\n(triage cap, CBOM merge/serial, readiness ordering, CLI ENOENT/--merge, sieve KAT\nskips), the dead-code removal and API-surface narrowing, the three new detector\nsurfaces (Azure Bicep, Swift/CryptoKit, Pulumi), and the real-repo validation +\ncorpus expansion. No previously-documented entries changed.",
"is_bot": false,
"headline": "docs: bring CHANGELOG [Unreleased] current through rounds 3–5",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T04:31:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "89dc0598aa850fc1abdc0faade4e74c7d1d997c1",
"body": "Three new detector surfaces (#5), each registered, unit-tested, and pinned by the\nbenchmark corpus:\n\n- bicep: Azure-native IaC (.bicep) — Microsoft.KeyVault `kty: 'RSA'/'EC'` keys\n (gated to the Key Vault marker) and legacy `minimumTlsVersion: 'TLS1_0'/'TLS1_1'`.\n Complements the existing ARM/Clou\n[…]\nhe `algorithm` value (RSA/ECDSA/ED25519).\n\nValidated against real OSS repos (gin, mux, flask, terraform-aws-eks, express,\nhelm/charts): zero false positives from the new detectors. Suite: 916 passing.",
"is_bot": false,
"headline": "detectors: add Azure Bicep, Swift/CryptoKit, and Pulumi coverage",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T04:27:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "877319c024ada9a572206b21d631e7e735e5a6db",
"body": "Add 7 labeled corpus cases so the new coverage is pinned by the precision/recall\ngates (was invisible to the benchmark before):\n\nPositives:\n- GCP service-account JSON with a single-line \\n-escaped PKCS#8 key\n (pem-pkcs8-private-key)\n- Terraform tls_private_key ED25519 (tf-ed25519-key)\n- Ansible com\n[…]\nide a Terraform description string\n- a PEM parser's paired header/footer string constants\n- commented-out PHP openssl crypto\n\nBenchmark: recall perfect, negative set strict (0 FP). Suite: 899 passing.",
"is_bot": false,
"headline": "benchmark: expand corpus for the round 3/4/5 detector surfaces",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T04:18:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "173d388feb0909804020bd84b4cfc5e14fa16bf5",
"body": "Empirical validation (scanning real OSS repos — gin, flask, terraform-aws-eks,\nhelm/charts, express, gorilla/mux) surfaced one false-positive class: the\nssh-kex-classical / tls-classical-kex token rules fired on classical algorithm\nnames LISTED inside a Terraform/Packer `description = \"…\"` string (\"\n[…]\n is unaffected.\n\nThe rest of the sweep (~82 findings across 6 repos) was legitimate: real embedded\ntest certs/keys, real InsecureSkipVerify, and intentional classical-crypto deps.\n\nSuite: 899 passing.",
"is_bot": false,
"headline": "source: don't fire transport-KEX rules on algorithm names in a doc field",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T04:15:40Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5560caa06ce10bd7549191f63e322e85da7b595c",
"body": null,
"is_bot": false,
"headline": "test: cover cosign sign-blob subcommand",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T03:44:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "dd2d584af6bebd42d5c95c1dfd1aba61db40b80a",
"body": "Un-export 71 symbols across the workspace that are referenced only within their\nown declaring file — helpers, config/option interfaces, and protocol member types\nthat are not part of any package's public API (none re-exported by an index, none\nimported by another module or test). The build (declarat\n[…]\nrms nothing outside each file used them. Also delete mcp's JsonValue type,\nwhich turned out to be unused in-file once un-exported.\n\nNo behavior change. Suite: 894 passing; lint/format/zero-deps clean.",
"is_bot": false,
"headline": "narrow visibility of internal-only symbols; drop dead JsonValue type",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T03:43:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ee573f43af9d63f682362c952fb06c4ce6c008df",
"body": "- Delete three symbols with zero references anywhere: mcp `ToolInputSchema` (and\n the now-unused JsonSchema import it existed to reference), sieve `SuccessResponse`,\n and mcp `writeLine` (a redundant helper — runStdioServer writes inline).\n- cicd: reorder the cosign subcommand alternation so `sign\n[…]\nhortening its matchLength).\n- cloud-kms: drop the redundant `CustomerMasterKeySpec` fast-reject conjunct — the\n string contains `KeySpec`, so the earlier check already covers it.\n\nSuite: 894 passing.",
"is_bot": false,
"headline": "remove dead code: unused exports, redundant helper, unreachable branches",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T03:40:13Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "88e41c5b8c2bcf3b1229272ac8638c5592b610b8",
"body": "- ansible: an openssl_privatekey `type: X448` now reports algorithm X448 instead\n of the shared XDH rule's default X25519 label.\n- database: the sslmode prefilter now also admits the `ssl_mode` (underscore) form\n the RE_WEAK_SSLMODE regex already matches — previously the gate silently blocked\n every underscore-only file, making that regex branch dead.\n\nSuite: 894 passing.",
"is_bot": false,
"headline": "ansible/database: correct X448 label and align the sslmode prefilter",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T03:27:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e97bc430284bbee36af0972ac10e55788f7a3487",
"body": "An adversarial verification pass over the round 3 diff surfaced six regressions —\ninputs the test suite didn't cover. All fixed and pinned with tests.\n\n- pem: a long single-line, `\\n`-escaped key body (GCP service-account JSON,\n `PRIVATE_KEY=\"…\\n…\"`) pushed the -----END marker past the 800-char win\n[…]\ny checked the immediate preceding\n char, so a hardened full-suite exclusion (`HIGH:!ECDHE-RSA-RC4-SHA`) false-\n positived. The lookbehind now walks back to the element boundary.\n\nSuite: 893 passing.",
"is_bot": false,
"headline": "fix regressions from the round 3 detector changes (verification pass)",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T03:18:27Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5ea64d43ce303938ecc04944562b4cbb461c0bb0",
"body": "…m ids\n\n- c: the TLS-version rule now also matches TLSv1_1_method, the _client/_server\n method variants, and SSLv2_method (previously only TLSv1_method/SSLv3_method).\n- openpgp: map the RFC 9580 (crypto-refresh) v6 public-key algorithm ids —\n 25 X25519, 26 X448 (key agreement, HNDL), 27 Ed25519, 28 Ed448 (signatures) —\n so v6 keys classify precisely instead of falling back to a generic finding.\n\nSuite: 887 passing.",
"is_bot": false,
"headline": "c/openpgp: widen legacy TLS method forms and map RFC 9580 v6 algorith…",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T02:59:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cd436ab7aa4747d339a1378f1a837b8d78d3a3c6",
"body": "…AT skips\n\nRound 3 audit follow-up on the non-detector engine (crashes, misleading output,\nsilent data loss).\n\n- triage: when capping to --max-findings, select the TOP by SEVERITY, not by\n file-path order — a critical in a late-sorting file was dropped from triage and\n sunk to the bottom of the re\n[…]\nT: an unverifiable vector (no seed/coins) is a SKIP, not a match — it no\n longer inflates the \"N/N matched\" count into a false conformance pass.\n\nAdds regression tests throughout. Suite: 887 passing.",
"is_bot": false,
"headline": "engine: fix triage cap, CBOM merge crashes/serial, readiness order, K…",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T02:57:30Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1384375b74d6a4cf3b88bccc48f95be282a877b9",
"body": "Round 3 audit follow-up on the language packs.\n\nDouble-counts (deferrals added to jwtDetector, mirroring jose.ts):\n- A JWK object inlined in JS/TS/Py source no longer fires BOTH jwk-* and\n jwt-classical-alg: jwtDetector skips alg tokens whose enclosing object has a\n `\"kty\"` (jwk owns it).\n- A quot\n[…]\nx448::Secret`.\n- elixir: `:crypto.compute_key` (the (EC)DH agreement op); JOSE OKP X25519/X448 is\n key agreement (HNDL), not an EdDSA signature.\n\nAdds regression tests throughout. Suite: 881 passing.",
"is_bot": false,
"headline": "source/language detectors: dedup double-counts and close FP/FN gaps",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T02:48:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9a06ef9988a41ad4fd1d160e61d0270dbc3490bb",
"body": "Round 3 audit follow-up on the infrastructure/config detectors. Root cause of the\nfalse positives: commentStyleForFile covers no config extension, so any config\ndetector that skipped maskCommentLines had zero comment protection.\n\nFalse positives (comment masking added; offsets preserved):\n- mesh, dn\n[…]\nno `\"` between the markers. This closes a self-regression where a PEM\nparser's paired header/footer string constants were accepted as a real key.\n\nAdds regression tests throughout. Suite: 870 passing.",
"is_bot": false,
"headline": "config detectors: comment masking for config formats, plus FN/FP fixes",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T02:35:24Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "99bdda97910f2a88d165573caf6d42cafc3cc709",
"body": "… scoping\n\nRound 3 correctness pass. Fixes three P0 false-positive classes plus two\nregressions from the Round 2 JWK/JOSE work, and makes the shared object-scoping\nhelper string-aware.\n\n- comments: add PHP/.phtml/Scala (`.scala`/`.sc`) to the C-style comment table\n and Ruby/Elixir (`.rb`/`.ex`/`.ex\n[…]\nlt marker.\n- keystore: accept BER indefinite-length PKCS#12 (0x80), emitted by NSS/Firefox\n .p12 exports, alongside the long-form DER lengths.\n\nAdds regression tests for each fix. Suite: 862 passing.",
"is_bot": false,
"headline": "core: eliminate P0 false-positive classes and harden per-key JWK/JOSE…",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-20T02:19:17Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4894d5ec21b5754b9fef379e7d2a6f167ec4d0d5",
"body": "Binary pipeline (from the binary-audit): detect PKCS#12-format keystores named\n.jks/.keystore (keytool default since Java 9) and the 30 81 / 30 83 DER length\nforms; count latin1 keystore bytes at on-disk size (serial/parallel budget parity);\nisKeystorePath uses endsWith so bare dotfiles agree with t\n[…]\nssaging keeps only static-RSA\n(ECDHE owned by source); secrets defers PGP MESSAGE to pem; cfn ARM kty requires a\nMicrosoft.KeyVault marker. qprobe upgrade drops stale net listeners. Regression-tested.",
"is_bot": false,
"headline": "audit round 1 fixes: binary keystore/openpgp + detector precision",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-19T17:43:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "787b69f4e235f2268d6f2372e4915cd7d9781a51",
"body": "…y_share\n\nThe TLS probe now sends a valid X25519MLKEM768 key_share (real X25519 public from\nnode:crypto + a valid-range ML-KEM-768 encapsulation key, ek||x25519 per\ndraft-ietf-tls-ecdhe-mlkem), so a supporting server selects 0x11EC directly in its\nServerHello — catching support-but-don't-prefer serv\n[…]\ntes the handshake): a ByteEncode12\nof in-range coefficients passes the encaps modulus check; the throwaway secret is\nnever computed. New mlkem768.ts, pure + unit-tested; fallback to x25519/HRR intact.",
"is_bot": false,
"headline": "qprobe: definitive hybrid negotiation via a well-formed ML-KEM-768 ke…",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-19T17:19:58Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b1b0489d303f601b19ae20e3ca43b656825d09cc",
"body": "Extend qprobe beyond TLS/SSH/SMTP to the other 'communication between things'\nendpoints, auto-selected by well-known port:\n- imap (:143) / pop3 (:110): line-based STARTTLS/STLS upgrade (generic\n probeLineStartTls helper), then the same negotiated-parameter inspection.\n- postgres (:5432): send the 8\n[…]\n853) and IMAPS (:993) already work as direct-TLS probes.\nAll reuse the clean-close hang guard and cert/KEX classification. Pure builders +\nmock-server dance tested; postgres upgrade path e2e-verified.",
"is_bot": false,
"headline": "qprobe: add IMAP/POP3 STARTTLS and PostgreSQL SSLRequest probes",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-19T17:12:43Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "eab2897929c9c017cac4fc0bcad02bab6e79eabd",
"body": "Single-source ownership for overlapping surfaces (audit precision findings):\n- source.ts owns SSH KexAlgorithms + ECDHE cipher tokens; removed the redundant\n vpn net-sshd-classical-kex and mesh mesh-istio-classical-cipher rules.\n- cloudformation.ts owns crypto inside CFN/ARM templates: jwk + cloud-\n[…]\ntensions; usage-aware — a signing RSA/EC JWK is a signature\n (hndl:false), encryption keys stay hndl:true.\n- jose: defer to jwk when the alg is inside a JWK object.\nRegression-tested; 837 tests pass.",
"is_bot": false,
"headline": "detectors: fix cross-detector double-counts + jwk sig/enc classification",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-19T17:05:01Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "caddec1ebc12b0afb5d24e180b86eb9fdf9912c2",
"body": "Building on the byte-preserving binary read (keystore pipeline), extend it to\nOpenPGP keyrings (.gpg/.pgp/.kbx) and add an openpgp detector that parses packet\ntags: committed SECRET keys (sensitive; the sharp finding — a private key in a\nrepo), public keys, binary PGP-encrypted messages (PKESK → HND\n[…]\nPG\nkeyboxes. The public-key algorithm (RSA/DSA/ElGamal/ECDSA/EdDSA/ECDH) is read from\nthe packet body. Bounds-checked, fuzz-tested, pipeline-tested. Armored blocks stay\nwith the PEM/secrets detectors.",
"is_bot": false,
"headline": "detect binary OpenPGP key material and GnuPG keyboxes",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-19T16:46:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4d78c7dc8da074ebbed1e048fa318dc293b7a19c",
"body": "Previously the networked probe_endpoint tool was refused unconditionally on the\nHTTP transport. Mirror the allowFs pattern instead: it is OFF by default on HTTP\nbut a trusted operator can enable it via QUANTAKRYPTO_MCP_ALLOW_NETWORK=1 (or the\nallowNetwork option). Threaded through HttpServerOptions/\n[…]\nlowFs, allowNetwork); startup banner shows probe:on/off.\nThe per-call ownership attestation and range refusal still apply on every transport.\nstdio (local, trusted) is unchanged. Docs + tests updated.",
"is_bot": false,
"headline": "mcp: make HTTP exposure of probe_endpoint an opt-in parameter",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-19T16:19:40Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a3f4017158dde01b2ba766b8f4d68809fc8b2be3",
"body": "The scan pipeline hard-skipped binary files, so keystores (private key material)\nwere invisible. Add a keystore extension set (walk.ts isKeystorePath); the serial\nand parallel scan paths now read those extensions byte-preserving (latin1) and\nexempt them from the minified skip, so a new keystore dete\n[…]\nppet dropped). Other binaries stay skipped.\nPipeline-tested end to end. Also records this session's platform work (qscan\n--cbom --merge, MCP probe_endpoint, infra Action recipe, detector-audit fixes).",
"is_bot": false,
"headline": "detect committed cryptographic keystores (JKS/JCEKS/PKCS12/BKS)",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-19T16:13:36Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a8f882d02dcd2c65f7d7d2672fb603411d5b78b0",
"body": "Exposes qProbe's live-endpoint probing to AI agents. The qprobe plane is loaded via\ndynamic import so the server stays offline until the tool is invoked, and the\nownership attestation is enforced: probe_endpoint refuses unless i_own_this=true and\nrefuses CIDR/ranges (helpful message). Errored/unreac\n[…]\nRefused UNCONDITIONALLY on the HTTP\ntransport (new NETWORK_TOOL_NAMES) — a hosted MCP must not be an arbitrary-host\nprobing oracle. mcp now depends on @quantakrypto/qprobe (internal, zero-dep intact).",
"is_bot": false,
"headline": "mcp: add gated probe_endpoint tool (the only networked MCP tool)",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-19T16:06:50Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "033ef7175b340a5f9d04ffdc0eb7dcfc7d8e2321",
"body": "…+ combined CBOM)\n\nNew example workflow showing the infra line end to end: qScan gates code + IaC on\nevery change, a weekly scheduled job probes owned TLS/SSH endpoints with qProbe\n(behind a committed ownership manifest), and 'qscan --cbom --merge' fuses the scan\nand endpoint CBOMs into one combined code + infrastructure + wire bill of materials.\nAdds an owned-hosts.example.txt manifest template.",
"is_bot": false,
"headline": "action: infrastructure readiness recipe (IaC scan + scheduled qprobe …",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-19T15:22:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d7547aaa27f7d9b0bf665a3ae9e4028c9267a379",
"body": "… CBOM\n\nThe mergeCboms engine (core/cbom-merge.ts) existed but was unwired. Add a\nrepeatable --merge <cbom.json> flag: with --cbom it reads external CBOMs (e.g. a\nqprobe endpoint CBOM) and merges them with the scan CBOM via CycloneDX, producing\none combined code + infrastructure bill of materials. Errors (missing file, non-\nJSON, non-CycloneDX) exit 2 with a clear message. Unit + e2e tested.",
"is_bot": false,
"headline": "qscan: wire mergeCboms — qscan --cbom --merge for combined code+infra…",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-19T15:20:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4b54926228119bb179b99de832497e133fb68e28",
"body": "…(audit)\n\nAddresses infra config-detector audit findings (my detectors):\n- ReDoS: bound the unbounded [^\\n]* / [^\\n&|;]*? spans in messaging (ssl.protocol,\n ssl.cipher.suites) and cicd (gpg, codesign) — they blew the repo's 2s budget on\n adversarial input. Add config-detector inputs to redos.test.\n[…]\n(the cipher rule reports the KEX harvest).\n\n(vpn sshd double-count and the cross-detector / other-agent-owned findings are left\nfor coordination — the other agent is actively remediating those files.)",
"is_bot": false,
"headline": "detectors: fix ReDoS, comment-masking FPs, and cipher classification …",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-19T15:12:37Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "febabf20e71da5450bee9ea810081ee43a7c23da",
"body": "Two new config-scope detectors closing audited gaps:\n- supply-chain: Docker Content Trust (Notary v1), CNCF Notation, in-toto signing\n (signature-side, gated to CI/Dockerfile/shell, comment-masked)\n- vault: native HashiCorp Vault HCL transit key types (rsa-*/ecdsa-p*/ed25519) and\n pki role key_type; gated to .hcl + a transit/pki marker so it never overlaps the\n terraform detector (.tf)\n\nAlso records the ansible/age detectors and the qprobe hang fix in CHANGELOG.",
"is_bot": false,
"headline": "detect supply-chain signing and native vault hcl crypto",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-19T14:03:58Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4e9b4012b750a45f42998065c8852ac112d00198",
"body": "Two new config-scope detectors closing audited gaps:\n- ansible: community.crypto openssl_privatekey/csr type RSA/ECC (comment-masked, gated)\n- age: committed AGE-SECRET-KEY-1 identity (X25519 private key) — worse than a\n recipient; sensitive so the snippet is dropped. Closes the secrets-detector FN.",
"is_bot": false,
"headline": "detect ansible community.crypto keys and committed age identity keys",
"author_name": "Leon Acosta @ Dandelion Labs",
"author_login": "leonacostaok",
"committed_at": "2026-07-19T13:58:28Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 4,
"commits_last_year": 254,
"latest_release_at": "2026-07-23T05:57:13Z",
"latest_release_tag": "v1",
"releases_from_tags": false,
"days_since_last_push": 0,
"active_weeks_last_year": 6,
"days_since_latest_release": 3,
"mean_days_between_releases": 2.5
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": true,
"health_percentage": 87,
"has_issue_template": false,
"has_code_of_conduct": true,
"has_pull_request_template": true
},
"ecosystem": {
"packages": [
{
"name": "@quantakrypto/mcp",
"exists": true,
"license": "Apache-2.0",
"keywords": [],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/@quantakrypto/mcp",
"is_deprecated": false,
"latest_version": "0.5.2",
"repository_url": "https://github.com/quantakrypto/pqc-tools",
"versions_count": 13,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 2087,
"first_published_at": "2026-06-22T13:45:51.286000Z",
"latest_published_at": "2026-07-23T03:34:07.172000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 4
},
{
"name": "@quantakrypto/core",
"exists": true,
"license": "Apache-2.0",
"keywords": [],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/@quantakrypto/core",
"is_deprecated": false,
"latest_version": "0.5.0",
"repository_url": "https://github.com/quantakrypto/pqc-tools",
"versions_count": 11,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 2041,
"first_published_at": "2026-06-22T13:45:42.443000Z",
"latest_published_at": "2026-07-20T15:48:15.033000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 6
},
{
"name": "@quantakrypto/agent",
"exists": true,
"license": "Apache-2.0",
"keywords": [],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/@quantakrypto/agent",
"is_deprecated": false,
"latest_version": "0.5.0",
"repository_url": "https://github.com/quantakrypto/pqc-tools",
"versions_count": 6,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 725,
"first_published_at": "2026-07-03T12:32:08.324000Z",
"latest_published_at": "2026-07-20T15:48:11.055000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 6
},
{
"name": "@quantakrypto/qscan",
"exists": true,
"license": "Apache-2.0",
"keywords": [],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/@quantakrypto/qscan",
"is_deprecated": false,
"latest_version": "0.5.0",
"repository_url": "https://github.com/quantakrypto/pqc-tools",
"versions_count": 11,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 1597,
"first_published_at": "2026-06-22T13:45:48.337000Z",
"latest_published_at": "2026-07-20T15:48:26.187000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 6
},
{
"name": "@quantakrypto/sieve",
"exists": true,
"license": "Apache-2.0",
"keywords": [],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/@quantakrypto/sieve",
"is_deprecated": false,
"latest_version": "0.5.0",
"repository_url": "https://github.com/quantakrypto/pqc-tools",
"versions_count": 11,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 1714,
"first_published_at": "2026-06-22T13:45:45.289000Z",
"latest_published_at": "2026-07-20T15:48:29.507000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 6
},
{
"name": "@quantakrypto/qprobe",
"exists": true,
"license": "Apache-2.0",
"keywords": [],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/@quantakrypto/qprobe",
"is_deprecated": false,
"latest_version": "0.5.0",
"repository_url": "https://github.com/quantakrypto/pqc-tools",
"versions_count": 2,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 312,
"first_published_at": "2026-07-19T08:12:24.768000Z",
"latest_published_at": "2026-07-20T15:48:22.571000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 6
}
]
},
"popularity": {
"forks": 0,
"stars": 9,
"watchers": 0,
"fork_history": {
"days": [],
"complete": true,
"collected": 0,
"total_forks": 0
},
"star_history": null,
"open_issues_and_prs": 7
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [
"examples"
],
"has_llms_txt": false,
"has_dockerfile": true,
"has_mcp_signal": true,
"bootstrap_files": [],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [
"packages/action/tsconfig.json",
"packages/agent/tsconfig.json",
"packages/core/tsconfig.json",
"packages/mcp/tsconfig.json",
"packages/qprobe/tsconfig.json",
"packages/qscan/tsconfig.json",
"packages/sieve/tsconfig.json",
"tsconfig.json"
],
"toolchain_manifests": [
"packages/core/test/benchmark/recall/csharp/Acme.Signing.csproj",
"packages/core/test/benchmark/recall/go/go.mod",
"packages/core/test/benchmark/recall/java/pom.xml",
"packages/core/test/benchmark/recall/rust/Cargo.toml"
],
"largest_source_bytes": 59062,
"source_files_sampled": 454,
"oversized_source_files": 0,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"dependencies": {
"manifests": [
"package.json"
],
"advisories": {
"error": null,
"scope": "published_package",
"source": "osv",
"findings": [],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 2,
"malicious_count": 0,
"assessed_package": "npm:@quantakrypto/mcp@0.5.2",
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"npm"
],
"dependencies": [
{
"name": "@quantakrypto/core",
"manifest": "packages/action/package.json",
"ecosystem": "npm",
"version_constraint": "0.5.0"
},
{
"name": "@quantakrypto/qscan",
"manifest": "packages/action/package.json",
"ecosystem": "npm",
"version_constraint": "0.5.0"
},
{
"name": "@quantakrypto/core",
"manifest": "packages/agent/package.json",
"ecosystem": "npm",
"version_constraint": "0.5.0"
},
{
"name": "@quantakrypto/core",
"manifest": "packages/mcp/package.json",
"ecosystem": "npm",
"version_constraint": "0.5.0"
},
{
"name": "@quantakrypto/qprobe",
"manifest": "packages/mcp/package.json",
"ecosystem": "npm",
"version_constraint": "0.5.0"
},
{
"name": "@quantakrypto/core",
"manifest": "packages/qprobe/package.json",
"ecosystem": "npm",
"version_constraint": "0.5.0"
},
{
"name": "@quantakrypto/agent",
"manifest": "packages/qscan/package.json",
"ecosystem": "npm",
"version_constraint": "0.5.0"
},
{
"name": "@quantakrypto/core",
"manifest": "packages/qscan/package.json",
"ecosystem": "npm",
"version_constraint": "0.5.0"
},
{
"name": "@noble/post-quantum",
"manifest": "validation/sieve-real-sut/package.json",
"ecosystem": "npm",
"version_constraint": "^0.4.0"
}
],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "@noble/post-quantum",
"direct": true,
"version": "0.4.1",
"ecosystem": "npm"
},
{
"name": "@noble/post-quantum",
"direct": true,
"version": "0.6.1",
"ecosystem": "npm"
},
{
"name": "@quantakrypto/agent",
"direct": true,
"version": "0.5.0",
"ecosystem": "npm"
},
{
"name": "@quantakrypto/core",
"direct": true,
"version": "0.5.0",
"ecosystem": "npm"
},
{
"name": "@quantakrypto/qprobe",
"direct": true,
"version": "0.5.0",
"ecosystem": "npm"
},
{
"name": "@quantakrypto/qscan",
"direct": true,
"version": "0.5.0",
"ecosystem": "npm"
},
{
"name": "anyhow",
"direct": false,
"version": null,
"ecosystem": "crates"
},
{
"name": "ed25519-dalek",
"direct": false,
"version": null,
"ecosystem": "crates"
},
{
"name": "hex",
"direct": false,
"version": null,
"ecosystem": "crates"
},
{
"name": "openssl",
"direct": false,
"version": null,
"ecosystem": "crates"
},
{
"name": "rsa",
"direct": false,
"version": null,
"ecosystem": "crates"
},
{
"name": "serde",
"direct": false,
"version": null,
"ecosystem": "crates"
},
{
"name": "serde_json",
"direct": false,
"version": null,
"ecosystem": "crates"
},
{
"name": "tokio",
"direct": false,
"version": null,
"ecosystem": "crates"
},
{
"name": "tracing",
"direct": false,
"version": null,
"ecosystem": "crates"
},
{
"name": "x25519-dalek",
"direct": false,
"version": null,
"ecosystem": "crates"
},
{
"name": "github.com/cloudflare/circl",
"direct": false,
"version": "v1.3.9",
"ecosystem": "go"
},
{
"name": "github.com/decred/dcrd/dcrec/secp256k1/v4",
"direct": false,
"version": "v4.3.0",
"ecosystem": "go"
},
{
"name": "github.com/golang-jwt/jwt/v5",
"direct": false,
"version": "v5.2.1",
"ecosystem": "go"
},
{
"name": "golang.org/x/crypto",
"direct": false,
"version": "v0.24.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/sys",
"direct": false,
"version": "v0.21.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/term",
"direct": false,
"version": "v0.21.0",
"ecosystem": "go"
},
{
"name": "com.fasterxml.jackson.core:jackson-databind",
"direct": false,
"version": "2.17.1",
"ecosystem": "maven"
},
{
"name": "io.jsonwebtoken:jjwt-api",
"direct": false,
"version": "0.11.5",
"ecosystem": "maven"
},
{
"name": "org.bouncycastle:bcpkix-jdk18on",
"direct": false,
"version": "1.78.1",
"ecosystem": "maven"
},
{
"name": "org.bouncycastle:bcprov-jdk18on",
"direct": false,
"version": "1.78.1",
"ecosystem": "maven"
},
{
"name": "@esbuild/aix-ppc64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/android-arm",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/android-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/android-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/darwin-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/darwin-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/freebsd-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/freebsd-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-arm",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-ia32",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-loong64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-mips64el",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-ppc64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-riscv64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-s390x",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/netbsd-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/netbsd-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/openbsd-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/openbsd-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/openharmony-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/sunos-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/win32-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/win32-ia32",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/win32-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@eslint-community/eslint-utils",
"direct": false,
"version": "4.9.1",
"ecosystem": "npm"
},
{
"name": "@eslint-community/regexpp",
"direct": false,
"version": "4.12.2",
"ecosystem": "npm"
},
{
"name": "@eslint/config-array",
"direct": false,
"version": "0.21.2",
"ecosystem": "npm"
},
{
"name": "@eslint/config-helpers",
"direct": false,
"version": "0.4.2",
"ecosystem": "npm"
},
{
"name": "@eslint/core",
"direct": false,
"version": "0.17.0",
"ecosystem": "npm"
},
{
"name": "@eslint/eslintrc",
"direct": false,
"version": "3.3.5",
"ecosystem": "npm"
},
{
"name": "@eslint/js",
"direct": false,
"version": "9.39.4",
"ecosystem": "npm"
},
{
"name": "@eslint/object-schema",
"direct": false,
"version": "2.1.7",
"ecosystem": "npm"
},
{
"name": "@eslint/plugin-kit",
"direct": false,
"version": "0.4.1",
"ecosystem": "npm"
},
{
"name": "@humanfs/core",
"direct": false,
"version": "0.19.2",
"ecosystem": "npm"
},
{
"name": "@humanfs/node",
"direct": false,
"version": "0.16.8",
"ecosystem": "npm"
},
{
"name": "@humanfs/types",
"direct": false,
"version": "0.15.0",
"ecosystem": "npm"
},
{
"name": "@humanwhocodes/module-importer",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "@humanwhocodes/retry",
"direct": false,
"version": "0.4.3",
"ecosystem": "npm"
},
{
"name": "@noble/ciphers",
"direct": false,
"version": "2.2.0",
"ecosystem": "npm"
},
{
"name": "@noble/curves",
"direct": false,
"version": "2.2.0",
"ecosystem": "npm"
},
{
"name": "@noble/hashes",
"direct": false,
"version": "1.8.0",
"ecosystem": "npm"
},
{
"name": "@noble/hashes",
"direct": false,
"version": "2.2.0",
"ecosystem": "npm"
},
{
"name": "@quantakrypto/action",
"direct": false,
"version": "0.5.0",
"ecosystem": "npm"
},
{
"name": "@quantakrypto/mcp",
"direct": false,
"version": "0.5.2",
"ecosystem": "npm"
},
{
"name": "@quantakrypto/observatory",
"direct": false,
"version": "0.0.0",
"ecosystem": "npm"
},
{
"name": "@quantakrypto/sieve",
"direct": false,
"version": "0.5.0",
"ecosystem": "npm"
},
{
"name": "@types/estree",
"direct": false,
"version": "1.0.9",
"ecosystem": "npm"
},
{
"name": "@types/json-schema",
"direct": false,
"version": "7.0.15",
"ecosystem": "npm"
},
{
"name": "@types/node",
"direct": false,
"version": "26.1.1",
"ecosystem": "npm"
},
{
"name": "@types/node",
"direct": false,
"version": "^20.12.0",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/eslint-plugin",
"direct": false,
"version": "8.61.0",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/parser",
"direct": false,
"version": "8.61.0",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/project-service",
"direct": false,
"version": "8.61.0",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/scope-manager",
"direct": false,
"version": "8.61.0",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/tsconfig-utils",
"direct": false,
"version": "8.61.0",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/type-utils",
"direct": false,
"version": "8.61.0",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/types",
"direct": false,
"version": "8.61.0",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/typescript-estree",
"direct": false,
"version": "8.61.0",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/utils",
"direct": false,
"version": "8.61.0",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/visitor-keys",
"direct": false,
"version": "8.61.0",
"ecosystem": "npm"
},
{
"name": "acorn",
"direct": false,
"version": "8.16.0",
"ecosystem": "npm"
},
{
"name": "acorn-jsx",
"direct": false,
"version": "5.3.2",
"ecosystem": "npm"
},
{
"name": "ajv",
"direct": false,
"version": "6.15.0",
"ecosystem": "npm"
},
{
"name": "ansi-styles",
"direct": false,
"version": "4.3.0",
"ecosystem": "npm"
},
{
"name": "argparse",
"direct": false,
"version": "2.0.1",
"ecosystem": "npm"
},
{
"name": "balanced-match",
"direct": false,
"version": "1.0.2",
"ecosystem": "npm"
},
{
"name": "balanced-match",
"direct": false,
"version": "4.0.4",
"ecosystem": "npm"
},
{
"name": "brace-expansion",
"direct": false,
"version": "1.1.16",
"ecosystem": "npm"
},
{
"name": "brace-expansion",
"direct": false,
"version": "5.0.7",
"ecosystem": "npm"
},
{
"name": "callsites",
"direct": false,
"version": "3.1.0",
"ecosystem": "npm"
},
{
"name": "chalk",
"direct": false,
"version": "4.1.2",
"ecosystem": "npm"
},
{
"name": "color-convert",
"direct": false,
"version": "2.0.1",
"ecosystem": "npm"
},
{
"name": "color-name",
"direct": false,
"version": "1.1.4",
"ecosystem": "npm"
},
{
"name": "concat-map",
"direct": false,
"version": "0.0.1",
"ecosystem": "npm"
},
{
"name": "cross-spawn",
"direct": false,
"version": "7.0.6",
"ecosystem": "npm"
},
{
"name": "debug",
"direct": false,
"version": "4.4.3",
"ecosystem": "npm"
},
{
"name": "deep-is",
"direct": false,
"version": "0.1.4",
"ecosystem": "npm"
},
{
"name": "elliptic",
"direct": false,
"version": "^6.5.4",
"ecosystem": "npm"
},
{
"name": "elliptic",
"direct": false,
"version": "^6.5.5",
"ecosystem": "npm"
},
{
"name": "esbuild",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "escape-string-regexp",
"direct": false,
"version": "4.0.0",
"ecosystem": "npm"
},
{
"name": "eslint",
"direct": false,
"version": "9.39.4",
"ecosystem": "npm"
},
{
"name": "eslint-scope",
"direct": false,
"version": "8.4.0",
"ecosystem": "npm"
},
{
"name": "eslint-visitor-keys",
"direct": false,
"version": "3.4.3",
"ecosystem": "npm"
},
{
"name": "eslint-visitor-keys",
"direct": false,
"version": "4.2.1",
"ecosystem": "npm"
},
{
"name": "eslint-visitor-keys",
"direct": false,
"version": "5.0.1",
"ecosystem": "npm"
},
{
"name": "espree",
"direct": false,
"version": "10.4.0",
"ecosystem": "npm"
},
{
"name": "esquery",
"direct": false,
"version": "1.7.0",
"ecosystem": "npm"
},
{
"name": "esrecurse",
"direct": false,
"version": "4.3.0",
"ecosystem": "npm"
},
{
"name": "estraverse",
"direct": false,
"version": "5.3.0",
"ecosystem": "npm"
},
{
"name": "esutils",
"direct": false,
"version": "2.0.3",
"ecosystem": "npm"
},
{
"name": "express",
"direct": false,
"version": "^4.18.0",
"ecosystem": "npm"
},
{
"name": "express",
"direct": false,
"version": "^4.19.2",
"ecosystem": "npm"
},
{
"name": "fast-check",
"direct": false,
"version": "4.9.0",
"ecosystem": "npm"
},
{
"name": "fast-deep-equal",
"direct": false,
"version": "3.1.3",
"ecosystem": "npm"
},
{
"name": "fast-json-stable-stringify",
"direct": false,
"version": "2.1.0",
"ecosystem": "npm"
},
{
"name": "fast-levenshtein",
"direct": false,
"version": "2.0.6",
"ecosystem": "npm"
},
{
"name": "fdir",
"direct": false,
"version": "6.5.0",
"ecosystem": "npm"
},
{
"name": "file-entry-cache",
"direct": false,
"version": "8.0.0",
"ecosystem": "npm"
},
{
"name": "find-up",
"direct": false,
"version": "5.0.0",
"ecosystem": "npm"
},
{
"name": "flat-cache",
"direct": false,
"version": "4.0.1",
"ecosystem": "npm"
},
{
"name": "flatted",
"direct": false,
"version": "3.4.2",
"ecosystem": "npm"
},
{
"name": "fsevents",
"direct": false,
"version": "2.3.3",
"ecosystem": "npm"
},
{
"name": "glob-parent",
"direct": false,
"version": "6.0.2",
"ecosystem": "npm"
},
{
"name": "globals",
"direct": false,
"version": "14.0.0",
"ecosystem": "npm"
},
{
"name": "has-flag",
"direct": false,
"version": "4.0.0",
"ecosystem": "npm"
},
{
"name": "ignore",
"direct": false,
"version": "5.3.2",
"ecosystem": "npm"
},
{
"name": "ignore",
"direct": false,
"version": "7.0.5",
"ecosystem": "npm"
},
{
"name": "import-fresh",
"direct": false,
"version": "3.3.1",
"ecosystem": "npm"
},
{
"name": "imurmurhash",
"direct": false,
"version": "0.1.4",
"ecosystem": "npm"
},
{
"name": "is-extglob",
"direct": false,
"version": "2.1.1",
"ecosystem": "npm"
},
{
"name": "is-glob",
"direct": false,
"version": "4.0.3",
"ecosystem": "npm"
},
{
"name": "isexe",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "js-yaml",
"direct": false,
"version": "4.3.0",
"ecosystem": "npm"
},
{
"name": "json-buffer",
"direct": false,
"version": "3.0.1",
"ecosystem": "npm"
},
{
"name": "json-schema-traverse",
"direct": false,
"version": "0.4.1",
"ecosystem": "npm"
},
{
"name": "json-stable-stringify-without-jsonify",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "jsonwebtoken",
"direct": false,
"version": "^9.0.0",
"ecosystem": "npm"
},
{
"name": "jsonwebtoken",
"direct": false,
"version": "^9.0.2",
"ecosystem": "npm"
},
{
"name": "keyv",
"direct": false,
"version": "4.5.4",
"ecosystem": "npm"
},
{
"name": "levn",
"direct": false,
"version": "0.4.1",
"ecosystem": "npm"
},
{
"name": "locate-path",
"direct": false,
"version": "6.0.0",
"ecosystem": "npm"
},
{
"name": "lodash",
"direct": false,
"version": "^4.17.21",
"ecosystem": "npm"
},
{
"name": "lodash.merge",
"direct": false,
"version": "4.6.2",
"ecosystem": "npm"
},
{
"name": "minimatch",
"direct": false,
"version": "10.2.5",
"ecosystem": "npm"
},
{
"name": "minimatch",
"direct": false,
"version": "3.1.5",
"ecosystem": "npm"
},
{
"name": "ms",
"direct": false,
"version": "2.1.3",
"ecosystem": "npm"
},
{
"name": "natural-compare",
"direct": false,
"version": "1.4.0",
"ecosystem": "npm"
},
{
"name": "node-forge",
"direct": false,
"version": "^1.3.1",
"ecosystem": "npm"
},
{
"name": "optionator",
"direct": false,
"version": "0.9.4",
"ecosystem": "npm"
},
{
"name": "p-limit",
"direct": false,
"version": "3.1.0",
"ecosystem": "npm"
},
{
"name": "p-locate",
"direct": false,
"version": "5.0.0",
"ecosystem": "npm"
},
{
"name": "parent-module",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "path-exists",
"direct": false,
"version": "4.0.0",
"ecosystem": "npm"
},
{
"name": "path-key",
"direct": false,
"version": "3.1.1",
"ecosystem": "npm"
},
{
"name": "picomatch",
"direct": false,
"version": "4.0.4",
"ecosystem": "npm"
},
{
"name": "pino",
"direct": false,
"version": "^9.2.0",
"ecosystem": "npm"
},
{
"name": "prelude-ls",
"direct": false,
"version": "1.2.1",
"ecosystem": "npm"
},
{
"name": "prettier",
"direct": false,
"version": "3.8.3",
"ecosystem": "npm"
},
{
"name": "punycode",
"direct": false,
"version": "2.3.1",
"ecosystem": "npm"
},
{
"name": "pure-rand",
"direct": false,
"version": "8.4.2",
"ecosystem": "npm"
},
{
"name": "resolve-from",
"direct": false,
"version": "4.0.0",
"ecosystem": "npm"
},
{
"name": "semver",
"direct": false,
"version": "7.8.3",
"ecosystem": "npm"
},
{
"name": "shebang-command",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "shebang-regex",
"direct": false,
"version": "3.0.0",
"ecosystem": "npm"
},
{
"name": "strip-json-comments",
"direct": false,
"version": "3.1.1",
"ecosystem": "npm"
},
{
"name": "supports-color",
"direct": false,
"version": "7.2.0",
"ecosystem": "npm"
},
{
"name": "tinyglobby",
"direct": false,
"version": "0.2.17",
"ecosystem": "npm"
},
{
"name": "ts-api-utils",
"direct": false,
"version": "2.5.0",
"ecosystem": "npm"
},
{
"name": "tsx",
"direct": false,
"version": "4.23.1",
"ecosystem": "npm"
},
{
"name": "type-check",
"direct": false,
"version": "0.4.0",
"ecosystem": "npm"
},
{
"name": "typescript",
"direct": false,
"version": "5.9.3",
"ecosystem": "npm"
},
{
"name": "typescript",
"direct": false,
"version": "^5.4.5",
"ecosystem": "npm"
},
{
"name": "typescript-eslint",
"direct": false,
"version": "8.61.0",
"ecosystem": "npm"
},
{
"name": "undici-types",
"direct": false,
"version": "8.3.0",
"ecosystem": "npm"
},
{
"name": "uri-js",
"direct": false,
"version": "4.4.1",
"ecosystem": "npm"
},
{
"name": "which",
"direct": false,
"version": "2.0.2",
"ecosystem": "npm"
},
{
"name": "word-wrap",
"direct": false,
"version": "1.2.5",
"ecosystem": "npm"
},
{
"name": "yocto-queue",
"direct": false,
"version": "0.1.0",
"ecosystem": "npm"
},
{
"name": "BouncyCastle.Cryptography",
"direct": false,
"version": "2.4.0",
"ecosystem": "nuget"
},
{
"name": "Newtonsoft.Json",
"direct": false,
"version": "13.0.3",
"ecosystem": "nuget"
},
{
"name": "System.IdentityModel.Tokens.Jwt",
"direct": false,
"version": "7.5.1",
"ecosystem": "nuget"
},
{
"name": "cryptography",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "cryptography",
"direct": false,
"version": "49.0.0",
"ecosystem": "pypi"
},
{
"name": "fastapi",
"direct": false,
"version": "0.110.1",
"ecosystem": "pypi"
},
{
"name": "paramiko",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "prometheus-client",
"direct": false,
"version": "0.20.0",
"ecosystem": "pypi"
},
{
"name": "pycryptodome",
"direct": false,
"version": "3.20.0",
"ecosystem": "pypi"
},
{
"name": "pycryptodome",
"direct": false,
"version": "3.23.0",
"ecosystem": "pypi"
},
{
"name": "pydantic-settings",
"direct": false,
"version": "2.2.1",
"ecosystem": "pypi"
},
{
"name": "pyjwt",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "pyopenssl",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "python-dotenv",
"direct": false,
"version": "1.0.1",
"ecosystem": "pypi"
},
{
"name": "requests",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "requests",
"direct": false,
"version": "2.34.2",
"ecosystem": "pypi"
},
{
"name": "structlog",
"direct": false,
"version": "24.1.0",
"ecosystem": "pypi"
},
{
"name": "uvicorn",
"direct": false,
"version": "0.29.0",
"ecosystem": "pypi"
},
{
"name": "ed25519",
"direct": false,
"version": null,
"ecosystem": "rubygems"
},
{
"name": "jwt",
"direct": false,
"version": null,
"ecosystem": "rubygems"
},
{
"name": "net-ssh",
"direct": false,
"version": null,
"ecosystem": "rubygems"
},
{
"name": "pg",
"direct": false,
"version": null,
"ecosystem": "rubygems"
},
{
"name": "puma",
"direct": false,
"version": null,
"ecosystem": "rubygems"
},
{
"name": "rails",
"direct": false,
"version": null,
"ecosystem": "rubygems"
},
{
"name": "rbnacl",
"direct": false,
"version": null,
"ecosystem": "rubygems"
},
{
"name": "rspec-rails",
"direct": false,
"version": null,
"ecosystem": "rubygems"
},
{
"name": "rubocop",
"direct": false,
"version": null,
"ecosystem": "rubygems"
}
],
"collected": true,
"truncated": false,
"total_count": 214,
"direct_count": 6,
"indirect_count": 208
}
},
"maintainership": {
"issues": {
"open_prs": 7,
"merged_prs": 17,
"open_issues": 0,
"closed_ratio": null,
"closed_issues": 0,
"closed_unmerged_prs": 14
},
"bus_factor": 1,
"bot_contributors": 1,
"top_contributors": [
{
"type": "User",
"login": "leonacostaok",
"commits": 248,
"avatar_url": "https://avatars.githubusercontent.com/u/7293791?v=4"
}
],
"contributors_sampled": 1,
"top_contributor_share": 1
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"ci.yml",
"codeql.yml",
"github-packages.yml",
"mcp-registry.yml",
"release.yml",
"scorecard.yml",
"supply-chain-audit.yml"
],
"has_docs_dir": true,
"linter_configs": [
"eslint.config.js"
],
"has_editorconfig": true,
"has_linter_config": true,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"package-lock.json"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": null,
"reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 10,
"reason": "13 out of 13 merged PRs checked by a CI test -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 5,
"reason": "badge detected: Passing",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/25 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 3,
"reason": "project has 1 contributing companies or organizations -- score normalized to 3",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 10,
"reason": "project is fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 0,
"reason": "project was created within the last 90 days. Please review its contents carefully",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": 10,
"reason": "packaging workflow detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 9,
"reason": "dependency not pinned by hash detected -- score normalized to 9",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 9,
"reason": "SAST tool detected but not run on all commits",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 10,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 10,
"reason": "GitHub workflow tokens follow principle of least privilege",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 0,
"reason": "52 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "409726240647384572233737a78f2a66bd9854d1",
"ran_at": "2026-07-27T03:49:10Z",
"aggregate_score": 7.1,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": true,
"has_security_policy": true,
"has_dependabot_config": true
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-26T17:49:06Z",
"oldest_open_prs": [
{
"number": 6,
"created_at": "2026-07-15T07:31:01Z",
"last_comment_at": "2026-07-23T10:16:56Z",
"last_comment_author": "leonacostaok"
},
{
"number": 7,
"created_at": "2026-07-15T07:31:03Z",
"last_comment_at": "2026-07-23T10:16:58Z",
"last_comment_author": "leonacostaok"
},
{
"number": 22,
"created_at": "2026-07-21T13:54:49Z",
"last_comment_at": "2026-07-23T10:17:00Z",
"last_comment_author": "leonacostaok"
},
{
"number": 23,
"created_at": "2026-07-21T13:54:51Z",
"last_comment_at": "2026-07-23T10:17:01Z",
"last_comment_author": "leonacostaok"
},
{
"number": 24,
"created_at": "2026-07-21T13:54:52Z",
"last_comment_at": "2026-07-23T10:17:03Z",
"last_comment_author": "leonacostaok"
},
{
"number": 25,
"created_at": "2026-07-21T13:55:04Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 27,
"created_at": "2026-07-23T00:48:07Z",
"last_comment_at": "2026-07-23T10:17:05Z",
"last_comment_author": "leonacostaok"
}
],
"last_merged_pr_at": "2026-07-26T17:47:26Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": []
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/quantakrypto/pqc-tools",
"host": "github.com",
"name": "pqc-tools",
"owner": "quantakrypto"
},
"metrics": {
"overall": {
"key": "overall",
"band": "moderate",
"name": "Overall health",
"note": null,
"notes": [],
"value": 67,
"inputs": {
"security": 77,
"vitality": 75,
"community": 55,
"governance": 43,
"engineering": 90
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 75,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "moderate",
"name": "Development activity",
"note": null,
"notes": [],
"value": 58,
"inputs": {
"commits_last_year": 254,
"human_commit_share": 0.98,
"days_since_last_push": 0,
"active_weeks_last_year": 6
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "6/52 weeks with commits",
"points": 4.2,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 6
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "254 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 254
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "project was created within the last 90 days. Please review its contents carefully",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 100,
"inputs": {
"releases_count": 4,
"latest_release_tag": "v1",
"releases_from_tags": false,
"days_since_latest_release": 3,
"mean_days_between_releases": 2.5
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "4 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 4
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 3 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 3
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~2.5 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 2.5
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "repository_too_young",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "moderate",
"name": "Community & Adoption",
"value": 55,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "critical",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 15,
"inputs": {
"forks": 0,
"stars": 9,
"watchers": 0,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "9 stars",
"points": 14.6,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 9
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "0 forks",
"points": 0,
"status": "missed",
"details": [
{
"code": "forks",
"params": {
"count": 0
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "0 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 0
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "excellent",
"name": "Community health",
"note": null,
"notes": [],
"value": 92,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": true,
"has_issue_template": false,
"has_code_of_conduct": true,
"has_pull_request_template": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (Apache-2.0)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "Apache-2.0"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 18,
"status": "met",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 13.5,
"status": "met",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 6.3,
"status": "met",
"details": [],
"max_points": 6.3
}
]
},
{
"key": "ecosystem_adoption",
"band": "moderate",
"name": "Ecosystem adoption (downloads)",
"note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"registry_dependents"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 66,
"inputs": {
"packages": [
"@quantakrypto/mcp",
"@quantakrypto/core",
"@quantakrypto/agent",
"@quantakrypto/qscan",
"@quantakrypto/sieve",
"@quantakrypto/qprobe"
],
"dependents": null,
"ecosystems": "npm",
"total_downloads": null,
"monthly_downloads": 8476
},
"components": [
{
"key": "monthly_downloads",
"name": "Monthly downloads",
"detail": "8,476 downloads/month across npm",
"points": 52.4,
"status": "partial",
"details": [
{
"code": "downloads_monthly",
"params": {
"count": 8476,
"ecosystems": "npm"
}
}
],
"max_points": 80
},
{
"key": "registry_dependents",
"name": "Registry dependents",
"detail": "not reported by this ecosystem",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_reported_by_this_ecosystem",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "at_risk",
"name": "Sustainability & Governance",
"value": 43,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 13,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 1,
"top_contributor_share": 1
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 100% of commits",
"points": 0,
"status": "missed",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 100
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "1 contributors",
"points": 1.4,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 1
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 1 contributing companies or organizations -- score normalized to 3",
"points": 3,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "at_risk",
"name": "Issue & PR responsiveness",
"note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"issue_resolution"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 39,
"inputs": {
"merged_prs": 17,
"open_issues": 0,
"closed_issues": 0,
"issue_closed_ratio": null,
"closed_unmerged_prs": 14
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "no issues or no data",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_issues_or_data",
"params": {}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "17/31 decided PRs merged",
"points": 21,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 17,
"decided": 31
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/25 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "at_risk",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 38,
"inputs": {
"followers": 1,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "quantakrypto",
"public_repos": 4,
"account_age_days": 34
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "1 followers of quantakrypto",
"points": 2.2,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 1,
"login": "quantakrypto"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "4 public repos, account ~0 yr old",
"points": 5.3,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 4
}
},
{
"code": "account_age_years",
"params": {
"years": 0
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"@quantakrypto/mcp",
"@quantakrypto/core",
"@quantakrypto/agent",
"@quantakrypto/qscan",
"@quantakrypto/sieve",
"@quantakrypto/qprobe"
],
"ecosystems": "npm",
"any_deprecated": false,
"min_days_since_publish": 4
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "6 package(s) on npm",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 6,
"ecosystems": "npm"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 4 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 4
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "13 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 13
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "excellent",
"name": "Engineering Quality",
"value": 90,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "excellent",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": true,
"has_linter_config": true,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "7 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 7
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": "eslint.config.js",
"points": 16,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "eslint.config.js"
}
}
],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 6.4,
"status": "met",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "13 out of 13 merged PRs checked by a CI test -- score normalized to 10",
"points": 20,
"status": "met",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "excellent",
"name": "Documentation",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"topics": [
"crypto-agility",
"cryptography",
"harvest-now-decrypt-later",
"infosec",
"post-quantum",
"pqc",
"pqc-migration",
"pqc-readiness",
"pqcrypto",
"q-day",
"quantum",
"quantum-readiness",
"security-training",
"encryption-strategy",
"pqc-certification",
"cbom",
"mcp",
"post-quantum-cryptography",
"sbom",
"nist"
],
"has_wiki": false,
"homepage": "https://quantakrypto.com/tools",
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": "https://quantakrypto.com/tools",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": "20 topics",
"points": 10,
"status": "met",
"details": [
{
"code": "topics_count",
"params": {
"count": 20
}
}
],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "good",
"name": "Security",
"value": 77,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "good",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Branch-Protection, Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"branch_protection",
"signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 71,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 16,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 2,
"scorecard_aggregate": 7.1
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "13 out of 13 merged PRs checked by a CI test -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "badge detected: Passing",
"points": 1.2,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/25 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 1 contributing companies or organizations -- score normalized to 3",
"points": 0.8,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is fuzzed",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "project was created within the last 90 days. Please review its contents carefully",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 9",
"points": 4.5,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool detected but not run on all commits",
"points": 4.5,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "GitHub workflow tokens follow principle of least privilege",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "52 existing vulnerabilities detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "excellent",
"name": "Dependency advisories",
"note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:@quantakrypto/mcp@0.5.2 runtime dependency closure — what installing the published package pulls in — 2 packages. Reachability is not analyzed.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"no_advisories_left_outstanding"
]
}
},
{
"code": "weights_renormalized",
"params": {}
},
{
"code": "advisories_scope_published",
"params": {
"package": "npm:@quantakrypto/mcp@0.5.2",
"assessed": 2
}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 100,
"inputs": {
"source": "osv",
"advisories": 0,
"affected_packages": 0,
"assessed_packages": 2,
"unassessed_packages": 0,
"affected_by_severity": "none",
"direct_affected_packages": 0
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "no direct dependency carries a known advisory",
"points": 35,
"status": "met",
"details": [
{
"code": "no_direct_advisories",
"params": {}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "no indirect dependency carries a known advisory",
"points": 25,
"status": "met",
"details": [
{
"code": "no_indirect_advisories",
"params": {}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "no advisory carries a publication date",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_no_publication_date",
"params": {}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "excellent",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 2,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 1
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "good",
"name": "AI Readiness",
"value": 70,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "at_risk",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 0.918,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "no CLAUDE.md / AGENTS.md / editor rules",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_instructions",
"params": {}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "90 of 98 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 90,
"sampled": 98
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "good",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 84,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"package-lock.json"
],
"has_dockerfile": true,
"typed_language": true,
"bootstrap_files": [],
"has_devcontainer": false,
"has_linter_config": true,
"typecheck_configs": [
"packages/action/tsconfig.json",
"packages/agent/tsconfig.json",
"packages/core/tsconfig.json",
"packages/mcp/tsconfig.json",
"packages/qprobe/tsconfig.json",
"packages/qscan/tsconfig.json",
"packages/sieve/tsconfig.json",
"tsconfig.json"
],
"agent_commit_share": 0,
"toolchain_manifests": [
"packages/core/test/benchmark/recall/csharp/Acme.Signing.csproj",
"packages/core/test/benchmark/recall/go/go.mod",
"packages/core/test/benchmark/recall/java/pom.xml",
"packages/core/test/benchmark/recall/rust/Cargo.toml"
],
"dependency_bot_commit_share": 0.02
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "packages/core/test/benchmark/recall/csharp/Acme.Signing.csproj, packages/core/test/benchmark/recall/go/go.mod, packages/core/test/benchmark/recall/java/pom.xml (toolchain convention, no task runner)",
"points": 12.6,
"status": "partial",
"details": [
{
"code": "toolchain_convention",
"params": {
"files": "packages/core/test/benchmark/recall/csharp/Acme.Signing.csproj, packages/core/test/benchmark/recall/go/go.mod, packages/core/test/benchmark/recall/java/pom.xml"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": "eslint.config.js",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "eslint.config.js"
}
}
],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "packages/action/tsconfig.json, packages/agent/tsconfig.json, packages/core/tsconfig.json, packages/mcp/tsconfig.json, packages/qprobe/tsconfig.json, packages/qscan/tsconfig.json, packages/sieve/tsconfig.json, tsconfig.json",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "packages/action/tsconfig.json, packages/agent/tsconfig.json, packages/core/tsconfig.json, packages/mcp/tsconfig.json, packages/qprobe/tsconfig.json, packages/qscan/tsconfig.json, packages/sieve/tsconfig.json, tsconfig.json"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "Dockerfile, lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Dockerfile, lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "no agent-authored commits among the last 100",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_authored_commits",
"params": {
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "2 of the last 100 commits are automated dependency updates",
"points": 8,
"status": "met",
"details": [
{
"code": "dependency_bot_commits",
"params": {
"count": 2,
"sampled": 100
}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 9",
"points": 9,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"primary_language": "TypeScript",
"largest_source_bytes": 59062,
"source_files_sampled": 454,
"oversized_source_files": 0
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "TypeScript (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "TypeScript"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "0/454 source files over 60KB",
"points": 55,
"status": "met",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 454,
"oversized": 0
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "moderate",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 60,
"inputs": {
"example_dirs": [
"examples"
],
"has_mcp_signal": true,
"api_schema_files": []
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 20,
"status": "met",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": "examples",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "examples"
}
}
],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
],
"report_type": "repository",
"generated_at": "2026-07-27T03:49:20.509862Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/q/quantakrypto/pqc-tools.svg",
"full_name": "quantakrypto/pqc-tools",
"license_state": "standard",
"license_spdx": "Apache-2.0"
}