Public record
Software health reportschema 0.27.0 · metrics 1.13.0 · 2026-07-25 23:19 UTC

rafay99-epic / envpilot.dev

The Ultimate tool for managing and securing the Environment Variables.

TypeScriptMIT★ 0 stars⑂ 0 forkssince Feb 2026View on GitHub ↗

rafay99-epic/envpilot.dev holds a health index of 63 out of 100, placing it in the Moderate band. It scores highest on Engineering Quality (89/100) and lowest on Community & Adoption (39/100). It was last updated 5 days ago. A single contributor accounts for most of its recent work.

63
overall / 100
Moderate

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

63
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

Abdul RafayPersonal account
9 followers64 public repossince Apr 2021@Tudo-Tech-Lab

This repository is owned by a personal account. A single-owner project carries more continuity risk than an organization-backed one.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publishTags
npm@envpilot/cli1.19.02,472295 days agoenvenvironmentvariablesclidotenvsecrets
npmenvpilot1.0.43553821 days ago

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

80Good · 22% of overall
How it's scored
36/36Push recency — last push 5 days ago
9/36Commit cadence — 13/52 weeks with commits
18/18Commit volume — 155 commits in the last year
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year155
human_commit_share1
days_since_last_push5
active_weeks_last_year13
How it's scored
27/27Ships releases — 79 releases published
36/36Release recency — latest release 5 days ago
27/27Release cadence — a release every ~0.2 days
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Inputs used
releases_count79
latest_release_tagv1.43.0+311a623
releases_from_tagsno
days_since_latest_release5
mean_days_between_releases0.2

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

39At risk · 18% of overall
How it's scored
0/60Stars — 0 stars
0/25Forks — 0 forks
0/15Watchers — 0 watchers
Inputs used
forks0
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (MIT)
18/18CONTRIBUTING guide
0/13.5Code of conduct
0/7.2Issue template
0/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingyes
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno
How it's scored
45.3/80Monthly downloads — 2,507 downloads/month across npm
0/20Registry dependents — not reported by this ecosystem
Inputs used
packages@envpilot/cli, envpilot
dependents
ecosystemsnpm
total_downloads
monthly_downloads2,507
Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

54Moderate · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
0/22.5Commit distribution — top contributor authored 100% of commits
1.4/13.5Contributor breadth — 1 contributors
3/10OpenSSF Scorecard: Contributors — project has 1 contributing companies or organizations -- score normalized to 3
Inputs used
bus_factor1
contributors_sampled1
top_contributor_share1
How it's scored
0/46.8Issue resolution — no issues or no data
36.3/38.3PR acceptance — 147/155 decided PRs merged
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Inputs used
merged_prs147
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs8
Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.
How it's scored
10/30Ownership backing — personal (user) account
0/20Verified domain — not applicable to user accounts
7.2/25Owner reach — 9 followers of rafay99-epic
23.5/25Track record — 64 public repos, account ~5 yr old
Inputs used
followers9
owner_typeUser
is_verified
owner_loginrafay99-epic
public_repos64
account_age_days1,926
Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.
How it's scored
25/25Published & resolvable — 2 package(s) on npm
35/35Publish recency — latest publish 5 days ago
20/20Version history — 29 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packages@envpilot/cli, envpilot
ecosystemsnpm
any_deprecatedno
min_days_since_publish5

Engineering Quality

Are baseline engineering and documentation practices in place?

89Excellent · 20% of overall
How it's scored
24/24CI workflows — 8 workflow(s)
24/24Tests present
16/16Linter config — eslint.config.mjs
0/9.6Pre-commit hooks
0/6.4.editorconfig
18/20OpenSSF Scorecard: CI-Tests — 29 out of 30 merged PRs checked by a CI test -- score normalized to 9
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configyes
has_precommit_configno

Documentation

100Excellent
How it's scored
30/30README
25/25Documentation directory
15/15Documentation / homepage site — https://envpilot.dev
10/10Repository description
10/10Topics — 7 topics
10/10Wiki
Inputs used
topicscli, code, convex, extension, nextjs, role-based-access-control, vs
has_wikiyes
homepagehttps://envpilot.dev
has_readmeyes
has_docs_diryes
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

46At risk · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
2.2/2.5CI-Tests — 29 out of 30 merged PRs checked by a CI test -- score normalized to 9
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0.8/2.5Contributors — project has 1 contributing companies or organizations -- score normalized to 3
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — no data
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
2/5Security-Policy — security policy file detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 94 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate3.2
Excluded from scoring (no data or not applicable): packaging. Remaining weights renormalized.
How it's scored
35/35Direct dependencies free of known advisories — no direct dependency carries a known advisory
25/25Indirect dependencies free of known advisories — no indirect dependency carries a known advisory
0/40No advisories left outstanding — no advisory carries a publication date
Inputs used
sourceosv
advisories0
affected_packages0
assessed_packages186
unassessed_packages0
affected_by_severitynone
direct_affected_packages0
Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:@envpilot/cli@1.19.0 runtime dependency closure — what installing the published package pulls in — 186 packages. Reachability is not analyzed.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

63Moderate · 0% of overall
How it's scored
45/45Agent instructions — .agents/skills/vercel-react-best-practices/AGENTS.md, AGENTS.md, CLAUDE.md
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 95 of 100 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share0.95
agent_instruction_files.agents/skills/vercel-react-best-practices/AGENTS.md, AGENTS.md, CLAUDE.md
agent_instruction_max_bytes105,774
How it's scored
0/18One-command bootstrap
22/22Automated tests
11/11Lint / format config — eslint.config.mjs
11/11Static type checking — apps/admin/tsconfig.json, apps/blog/tsconfig.json, apps/cli/tsconfig.json, apps/docs/tsconfig.json, apps/vscode-extension/tsconfig.json, apps/web/tsconfig.json, convex/tsconfig.json, packages/github-action/tsconfig.json, packages/ui/tsconfig.json
0/10Reproducible environment
4/10Demonstrated agent practice — 2 of the last 100 commits agent-authored or agent-credited
0/8Automated maintenance — no automated dependency updates observed
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Inputs used
has_nixno
has_testsyes
lockfiles
has_dockerfileno
typed_languageyes
bootstrap_files
has_devcontainerno
has_linter_configyes
typecheck_configsapps/admin/tsconfig.json, apps/blog/tsconfig.json, apps/cli/tsconfig.json, apps/docs/tsconfig.json, apps/vscode-extension/tsconfig.json, apps/web/tsconfig.json, convex/tsconfig.json, packages/github-action/tsconfig.json, packages/ui/tsconfig.json
agent_commit_share0.02
toolchain_manifests
dependency_bot_commit_share0
How it's scored
45/45Type-checkable code — TypeScript (statically typed)
54.6/55Manageable file sizes — 5/697 source files over 60KB
Inputs used
primary_languageTypeScript
largest_source_bytes76,271
source_files_sampled697
oversized_source_files5
How it's scored
0/40API schema (OpenAPI/GraphQL/proto)
20/20MCP server
0/40Runnable examples
Inputs used
example_dirs
has_mcp_signalyes
api_schema_files

Key facts

0GitHub stars
1contributors
155commits, last 12 months
5days since last push
79releases
1bus factor
0open issues
npmpackage ecosystems

More detail

OpenSSF Scorecard 3.2 / 10
3.2aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-25 23:18 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
9CI-Tests29 out of 30 merged PRs checked by a CI test -- score normalized to 9
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
3Contributorsproject has 1 contributing companies or organizations -- score normalized to 3
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
n/aPackagingpackaging workflow not detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
4Security-Policysecurity policy file detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities94 existing vulnerabilities detected
Direct dependencies 83
RegistryPackageVersion constraintManifest
npm@convex-dev/rate-limiter^0.3.2package.json
npm@convex-dev/workflow^0.3.5package.json
npm@convex-dev/workpool^0.4.1package.json
npmresend^6.9.3package.json
npm@dnd-kit/core^6.3.1apps/admin/package.json
npm@dnd-kit/utilities^3.2.2apps/admin/package.json
npm@fontsource-variable/geist^5.2.8apps/admin/package.json
npm@fontsource-variable/geist-mono^5.2.8apps/admin/package.json
npm@tanstack/react-router^1.120.3apps/admin/package.json
npm@workos-inc/authkit-react^0.16.1apps/admin/package.json
npmclass-variance-authority^0.7.1apps/admin/package.json
npmclsx^2.1.1apps/admin/package.json
npmconvex^1.32.0apps/admin/package.json
npmdate-fns^4.1.0apps/admin/package.json
npmlucide-react^0.577.0apps/admin/package.json
npmreact^19.1.0apps/admin/package.json
npmreact-dom^19.1.0apps/admin/package.json
npmreact-markdown^10.1.0apps/admin/package.json
npmremark-gfm^4.0.1apps/admin/package.json
npmtailwind-merge^3.0.2apps/admin/package.json
npmzustand^5.0.5apps/admin/package.json
npm@envpilot/uiworkspace:*apps/blog/package.json
npmdate-fns^4.1.0apps/blog/package.json
npmgray-matter^4.0.3apps/blog/package.json
npmlucide-react^0.577.0apps/blog/package.json
npmnext^16.2.10apps/blog/package.json
npmnext-mdx-remote^6.0.0apps/blog/package.json
npmreact^19.2.4apps/blog/package.json
npmreact-dom^19.2.4apps/blog/package.json
npmrehype-pretty-code^0.14.3apps/blog/package.json
npmremark-gfm^4.0.1apps/blog/package.json
npmshiki^4.0.2apps/blog/package.json
npmzod^4.3.6apps/blog/package.json
npm@sentry/node^10.43.0apps/cli/package.json
npmchalk^5.3.0apps/cli/package.json
npmcommander^12.1.0apps/cli/package.json
npmconf^13.0.1apps/cli/package.json
npmconvex^1.32.0apps/cli/package.json
npmcross-spawn^7.0.6apps/cli/package.json
npmdotenv^16.4.7apps/cli/package.json
npmink^5.2.1apps/cli/package.json
npminquirer^12.3.2apps/cli/package.json
npmopen^10.1.0apps/cli/package.json
npmora^8.1.1apps/cli/package.json
npmreact^18.3.1apps/cli/package.json
npmzod^4.3.6apps/cli/package.json
npm@sentry/node^10.43.0apps/vscode-extension/package.json
npmaxios^1.6.2apps/vscode-extension/package.json
npmconvex^1.32.0apps/vscode-extension/package.json
npm@envpilot/uiworkspace:*apps/web/package.json
npm@modelcontextprotocol/sdk^1.29.0apps/web/package.json
npm@polar-sh/sdk^0.46.6apps/web/package.json
npm@sentry/nextjs^10apps/web/package.json
npm@tanstack/react-hotkeys^0.4.1apps/web/package.json
npm@tanstack/react-query^5.90.21apps/web/package.json
npm@vercel/analytics^1.6.1apps/web/package.json
npm@workos-inc/authkit-nextjs^2.14.0apps/web/package.json
npm@workos-inc/node^8.5.0apps/web/package.json
npmcanvas-confetti^1.9.4apps/web/package.json
npmclass-variance-authority^0.7.1apps/web/package.json
npmclsx^2.1.1apps/web/package.json
npmconvex^1.32.0apps/web/package.json
npmdate-fns^4.1.0apps/web/package.json
npmframer-motion^12.35.2apps/web/package.json
npmjose^5.10.0apps/web/package.json
npmlucide-react^0.577.0apps/web/package.json
npmmcp-handler1.1.0apps/web/package.json
npmnext^16.2.10apps/web/package.json
npmreact^19.2.4apps/web/package.json
npmreact-dom^19.2.4apps/web/package.json
npmreact-markdown^10.1.0apps/web/package.json
npmrecharts^3.8.0apps/web/package.json
npmremark-gfm^4.0.1apps/web/package.json
npmsonner^2.0.7apps/web/package.json
npmtailwind-merge^3.5.0apps/web/package.json
npmzod^4.3.6apps/web/package.json
npmzustand^5.0.11apps/web/package.json
npmtypescript-eslint^8packages/eslint-config/package.json
npm@actions/core^1.11.1packages/github-action/package.json
npmdate-fns^4.1.0packages/ui/package.json
npmframer-motion^12.35.2packages/ui/package.json
npmlucide-react^0.577.0packages/ui/package.json
npmmermaid^11packages/ui/package.json
All dependencies 100

Full resolved dependency set from the GitHub dependency graph: 60 direct and 40 indirect (transitive) packages. The transitive closure is complete when the repository commits a lockfile.

RegistryPackageVersionRelation
npm@actions/core^1.11.1direct
npm@convex-dev/rate-limiter^0.3.2direct
npm@convex-dev/workflow^0.3.5direct
npm@convex-dev/workpool^0.4.1direct
npm@dnd-kit/core^6.3.1direct
npm@dnd-kit/utilities^3.2.2direct
npm@fontsource-variable/geist^5.2.8direct
npm@fontsource-variable/geist-mono^5.2.8direct
npm@modelcontextprotocol/sdk^1.29.0direct
npm@polar-sh/sdk^0.46.6direct
npm@sentry/nextjs^10direct
npm@sentry/node^10.43.0direct
npm@tanstack/react-hotkeys^0.4.1direct
npm@tanstack/react-query^5.90.21direct
npm@tanstack/react-router^1.120.3direct
npm@vercel/analytics^1.6.1direct
npm@workos-inc/authkit-nextjs^2.14.0direct
npm@workos-inc/authkit-react^0.16.1direct
npm@workos-inc/node^8.5.0direct
npmaxios^1.6.2direct
npmcanvas-confetti^1.9.4direct
npmchalk^5.3.0direct
npmclass-variance-authority^0.7.1direct
npmclsx^2.1.1direct
npmcommander^12.1.0direct
npmconf^13.0.1direct
npmconvex^1.32.0direct
npmcross-spawn^7.0.6direct
npmdate-fns^4.1.0direct
npmdotenv^16.4.7direct
npmframer-motion^12.35.2direct
npmgray-matter^4.0.3direct
npmink^5.2.1direct
npminquirer^12.3.2direct
npmjose^5.10.0direct
npmlucide-react^0.577.0direct
npmmcp-handler1.1.0direct
npmmermaid^11direct
npmnext^16.2.10direct
npmnext-mdx-remote^6.0.0direct
npmopen^10.1.0direct
npmora^8.1.1direct
npmreact^18.3.1direct
npmreact^19.1.0direct
npmreact^19.2.4direct
npmreact-dom^19.1.0direct
npmreact-dom^19.2.4direct
npmreact-markdown^10.1.0direct
npmrecharts^3.8.0direct
npmrehype-pretty-code^0.14.3direct
npmremark-gfm^4.0.1direct
npmresend^6.9.3direct
npmshiki^4.0.2direct
npmsonner^2.0.7direct
npmtailwind-merge^3.0.2direct
npmtailwind-merge^3.5.0direct
npmtypescript-eslint^8direct
npmzod^4.3.6direct
npmzustand^5.0.11direct
npmzustand^5.0.5direct
npm@next/bundle-analyzer^16.2.3indirect
npm@playwright/test^1.58.2indirect
npm@tailwindcss/postcss^4indirect
npm@tailwindcss/vite^4.1.7indirect
npm@tanstack/react-query-devtools^5.91.3indirect
npm@tanstack/router-plugin^1.120.3indirect
npm@types/canvas-confetti^1.9.0indirect
npm@types/cross-spawn^6.0.6indirect
npm@types/node^22indirect
npm@types/node^22.10.10indirect
npm@types/node^22.15.0indirect
npm@types/react^18.3.12indirect
npm@types/react^19indirect
npm@types/react^19.1.6indirect
npm@types/react-dom^19indirect
npm@types/react-dom^19.1.6indirect
npm@types/vscode^1.85.0indirect
npm@vitejs/plugin-react^4.5.2indirect
npm@vscode/vsce^3.7.1indirect
npmbabel-plugin-react-compiler1.0.0indirect
npmconcurrently^9.1.2indirect
npmesbuild^0.19.8indirect
npmeslint^9indirect
npmeslint^9.28.0indirect
npmeslint-config-next16.1.6indirect
npmeslint-config-next^16.2.10indirect
npmnodemailer^9.0.3indirect
npmnpm-run-all^4.1.5indirect
npmprettier^3.6.2indirect
npmtailwindcss^4indirect
npmtailwindcss^4.1.7indirect
npmtsup^8.3.5indirect
npmturbo^2indirect
npmtypescript^5indirect
npmtypescript^5.3.2indirect
npmtypescript^5.7.3indirect
npmtypescript^5.8.3indirect
npmvite^6.3.5indirect
npmvitest^1.0.0indirect
npmvitest^3.0.4indirect
Dependency advisories 0

Installing npm:@envpilot/cli@1.19.0 pulls in 186 packages, direct and transitive: 0 carry known advisories, of which 0 are direct dependencies.

No known advisories affect the assessed dependencies.

An advisory means the version recorded in the dependency graph falls inside an advisory’s affected range. Reachability is not analysed, and the graph includes development and test pins — a finding may concern tooling rather than shipped software.

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [
        "cli",
        "code",
        "convex",
        "extension",
        "nextjs",
        "role-based-access-control",
        "vs"
      ],
      "is_fork": false,
      "size_kb": 15085,
      "has_wiki": true,
      "homepage": "https://envpilot.dev",
      "languages": {
        "CSS": 21848,
        "MDX": 509741,
        "HTML": 348,
        "Shell": 17209,
        "Python": 28427,
        "JavaScript": 17426,
        "TypeScript": 4831287
      },
      "pushed_at": "2026-07-20T10:29:58Z",
      "created_at": "2026-02-24T13:47:28Z",
      "owner_type": "User",
      "updated_at": "2026-07-20T09:14:55Z",
      "description": "The Ultimate tool for managing and securing the Environment Variables.  ",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": "https://rafay99.com",
      "name": "Abdul Rafay",
      "type": "User",
      "login": "rafay99-epic",
      "company": "@Tudo-Tech-Lab ",
      "location": "Islamabad",
      "followers": 9,
      "avatar_url": "https://avatars.githubusercontent.com/u/82662797?v=4",
      "created_at": "2021-04-16T14:01:05Z",
      "is_verified": null,
      "public_repos": 64,
      "account_age_days": 1926
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v1.43.0+311a623",
          "kind": "minor",
          "published_at": "2026-07-20T09:17:24Z"
        },
        {
          "tag": "v1.43.0",
          "kind": "minor",
          "published_at": "2026-07-20T08:28:55Z"
        },
        {
          "tag": "v1.42.0+82294d4",
          "kind": "minor",
          "published_at": "2026-07-20T07:40:36Z"
        },
        {
          "tag": "v1.42.0+45632a8",
          "kind": "minor",
          "published_at": "2026-07-19T23:50:52Z"
        },
        {
          "tag": "v1.42.0+1662e22",
          "kind": "minor",
          "published_at": "2026-07-19T23:22:35Z"
        },
        {
          "tag": "v1.42.0+0817718",
          "kind": "minor",
          "published_at": "2026-07-19T19:50:52Z"
        },
        {
          "tag": "v1.42.0",
          "kind": "minor",
          "published_at": "2026-07-19T15:13:14Z"
        },
        {
          "tag": "v1.41.0+4bbb02e",
          "kind": "minor",
          "published_at": "2026-07-18T22:02:12Z"
        },
        {
          "tag": "v1.41.0+f2543de",
          "kind": "minor",
          "published_at": "2026-07-18T16:15:37Z"
        },
        {
          "tag": "v1.41.0",
          "kind": "minor",
          "published_at": "2026-07-18T15:42:37Z"
        },
        {
          "tag": "v1.40.0",
          "kind": "minor",
          "published_at": "2026-07-18T15:37:04Z"
        },
        {
          "tag": "v1.39.0+3e7098b",
          "kind": "minor",
          "published_at": "2026-07-18T14:23:30Z"
        },
        {
          "tag": "v1.39.0",
          "kind": "minor",
          "published_at": "2026-07-18T10:35:03Z"
        },
        {
          "tag": "v1.38.0+a356984",
          "kind": "minor",
          "published_at": "2026-07-17T23:38:03Z"
        },
        {
          "tag": "v1.38.0+839e60a",
          "kind": "minor",
          "published_at": "2026-07-17T23:33:45Z"
        },
        {
          "tag": "v1.38.0",
          "kind": "minor",
          "published_at": "2026-07-17T23:28:29Z"
        },
        {
          "tag": "v1.37.0",
          "kind": "minor",
          "published_at": "2026-07-17T23:21:53Z"
        },
        {
          "tag": "v1.35.0",
          "kind": "minor",
          "published_at": "2026-07-17T14:46:06Z"
        },
        {
          "tag": "v1.34.3+c8527bc",
          "kind": "patch",
          "published_at": "2026-07-16T21:10:42Z"
        },
        {
          "tag": "v1.34.3+312587d",
          "kind": "patch",
          "published_at": "2026-07-16T21:08:22Z"
        },
        {
          "tag": "v1.34.3",
          "kind": "patch",
          "published_at": "2026-07-16T21:05:26Z"
        },
        {
          "tag": "v1.34.2+dfde4fe",
          "kind": "patch",
          "published_at": "2026-07-16T18:38:58Z"
        },
        {
          "tag": "v1.34.2+c2ab3d1",
          "kind": "patch",
          "published_at": "2026-07-16T18:05:50Z"
        },
        {
          "tag": "v1.34.2",
          "kind": "patch",
          "published_at": "2026-07-16T16:06:00Z"
        },
        {
          "tag": "v1.34.1",
          "kind": "patch",
          "published_at": "2026-07-16T15:51:38Z"
        },
        {
          "tag": "v1.34.0",
          "kind": "minor",
          "published_at": "2026-07-16T15:25:34Z"
        },
        {
          "tag": "v1.33.1+b54d303",
          "kind": "patch",
          "published_at": "2026-07-12T01:15:31Z"
        },
        {
          "tag": "v1.33.1+b9e030d",
          "kind": "patch",
          "published_at": "2026-07-12T01:08:59Z"
        },
        {
          "tag": "v1.33.1+053738d",
          "kind": "patch",
          "published_at": "2026-07-12T00:38:02Z"
        },
        {
          "tag": "v1.33.1+7130477",
          "kind": "patch",
          "published_at": "2026-07-11T23:58:40Z"
        },
        {
          "tag": "v1.33.1+7e70c5d",
          "kind": "patch",
          "published_at": "2026-07-11T22:32:36Z"
        },
        {
          "tag": "v1.33.1+e9cc2d0",
          "kind": "patch",
          "published_at": "2026-07-11T21:18:31Z"
        },
        {
          "tag": "v1.33.1",
          "kind": "patch",
          "published_at": "2026-07-11T21:12:32Z"
        },
        {
          "tag": "v1.33.0+6426bca",
          "kind": "minor",
          "published_at": "2026-07-11T20:03:14Z"
        },
        {
          "tag": "v1.33.0",
          "kind": "minor",
          "published_at": "2026-07-11T19:07:47Z"
        },
        {
          "tag": "v1.32.0",
          "kind": "minor",
          "published_at": "2026-07-11T19:00:02Z"
        },
        {
          "tag": "v1.31.0+435b07e",
          "kind": "minor",
          "published_at": "2026-07-11T11:09:12Z"
        },
        {
          "tag": "v1.31.0+74f81b7",
          "kind": "minor",
          "published_at": "2026-07-11T09:00:36Z"
        },
        {
          "tag": "v1.31.0",
          "kind": "minor",
          "published_at": "2026-07-11T08:14:24Z"
        },
        {
          "tag": "v1.30.0+367989a",
          "kind": "minor",
          "published_at": "2026-07-11T00:46:27Z"
        },
        {
          "tag": "v1.30.0",
          "kind": "minor",
          "published_at": "2026-07-11T00:33:47Z"
        },
        {
          "tag": "v1.29.1+4857e19",
          "kind": "patch",
          "published_at": "2026-07-10T22:51:01Z"
        },
        {
          "tag": "v1.29.1",
          "kind": "patch",
          "published_at": "2026-07-10T22:21:55Z"
        },
        {
          "tag": "v1.29.0",
          "kind": "minor",
          "published_at": "2026-07-10T20:54:18Z"
        },
        {
          "tag": "v1.28.2",
          "kind": "patch",
          "published_at": "2026-07-10T13:37:22Z"
        },
        {
          "tag": "v1.28.1",
          "kind": "patch",
          "published_at": "2026-07-09T21:47:38Z"
        },
        {
          "tag": "v1.28.0+1f9cf8f",
          "kind": "minor",
          "published_at": "2026-07-09T19:46:00Z"
        },
        {
          "tag": "v1.28.0+2945131",
          "kind": "minor",
          "published_at": "2026-07-09T16:41:23Z"
        },
        {
          "tag": "v1.28.0+5cbebf6",
          "kind": "minor",
          "published_at": "2026-07-09T16:24:47Z"
        },
        {
          "tag": "v1.28.0",
          "kind": "minor",
          "published_at": "2026-07-09T16:14:10Z"
        },
        {
          "tag": "v1.27.0",
          "kind": "minor",
          "published_at": "2026-07-06T08:04:18Z"
        },
        {
          "tag": "v1.26.1",
          "kind": "patch",
          "published_at": "2026-07-06T02:02:22Z"
        },
        {
          "tag": "v1.26.0",
          "kind": "minor",
          "published_at": "2026-07-06T01:23:07Z"
        },
        {
          "tag": "v1.25.0+07d968b",
          "kind": "minor",
          "published_at": "2026-07-06T00:54:43Z"
        },
        {
          "tag": "v1.25.0+5d6c044",
          "kind": "minor",
          "published_at": "2026-07-05T23:58:39Z"
        },
        {
          "tag": "v1.25.0+58a6582",
          "kind": "minor",
          "published_at": "2026-07-05T23:00:08Z"
        },
        {
          "tag": "v1.25.0",
          "kind": "minor",
          "published_at": "2026-07-05T21:35:34Z"
        },
        {
          "tag": "v1.22.1+9b48c88",
          "kind": "patch",
          "published_at": "2026-07-05T03:06:23Z"
        },
        {
          "tag": "v1.22.1",
          "kind": "patch",
          "published_at": "2026-07-05T02:59:42Z"
        },
        {
          "tag": "v1.22.0",
          "kind": "minor",
          "published_at": "2026-07-04T14:58:50Z"
        },
        {
          "tag": "v1.21.0",
          "kind": "minor",
          "published_at": "2026-07-04T13:56:53Z"
        },
        {
          "tag": "v1.20.1",
          "kind": "patch",
          "published_at": "2026-07-04T13:31:34Z"
        },
        {
          "tag": "v1.20.0",
          "kind": "minor",
          "published_at": "2026-07-04T12:46:11Z"
        },
        {
          "tag": "v1.19.0",
          "kind": "minor",
          "published_at": "2026-07-03T18:03:39Z"
        },
        {
          "tag": "v1.18.0+2162334",
          "kind": "minor",
          "published_at": "2026-07-03T17:58:12Z"
        },
        {
          "tag": "v1.18.0+178eed0",
          "kind": "minor",
          "published_at": "2026-07-03T17:54:50Z"
        },
        {
          "tag": "v1.18.0",
          "kind": "minor",
          "published_at": "2026-07-03T17:06:32Z"
        },
        {
          "tag": "v1.16.0+5ae00db",
          "kind": "minor",
          "published_at": "2026-07-03T08:08:03Z"
        },
        {
          "tag": "v1.16.0",
          "kind": "minor",
          "published_at": "2026-07-03T01:45:08Z"
        },
        {
          "tag": "v1.15.1+fc9e4af",
          "kind": "patch",
          "published_at": "2026-07-02T20:06:00Z"
        },
        {
          "tag": "v1.15.1+4354f36",
          "kind": "patch",
          "published_at": "2026-07-02T19:58:49Z"
        },
        {
          "tag": "v1.15.1",
          "kind": "patch",
          "published_at": "2026-07-02T10:30:19Z"
        },
        {
          "tag": "v1.12.1",
          "kind": "patch",
          "published_at": "2026-07-01T20:11:55Z"
        },
        {
          "tag": "v1.12.0",
          "kind": "minor",
          "published_at": "2026-06-12T08:38:25Z"
        },
        {
          "tag": "v1.11.0+803c0be",
          "kind": "minor",
          "published_at": "2026-06-08T09:33:47Z"
        },
        {
          "tag": "v1.11.0",
          "kind": "minor",
          "published_at": "2026-04-22T22:36:49Z"
        },
        {
          "tag": "cli-v1.6.1",
          "kind": "other",
          "published_at": "2026-04-17T18:46:17Z"
        },
        {
          "tag": "cli-v1.6.0",
          "kind": "other",
          "published_at": "2026-04-16T22:14:21Z"
        },
        {
          "tag": "cli-v1.5.0",
          "kind": "other",
          "published_at": "2026-04-15T19:40:06Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "311a623aa78b20ef168b3f9e779cca4e961d0274",
          "body": "…e MCP secrets (#156)\n\nContent backlog #1 and #2 from the GTM playbook:\n- 'dotenv-vault Is Deprecated — Here's Your Migration Path' (keyword:\n  dotenv-vault alternative). Honest three-way comparison: dotenvx as the\n  official successor, Doppler/Infisical per-seat, Envpilot flat — with a\n  real 10-mi\n[…]\ndge). Facts sourced from docs/mcp-server.mdx: endpoint, five\n  read-only tools, scoped keys, metadata_only, audit, rate limits, run\n  injection. Dated Jul 23 per playbook cadence.\n\nblog 1.5.0 -> 1.6.0",
          "is_bot": false,
          "headline": "feat(blog): week-1 GTM articles — dotenv-vault migration + Claude Cod…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-20T09:14:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "42bc6702a432e091b7c7c679e159f76c4667ffe9",
          "body": "* feat: MCP key scope guidance + unredacted API denials\n\nAn MCP key minted with the default scopes (variables only) failed every\ntool call, and prod redaction turned each denial into an opaque\n\"Server Error\"/500 — invisible in dev where plain Error survives.\n\n- create-key form: MCP panel maps each r\n[…]\n 'recommended' (requests/accounts-only\n  keys are valid), canceled request status, transport-level 401 for\n  missing bearer, request-tools denial variant, 5/hour request bucket\n  in the rate-limit row",
          "is_bot": false,
          "headline": "MCP key scope guidance + unredacted public API denials (#155)",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-20T08:20:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "82294d4f1d19d485d059c3d44ae467c02210d4c7",
          "body": "* docs: reorder MCP client setup, add Codex CLI, sync CLI reference with code\n\nMCP server page:\n- Move 'Connect a client' above tool/rate-limit reference so setup is first\n- Add Codex CLI setup (codex mcp add / config.toml, bearer_token_env_var)\n- Expand Claude Code entry with scope flags and verify\n[…]\n stale 'lower roles create requests' claim, fix 'approval-aware' wording\n- cli logout: state --all partial-failure behavior instead of promising it\n  always signs out every account\n\n* fixing-formating",
          "is_bot": false,
          "headline": "docs: MCP client setup (Codex + reorder) and CLI reference sync (#154)",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-20T07:37:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "45632a8879c1af4f245b66df9b0c804dfb8af2f0",
          "body": "…CLI 1.19.0 reference) (#153)\n\n* docs(cli): document the 1.19.0 command surface\n\n- new sections: secrets set/rm (masked two-step flow, role routing,\n  shared-environment semantics), variable requests review\n  (approve/reject/cancel, --value-stdin, masked machine-request\n  approval), diff (metadata d\n[…]\n+ full-page noise were layered behind body\ntext — decorative on marketing pages, hostile on a reading surface.\nDoc articles now render on a plain background; effects remain on\nnon-reading pages (404).",
          "is_bot": false,
          "headline": "Docs overhaul: categorized sidebar, deep rewrites, four new pages (+ …",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-19T23:47:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1662e225f98b478c2b05e63ba7b54f361687f9a0",
          "body": "…152)\n\n* fix(cli): run picks up variable changes; warns about other-env vars\n\nThe missing-variables bug: run cached decrypted secrets for 1h and made\nZERO server contact within that window, so a variable added/changed in\nthe dashboard was invisible for up to an hour. Root fix:\n\n- default --cache-ttl\n[…]\nith truncated/undecryptable as fields (warnings no longer\n  corrupt stdout).\n- requests approve: --value rejected on a TTY (masked prompt is the\n  interactive path); --value-stdin/--value stay for CI.",
          "is_bot": false,
          "headline": "CLI terminal-first: run fix + var/requests/diff commands (v1.19.0) (#…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-19T23:16:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0817718d4942e12980ea83990e3ac5e5600ab874",
          "body": "* fix(authz): enforce membership on projects.getById and listByOrganization\n\nBoth were bare public Convex queries — callable by anyone with the\ndeployment URL, no identity check, leaking project metadata across org\nboundaries (same class as the getBySlug hole closed in #150).\n\n- getById / listByOrga\n[…]\n, and\nprojects.getById/getBySlug now hard-depend on it. Docs now state the\nreal contract: sync the users row first, one authed client per handler,\nand getProjectOrganization requires an authed client.",
          "is_bot": false,
          "headline": "Enforce membership on projects.getById and listByOrganization (#151)",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-19T19:44:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "584daf465a1a7fab7d42d13375b4567a0ed2b008",
          "body": "…e mermaid (#150)\n\n* perf(content): single-pass MDX parse with React cache() in blog and docs\n\ngetDocBySlug/getAllDocs/getPostBySlug/getAllPosts now memoize per request;\nllms-full.txt builds from getAllDocsFull() instead of re-reading every file\na second time (O(2N) -> O(N) file I/O).\n\n* chore(hygie\n[…]\nrom the\n  pre-ResizeObserver measure\n\nRejected cubic finding: pulse-glow keyframe DOES exist\n(packages/ui/src/styles.css:55) and three shipped components use the\nidentical arbitrary-animation pattern.",
          "is_bot": false,
          "headline": "Next.js audit fixes, faster dashboard navigation, Next 16.2.10, inlin…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-19T15:04:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4bbb02ed375d59537802f097fcbfec45e0b5bac5",
          "body": "…s, series support (#149)\n\n* content(blog): ten engineering posts from the PR history (blog v1.2.0)\n\nTen long-form posts, each reconstructed from the real PRs, diffs and\ncurrent source rather than summarised from titles:\n\n- the-auth-cutover                      #83 #84 #85 #87 #88 #90\n- deletion-tha\n[…]\n 18 engineering posts are \"Building Envpilot\", numbered by date.\n\n47 mermaid diagrams parse under 11.16; verified rendering against the\nproduction build. 27 static pages, typecheck and prettier green.",
          "is_bot": false,
          "headline": "Blog: 18-post 'Building Envpilot' engineering series, mermaid diagram…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-18T21:53:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f2543de18c7a8cda44806b9718c541b54bb8ffb7",
          "body": "* ci: enable Vercel prod deploys for web, admin, blog, and docs\n\nThe GitHub Actions migration (#139) hard-disabled every Vercel deploy job\n(if: false &&) expecting Vercel's git integration to take over — but git\nauto-deploy was never enabled (all four vercel.json files still have\ngit.deploymentEnabl\n[…]\nnotes table shows real per-app\n  deploy statuses instead of a static Vercel label.\n- Pin the Vercel CLI to 56.3.1 in deploy-vercel.yml so prod deploy\n  behavior can't change via a silent @latest bump.",
          "is_bot": false,
          "headline": "ci: enable Vercel prod deploys for web, admin, blog, and docs (#148)",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-18T16:05:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b4c587eed5404d4782a78030c1cfed51b0e8ecfc",
          "body": "* feat(requests): machine-initiated variable requests + serviceTokens retirement\n\nAgents authenticated with an API key carrying the new 'requests' resource\n(the ONE mutating capability a key can have) file variable requests via\ntwo new MCP tools; a human reviewer approves in the dashboard and suppli\n[…]\name attribute — the one shape the pipeline preserves. Static import\n(build-resolved), console error + raw-source fallback instead of a\nsilent blank on render failure, StrictMode-safe fresh render ids.",
          "is_bot": false,
          "headline": "Machine-initiated variable requests + serviceTokens retirement (#147)",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-18T15:38:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "889b3811e6e57c5f3d86f97c0b85fbe555ee9342",
          "body": "…edentials (#146)\n\n* feat(api): one token model — surfaces field unifies Action/REST/MCP credentials\n\napiKeys gains an explicit surfaces array (github_action | rest_api |\nmcp_server); absent = grandfathered pre-surfaces key, valid everywhere.\n_authorizeRequest enforces surface scope (new surface_sco\n[…]\ny row's scope line wraps instead of truncating, so the surface\n  and expiry portion of a credential's scope is never hidden\n\n* fix(ui): DrawerPanel keeps focus pinned when it has no focusable children",
          "is_bot": false,
          "headline": "One Token Model: surfaces field unifies GitHub Action / REST / MCP cr…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-18T15:33:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3e7098b5c2323aa856f119a402fd9ad1a5476084",
          "body": "…g fixes (1.16.0) (#144)\n\n* feat(extension): clipboard lockdown — guard scope, cloaking, path identity\n\n* feat(extension): secret-name autocomplete + masked hover (ported from DopplerHQ/vscode, Apache-2.0)\n\n* fix(extension): sync correctness — self-write suppression, rebaseline drop, multi-root, ato\n[…]\nddress cubic review findings (PR #144)\n\n* docs(extension): add changelog for 1.16.0\n\n* docs(changelog): seed v1.49.1 entry — VS Code clipboard lockdown, cloaking, IntelliSense; drop stray CHANGELOG.md",
          "is_bot": false,
          "headline": "feat(extension): clipboard lockdown, IntelliSense, and 26 verified bu…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-18T14:19:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "209b7ecc5d4f0b082ef9e9e014faabaf82ea49c8",
          "body": "…builds (#145)\n\n* feat(admin): auth cutover - WorkOS AuthKit replaces shared admin secret\n\n* feat(admin): terminal design system + primitives\n\n* feat(admin): page rebuilds - tiers tab split, QueryState everywhere, cleanup\n\n* chore(admin): version bumps (admin 1.8.0, root 1.39.0)\n\n* fix(admin): apply\n[…]\ne list served by the backend allowlist (frontend\n  copy had drifted); login page explains the needs-an-account case\n\n* fix(admin): sign out returns to the admin origin, not the WorkOS default redirect",
          "is_bot": false,
          "headline": "Admin panel overhaul: WorkOS AuthKit, terminal design system, page re…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-18T10:32:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d15649c8d16d995deb01808e686c9c49438882f5",
          "body": "* docs: rewrite README for the public repo — pitch users, fix stale proprietary notice\n\nThe README was written for the private monorepo: contributor-only content,\nand a License section still claiming 'This project is proprietary software'\ndirectly under the MIT badge. Now that the repo is public, th\n[…]\ned\ntable, CLI quickstart, security, open-source-vs-paid, contributing, license.\nContributor setup and repo layout collapse into a details block so the\ntop of the page speaks to users, not maintainers.",
          "is_bot": false,
          "headline": "docs: rewrite README for the public repo (#143)",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-18T08:10:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "747527a514b910f9c6219bcf0a106f25c36555af",
          "body": "…ng, badges, CI refresh) (#142)\n\n* docs: open-source contributor set — CONTRIBUTING, SECURITY, self-hosting, badges, CI refresh\n\n- CONTRIBUTING.md: how to contribute — setup, branch/PR flow, code style,\n  testing, commit conventions.\n- SECURITY.md: private vulnerability disclosure (GitHub advisories\n[…]\ns\n  now flow through GitHub issues.\n\n* chore: remove .plans/ — internal planning notes, not needed in the open-source repo\n\n* chore: remove tracked .vscode/settings.json (empty) and gitignore .vscode/",
          "is_bot": false,
          "headline": "docs: open-source contributor set (CONTRIBUTING, SECURITY, self-hosti…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-17T23:41:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a356984c826598d5412321689c01daf1eeab877d",
          "body": "The platform is now MIT-licensed and public on GitHub (#138). Surface it\nwhere buyers evaluate trust: a proof-bar 'open source · MIT' badge, a Star\non GitHub CTA in the 'Built in the open' section (which finally links real\nsource), a hero mention, a footer Source link, and a dedicated FAQ entry.\nAls\n[…]\n— no longer true. Adds github to SITE_URLS as the single source\nfor the repo URL, and extends landing.spec.ts to lock the new links + schema.\n\nWeb 1.48.0 -> 1.49.0 (versions.ts manifest kept in sync).",
          "is_bot": false,
          "headline": "feat(web): showcase open source on the landing page (#140)",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-17T23:33:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "839e60a901f0653914438b569c53860f25b42493",
          "body": "… (#141)\n\nThe GitHub Actions convex-deploy seed loop was missing seed-role-registry\nand migrate-roles (added for the Role Registry release, and present in the\nold CircleCI loop). After the CircleCI->GitHub migration, a fresh deploy\nwould stop syncing the dynamic role system and every role would reso\n[…]\nd-tier-features, seed-role-registry,\n  migrate-roles, seed-changelog\n\nSo one deploy auto-syncs feature gates, tier overrides, the role registry,\nand the website changelog — no manual admin-panel step.",
          "is_bot": false,
          "headline": "ci(convex): seed role registry + migrate-roles on every GitHub deploy…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-17T23:31:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "44c65883a739bf51e23bac9a88be914a03dad2c3",
          "body": "…n floors raised (#131)\n\nPhase 2 of registry hardening. The registry-native builds are the new\nminimum: minCli 1.18.0, minExtension 1.15.0 (first builds calling the\nreal features/* Convex paths and consuming capability-driven roles).\n\n- delete all 11 legacy root convex/<module>.ts compat shims — no\n\n[…]\n@envpilot/cli 1.18.0 (blocked on new NPM_TOKEN in CircleCI)\n2. Open VSX has envpilot 1.15.0 (publish fixed by #129, unverified)\nSetting a min above a published, installable version is a total lockout.",
          "is_bot": false,
          "headline": "feat(platform): retire legacy client fallback — shims deleted, versio…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-17T23:24:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0c058de9e46e3d1297afa312022396569db43489",
          "body": "Envpilot is open source now, so GitHub Actions minutes are free and the\nwhole pipeline moves back to it.\n\n- ci.yml: restore the real trigger (push:main + pull_request), keeping\n  workflow_dispatch. Quality gate + per-surface builds + main-only\n  deploys (convex, vercel web/admin, cli, extension, hom\n[…]\nI stubs,\n  doc Bearer snippets) so only real credentials fail the gate. Full\n  history was swept clean once at open-sourcing; no real secrets found.\n\nRepo stays private until a separate explicit flip.",
          "is_bot": false,
          "headline": "ci: migrate from CircleCI to GitHub Actions; add gitleaks guard (#139)",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-17T23:16:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9240c45ed88134007c5727be941887aaa8dd440a",
          "body": "Syntax Lab Technology open-sources Envpilot; Rafay is the developer.\n\n- Root LICENSE: proprietary -> MIT\n- apps/cli, apps/vscode-extension LICENSE: proprietary -> MIT\n- apps/web, apps/admin: add MIT LICENSE\n- package.json license: UNLICENSED/SEE-LICENSE -> MIT across root, web,\n  admin, cli, extension; author set to Rafay (Syntax Lab Technology)\n- GitHub Action package already MIT (unchanged)\n\nCopyright (c) 2026 Syntax Lab Technology and Rafay",
          "is_bot": false,
          "headline": "chore: relicense the monorepo under MIT (open source) (#138)",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-17T23:12:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "348c18b3660fbe30b97da77037dc1f8b947f5354",
          "body": "…ead bytes (#137)\n\nPrints sha256 + client_ counts for dist/extension.js, its sourcemap, and\nthe unzipped VSIX bundle, then exits before publish. Temporary — reverted\nonce the real discrepancy is identified.",
          "is_bot": false,
          "headline": "ci(debug): forensic dump in extension package step — stop guessing, r…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-17T22:25:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c0fb7cceb57fda563603c284f773e51da763fe3c",
          "body": "…d it (#136)\n\nTHE actual root cause of every 'client id not in vsix' failure, from the\njob log: the value was provably in dist/extension.js AND the VSIX bundle\nwas checksum-identical to that dist — yet the embed grep failed. The\ngrep ran against $(unzip -p ...) captured into a shell variable; Linux\n\n[…]\nPES unzip|shasum.\n\nThe check now streams unzip -p | grep, exactly like the checksum pipe —\nbyte-exact, no variable. The build was correct all along; only the\nverification was reading a corrupted copy.",
          "is_bot": false,
          "headline": "fix(ci): stream the VSIX bundle into grep — variable capture truncate…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-17T22:13:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "173d46ba51c2eb5e886ba68222558c963d23ff38",
          "body": "The standalone verify step failed 'client id not in vsix' while the\npackage step in the SAME job proved the id was in dist and the VSIX\nbundle was checksum-identical to dist — the two steps were reading\ndifferent env values for the same variable. The check now runs in the\nsame shell that bakes the v\n[…]\name bytes, one truth.\n\nOn failure it prints value lengths and sha8 prefixes (never values) and\nwhich dist files contain the value, so any recurrence names the\nmismatch instead of presenting a mystery.",
          "is_bot": false,
          "headline": "fix(ci): extension embed verification moves into the build shell (#135)",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-17T22:06:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "761888717bc83759f96308add2fce7cb54534c4b",
          "body": "…ist (#134)\n\nThe EXT_PREBUILT env flag traveled through the same vsce-spawned npm\nchain that scrubs env on the CI image — the very bug that produced empty\nclient ids. The hook never saw the flag, rebuilt without env, and wiped\nthe good dist, so the embed verification kept failing.\n\nThe CI step now d\n[…]\nur-back is named explicitly instead of surfacing as a\nmystery embed failure.\n\nVerified locally with env -i (fully scrubbed env): marker survives,\nchecksums match, marker self-cleans, VSIX excludes it.",
          "is_bot": false,
          "headline": "fix(ci): file marker replaces env flag for the extension's prebuilt d…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-17T21:53:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "667fac334323c5e67ef29a55cb210bc490e59287",
          "body": "…son (#133)",
          "is_bot": false,
          "headline": "fix: prettier formatting on extension prepublish script and package.j…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-17T21:38:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3a185d40489947d55d34cbb81285f4baef924f91",
          "body": "…'s nested npm chain (#132)\n\npublish-extension failed its embed verification (client id absent from\nthe VSIX) even though the same project env vars passed the CLI job's\nidentical check. The CLI builds directly in the step shell; the\nextension rebuilt inside vsce's spawned npm chain, where the env di\n[…]\nust-built dist instead of\nrebuilding. Local vsce usage is unchanged (no flag = full chain).\n\nVerified locally: marker env values embed and survive into the VSIX\nthrough the exact new command sequence.",
          "is_bot": false,
          "headline": "fix(ci): build the extension in the step shell — env never risks vsce…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-17T21:33:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "02fb40e62b0f6ae8f2ca4d0b5212c05fea9bdece",
          "body": "…dmin panel (owner locked) (#130)\n\n* feat(rbac): merge-seed + system-role capability unlock (owner stays locked)\n\nPhase 1 of registry hardening. Granting a new feature's capability to a\nsystem role no longer requires a code edit.\n\n- seed-role-registry: system-role capability matrices now MERGE — key\n[…]\n of reading as 'no changes'\n- merge filter checks catalog membership only ('key in' walked the\n  prototype chain and admitted junk keys like toString)\n- capability-matrix intro copy matches the unlock",
          "is_bot": false,
          "headline": "feat(rbac): merge-seed — system-role capabilities editable from the a…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-17T21:25:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d3e4985f8933dae9ffe9fcbd144c902dddd1fe65",
          "body": "…mpt hangs CI (#129)\n\nvsce package warns when no LICENSE file exists and waits on an\ninteractive y/N confirmation; CircleCI has no TTY, so publish-extension\nstalled until the 10-minute no-output timeout. Same proprietary license\ntext the CLI already publishes.",
          "is_bot": false,
          "headline": "fix(extension): ship LICENSE in the VSIX — vsce's missing-license pro…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-17T21:06:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "340b39dc5c7d09d155dc02c82c7f2bff01aaca8d",
          "body": "* feat(rbac): role registry core — capability catalog, profiles, resolver, authz rewire\n\nRoles become data; capabilities stay code. The Feature-Registry pattern\napplied to RBAC:\n\n- convex/lib/capabilities.ts: the ~30-key capability catalog with\n  metadata, plus ORG/PROJECT_ACTION_TO_CAPABILITY compa\n[…]\nty per distinct slug\n  before the fan-out (memo no longer races inside Promise.all)\n- system slugs reserved in createRole (pre-seed shadowing blocked);\n  updateRoleMeta authenticates before validating",
          "is_bot": false,
          "headline": "feat(rbac): Role Registry — roles as data, capabilities as code (#128)",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-17T20:51:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "243f7e2138fc851372b71c8e7d74b8fc4bab1b62",
          "body": "…ounder strip, FAQ + free-tier seed alignment (#125)\n\n* feat(web): problem-first landing hero + free-tier CLI/extension seed alignment\n\n- Hero H1 leads with the pain point (\"Stop pasting .env files into Slack.\");\n  subline states surfaces + free-tier promise\n- Final CTA gets a new closer so the page\n[…]\n testimonial grid\nrenders only when TESTIMONIALS has real, permissioned entries — avatar\ninitials, name linking to the source, role, quote.\n\n* fix(web): trust section contact email -> ceo@envpilot.dev",
          "is_bot": false,
          "headline": "feat(web): landing conversion pass — problem-first hero, proof bar, f…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-17T14:37:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d908d4ff8e63dfbd7451723938d2d2d477881c4f",
          "body": "…, audit; restore 7 broken extension paths (#124)\n\n* feat(convex): unsync-on-close flags, pro gate, cascade resolution, unsync audit\n\n- projects.vscodeAutoUnsyncOnClose + projectMembers override (absent = secure default ON)\n- feature registry: vscode_unsync_customization (free false / pro true)\n- pr\n[…]\ntup sync pipeline starts only in trusted windows; granting trust\n  (onDidGrantWorkspaceTrust) starts it immediately without a reload\n\n* docs(changelog): v1.46.0 — VS Code unsync-on-close release entry",
          "is_bot": false,
          "headline": "feat: VS Code unsync-on-close — hash-guarded purge, pro-gated toggles…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-17T12:36:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c8527bccd6b75f94ad3bcff216b49264d750602c",
          "body": "…omplete (#123)\n\nAdd searchInProject query that walks a project's entire active variable set\n(bounded) and matches key/description substring + tag names in memory, reusing\nlistWithAccessPaginated's exact access model (resolveProjectAccessContext +\nmapVariableRow) so a hit never surfaces a variable t\n[…]\n the paginated list unchanged.\n\nRemove the dead, access-leaking `search` query (org-wide, no access filtering,\ntake-cap dropped newest rows) and its unused useVariableSearch hook.\n\nBump web to 1.45.0.",
          "is_bot": false,
          "headline": "feat(web): per-project variable search — server-side, access-aware, c…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-16T20:58:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "312587d1d8113f80b99c454ca877e4c300e63fee",
          "body": "…ge (#122)\n\n* feat(web): move Variable Requests to its own project page\n\nReplace the inline Variable Requests card at the bottom of the project\nvariables page with a dedicated /dashboard/projects/[slug]/requests\npage, reachable from a new sidebar item with a pending-count badge.\n\n- New convex query \n[…]\nsidebar badge.\n- NavItem/NavLink gain an optional badge pill, shown only when > 0.\n- apps/web bumped to 1.43.0 (feature); versions.ts APP_VERSIONS.web matches.\n\n* chore: web 1.44.0 (stacked on 1.43.0)",
          "is_bot": false,
          "headline": "feat(web): Variable Requests get their own project page + sidebar bad…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-16T20:57:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8586a745e091806f3304c40c409195ea4b773011",
          "body": "…ycle + request notifications (#121)\n\nSharing:\n- Convert every user-facing throw in sharing mutations/share action to\n  ConvexError so messages survive prod redaction; classify share routes via\n  sanitizeConvexError instead of error.message (expired/burned/revoked/\n  locked-out/invalid-OTP now map t\n[…]\nster on approve/reject\n  (scheduled, best-effort, dev-safe when RESEND is absent).\n\nweb 1.42.1 -> 1.43.0 (+ versions.ts), root +patch. Extend share e2e with a\ndelete-cascade -> reveal-fails assertion.",
          "is_bot": false,
          "headline": "fix(sharing,requests): ConvexError-based error handling + share lifec…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-16T20:56:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dfde4fe2942601b0265d2174610fbb0be1b032f8",
          "body": "…omain rules) (#120)\n\nCLAUDE.md rebuilt: removes the obsolete command-code subagent section and\nall GitHub-Actions-era CI prose; adds CircleCI pipeline v2 (dynamic\nconfig, quality-first, main-only deploys, force params, validate-before-\npush rule), per-environment variable-key uniqueness as a critic\n[…]\nligned (new apps, CircleCI, Vercel git-integration\nOFF); FEATURES gains the per-env uniqueness rule; ROADMAP + SECURITY-TODO\nget dated status headers; e2e README clarifies Playwright never runs in CI.",
          "is_bot": false,
          "headline": "docs: align every doc with current reality (pipeline v2, multi-app, d…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-16T18:30:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c2ab3d10788987db1d134e9edd8506cf293eac2c",
          "body": "… gated deploys (#119)\n\nSetup phase (config.yml): a ~15s detect job diffs the push (main: the\nmerge; branches: vs merge-base with main), maps paths to surfaces\n(convex/web/blog/docs/admin/cli/extension/action; packages/ui fans out\nto the three Next sites; root manifests/.circleci fan out to all), OR\n[…]\nd). Deploys can never\nrun from a branch. Manual control via pipeline parameters\n(force-<surface>, run-everything) from the UI or API.\n\nValidated offline: setup config + 6 generated-workflow scenarios.",
          "is_bot": false,
          "headline": "ci: pipeline v2 — dynamic per-surface workflows, quality-first, fully…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-16T17:57:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cc99647e2d6ef480158b2249d7b8d6d3a7730869",
          "body": "…eness (#118)\n\nA same-key variable (re)created while the original sat in the trash made\nrestore resurrect a clashing copy — two active variables in the same\nenvironment, nondeterministic pulls. Restore now runs the same\nfindEnvironmentConflicts check as create/update and rejects with the\nclashing en\n[…]\npecific\nduplicate message into 'already exists in this project' — that wording\nis now wrong (same key IS allowed in a different environment) and hid\nwhich environment clashed. Web 1.42.1, root 1.34.2.",
          "is_bot": false,
          "headline": "fix(variables): restore from trash re-validates per-environment uniqu…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-16T16:01:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "facf21ad908ff325f6e655cf25970f5788b836f6",
          "body": "…ty + vault orphan fix (#117)\n\n* fix(variables): surface real errors in prod + stop vault orphans on duplicate import\n\nBulk-importing env vars in production showed 'Server Error' per row and\nleaked an orphaned WorkOS Vault secret for every duplicate key.\n\nRoot causes:\n1. The duplicate-key rejection \n[…]\nlit + CircleCI); web 1.42.0, root 1.34.1\n\n* ci(circleci): version-tracker comment failures warn-and-skip (advisory job)\n\n* ci(circleci): drop version-tracker job (low value, kept causing PAT friction)",
          "is_bot": false,
          "headline": "feat(variables): per-environment key uniqueness + prod error visibili…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-16T15:47:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9eeb1fa94e1f1d3ff6cf637c3269000f0747d8ed",
          "body": "…s.envpilot.dev) with shared @envpilot/ui (#116)\n\n* feat: static MDX blog — disk-based, Zod-validated, search + tag filtering\n\nBlog posts are stored as MDX files in apps/web/content/blog/, parsed with\ngray-matter and validated at build time via a Zod frontmatter schema.\nThe listing page at /blog fea\n[…]\nSX tokens — first merge no longer fails on the not-yet-minted\nOPEN_VSX_TOKEN.\n\n---------\n\nCo-authored-by: CommandCodeBot <noreply@commandcode.ai>\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: split blog + docs into standalone apps (blog.envpilot.dev / doc…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-16T15:23:24Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b54d303deecc5337b94d950e256410b9a5846770",
          "body": "…y jobs (#115)\n\nFree-tier Actions minutes nearly exhausted 12 days into the cycle. Per-PR cost was ~13 jobs, each billed as a rounded-up minute with its own checkout+install (~15 billed min/push). Changes: (1) 8 check jobs (format + 6 per-package + convex) merged into one consolidated job — setup pa\n[…]\n cold, ~2-3 warm. Deploy pipeline, e2e gate wiring, and the 'All checks passed' required-check name untouched. No branch protection references the removed job names (verified — branch is unprotected).",
          "is_bot": false,
          "headline": "perf(ci): minutes diet — consolidate checks, cache turbo, gate PR-onl…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-12T01:06:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b9e030d80ca9f719405266a5ee43c0f4aacc4040",
          "body": "… on deploy (#114)\n\n12 new changelog entries covering everything shipped since v1.27.0: vault GC/trash, auth overhaul (device flow, server-verified identity, backend vault crypto), version enforcement, Homebrew, Pro plans go-live, GitHub Action + service tokens, public REST API + MCP server, securit\n[…]\nage revamp, billing UX, launch + welcome email. seed-changelog added to the deploy-convex seed loop so the website changelog updates automatically on every deploy (idempotent upsert by version+title).",
          "is_bot": false,
          "headline": "feat: changelog refresh — July release wave (v1.28–v1.40) + auto-seed…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-12T01:03:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "053738d2aeb867d38957a1ca0ddfbb163f634f9b",
          "body": "* feat: sync users to Loops.so marketing audience (web v1.41.0)\n\nNew signups are upserted as Loops contacts (email, first/last name, userId, source app-signup) via a scheduled internal action on the users.upsert insert branch — same seam as the welcome email, fires once per user. backfillContactsToL\n[…]\nrcel.json). Caveat documented in ci.yml: git auto-deploy loses the strict backend-first ordering (web can go live before deploy-convex finishes).\n\n* revert: drop web version bump — backend-only change",
          "is_bot": false,
          "headline": "feat: sync users to Loops.so marketing audience (web v1.41.0) (#113)",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-12T00:32:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7130477dfa3de1e6d5e94a434cbc2a91a674f253",
          "body": "* chore(scripts): add one-off launch email sender (Gmail SMTP)\n\n* feat: welcome email on first signup via Resend (web v1.40.0)\n\nNew users (free tier by default) now receive a personalized welcome email on their first sign-in. sendWelcomeEmail internalAction follows the existing dark-theme template s\n[…]\nexactly once per user regardless of which API route triggers creation. Falls back to 'there' greeting when WorkOS provides no name. DISABLE_EMAILS kill-switch and FROM_EMAIL config respected for free.",
          "is_bot": false,
          "headline": "feat: welcome email on first signup via Resend (web v1.40.0) (#112)",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-11T23:54:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7e70c5d128c96631ff7ba02e4937a56e86c922c3",
          "body": "…links + alpha badge retired (web v1.39.0) (#111)\n\n* feat(web): billing management UX — required cancel feedback, portal links, alpha badge retired (web v1.39.0)\n\n- Cancellation reason now REQUIRED (server zod + UI: Confirm disabled until\n  selected) — feedback lands on the Polar subscription\n  (cus\n[…]\ns 7.2/7.3: portal availability + cancellation-reason disclosure\n- Privacy 3.5: cancellation feedback recorded with the payment processor\n\n* chore(web): bump terms/privacy last-updated to July 12, 2026",
          "is_bot": false,
          "headline": "feat(web): billing management UX — required cancel feedback + portal …",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-11T22:28:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e9cc2d0cd3c52724cffa28d1a2b47c4ab1872bf9",
          "body": "…errors (web v1.38.1) (#110)\n\n* fix(web): friendly duplicate-variable-key feedback, no raw Convex errors (web v1.38.1)\n\n- sanitizeConvexError strips REPEATED 'Uncaught Error:' prefixes — actions\n  re-throwing a mutation's error double-wrap it, and the single strip leaked\n  'Uncaught Error: Variable \n[…]\nrms\n- e2e: duplicate-variable-error.spec.ts drives the real drawer, asserts the\n  friendly message and the absence of raw 'Uncaught Error' text\n\n* chore: merge main (perf wave 1), rebump web to 1.38.2",
          "is_bot": false,
          "headline": "fix(web): friendly duplicate-variable-key feedback, never raw Convex …",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-11T21:09:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ab4517336736abef807b7762aaf30ed44a09d600",
          "body": "* perf: cut Convex function calls and DB I/O (wave 1)\n\nBackend:\n- getOrgTiersBatch: lean tier-name-only sibling of getResolvedFeaturesBatch\n  (~4 docs/org vs ~60); /api/auth/me and the dashboard layout use it\n- tierDefinitions.by_default index: getDefaultTierName point-read instead of\n  whole-table \n[…]\nad of being\nreplaced by the normalized one from the route — normalize it at the\nsource for parity. All current consumers already normalize on read; this\nremoves the trap for the next one that doesn't.",
          "is_bot": false,
          "headline": "perf: cut Convex function calls and DB I/O — wave 1 (web v1.38.1) (#109)",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-11T21:07:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6426bca265f37a6f930b32e687861cdeb3f7a53f",
          "body": "* feat(web): revamp usage page — plan strip, alert zone, grouped quotas, plan-feature grid (web v1.38.0)\n\n* fix(web): responsive wrap on usage plan strip/alert/info bar; singular alert grammar; CLAUDE.md: developer runs full e2e suite",
          "is_bot": false,
          "headline": "feat(web): revamp organization usage page (web v1.38.0) (#108)",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-11T19:59:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "064e95e7d43565cc7c9a037c5f6a21b16572716c",
          "body": "…) (#107)\n\nThe trash UI was a collapsed 'Recently deleted' section buried at the\nbottom of the project page. Now a dedicated page at\n/dashboard/projects/[slug]/trash, linked from the project header next to\nCompare/Members (visible to roles that can delete variables):\n\n- Variables and shared accounts\n[…]\nomponent deleted; trash-restore e2e spec updated to\n  drive the new page + a new empty-trash round-trip spec (safe: each\n  worker owns its fixture project).\n\nRoot bump 1.31.0 -> 1.32.0 (web + convex).",
          "is_bot": false,
          "headline": "feat(web): dedicated project trash page with empty-trash (web v1.37.0…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-11T19:01:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "70855af6b37b090d63e8a0fd29c68449ba1b0961",
          "body": "….36.0, cli v1.17.0, ext v1.13.0) (#106)\n\n* feat: security hold (suspend member access) + removal exit UX (web v1.36.0)\n\nNew pro feature 'security_hold': freeze an org member's access org-wide\nwithout removing them — for compromised-device incidents. Membership,\nrole, project assignments, and grants\n[…]\nevocation-event subscriptions are\n   user-scoped so a suspended user who re-signs-in still receives the\n   unlink+delete events; the suspended message doesn't false-match the\n   session-expired regex.",
          "is_bot": false,
          "headline": "feat: security hold (suspend member access) + removal exit UX (web v1…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-11T18:54:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "435b07eb747e2e709e497756ac4737771e57d3b4",
          "body": "* ci: manual Vercel deploys triggered after Convex (backend-first)\n\nVercel's git integration auto-deployed web + admin on every push to\nmain, racing ahead of the Convex deploy — a frontend calling functions\nthat weren't live yet. Now:\n\n- apps/web/vercel.json + apps/admin/vercel.json disable auto-dep\n[…]\nurpose: provide terse/caveman communication modes, token-saving compression tooling, review/commit helpers, and validation/safety checks (sensitive-file denylist, 500KB limit, Anthropic/CLI fallback).",
          "is_bot": false,
          "headline": "ci: manual Vercel deploys triggered after Convex (backend-first) (#105)",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-11T11:04:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "74f81b7fef8e877b572c5432d258ddfbe81e234d",
          "body": "…104)\n\n* fix(extension): purge synced .env files on uninstall (ext v1.12.0)\n\nSynced .env files (plaintext secrets) survived extension uninstall\nforever — nothing in VS Code purges them, and deactivate() must never\ndelete (runs on every shutdown; caused data loss once).\n\nFix: vscode:uninstall hook + \n[…]\nshared/org machines — VS Code cannot clear SecretStorage during\nuninstall (microsoft/vscode#123817), so sign-out is what removes stored\ncredentials; admins can also revoke device sessions server-side.",
          "is_bot": false,
          "headline": "fix(extension): purge synced .env files on uninstall (ext v1.12.0) (#…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-11T08:56:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "660455e191d81674b52a93c7ac606a8efc4871b7",
          "body": "….35.0) (#103)\n\n* docs(api): quickstart, REST reference, MCP setup, Action guide, security model (Phase D)\n\nFive MDX pages in the existing file-based docs system (content/docs +\nnext-mdx-remote — nothing stored in Convex), registered in the docs index\nwith icons. Documents the /api/v1 endpoints, fil\n[…]\nuces an expiry badge); row locators scoped to the list container so the\ntoast's own <li> (which now contains the key name) can't cause strict-mode\nmatches. Full suite 72 passed / 4 skipped / 0 failed.",
          "is_bot": false,
          "headline": "feat: public REST API + MCP server + API keys platform + docs (web v1…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-11T08:09:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "367989a5dee890360dd4568e06a6cf79210e398b",
          "body": "* ci: GitHub Action check + publish pipeline (deploy-action)\n\nThe action package had no CI linkage: nothing built/tested it on PRs, and\npublishing to the public repo was manual-only. Now:\n\n- changes job gets an `action` path filter (packages/github-action/**);\n  check-action builds/lints/typechecks/\n[…]\ndating the package. Annotated in-workflow: the action is\ntag-pinned (deploy-action publishes + moves the floating v1) with no\n/api/version manifest entry — bumps are manual and each bump IS a\nrelease.",
          "is_bot": false,
          "headline": "ci: GitHub Action check + publish pipeline (#102)",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-11T00:41:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0943fb0f7f6fa738d6caa45491750d2635b1a57e",
          "body": "… (#101)\n\n* feat(cicd): service tokens + GitHub Action secret pulls (web v1.34.0)\n\nEnvpilot's first machine identity: long-lived, READ-ONLY service tokens\nscoped to one project + explicit environment list, consumed by the new\nGitHub Action to pull env vars into CI — one revocable secret in GitHub\nin\n[…]\nropped the tr -d '[:space:]',\nwhich would itself have corrupted secrets containing spaces (command\nsubstitution already strips the trailing newline). Same fix applied to\nscripts/convex-local-setup.sh.",
          "is_bot": false,
          "headline": "feat(cicd): service tokens + GitHub Action secret pulls (web v1.34.0)…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-11T00:28:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4857e19a9c9dbece0fad7d5cdcb0520f54174ac2",
          "body": "…xt v1.11.0) (#100)\n\n* perf(web): stop the app-wide getExtendedUsage subscription (v1.33.3)\n\ngetExtendedUsage reads up to ~2000 variable docs plus full per-project\nscans for shares, rotation variables, and shared accounts. It was\nsubscribed by useTierStoreSync, which the global dashboard nav mounts \n[…]\nplicate subscriptions\" (Convex client dedupes\nidentical query+args).\n\nVerified: check:all green; extension build/lint/typecheck/test 45/45;\nfull e2e suite 44 passed / 3 self-skipped / 0 failed (1.6m).",
          "is_bot": false,
          "headline": "perf: Convex Database I/O reduction + CI e2e gate off (web v1.33.3, e…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-10T22:45:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3c4eeab101d4c60a3f4deecbe615df19c7be5f2d",
          "body": "…33.2) (#99)\n\n* fix(billing): production-harden the Polar gateway (v1.33.2)\n\nPre-live-transaction hardening of the entire payment path, fixing every\ncritical/high finding from the billing audit:\n\nTRUST BOUNDARY (critical)\n- processWebhookEvent now requires a bridgeSecret checked constant-time\n  agai\n[…]\nas a\nduplicate, permanently dropping the payment event. The release now has its\nown try/catch (loud console.error including the webhook id for manual\ncleanup) and the original error always propagates.",
          "is_bot": false,
          "headline": "fix(billing): production-harden the Polar gateway before go-live (v1.…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-10T22:13:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "baac0856df26bab186468cb7b085fa401406a19f",
          "body": "…ast + retrying assertions (#98)\n\n* test(e2e): filter Vercel Analytics 404 + fix ambiguous usage-meter selector\n\nThe prod-build e2e run failed the zero-client-errors specs on a\n/_vercel/insights/script.js 404 — Vercel Web Analytics' script is served\nonly by Vercel's edge in real production, so a loc\n[…]\neave\ndebris with no signal in the report. Each skip is now console.warn'd and\nattached to the setup result as a warning annotation; the sweep still never\nfails the run over them (they retry next run).",
          "is_bot": false,
          "headline": "fix(e2e): unblock suite from tier-cap debris — pre-run purge + fail-f…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-10T20:45:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a0b891817ff0a67fa5439a5c147a7b7ca5890f64",
          "body": "…ld (#97)\n\nRoot cause of the main e2e gate failure (run 29100933255): a Convex query\nfired before the WorkOS JWT was attached to the socket, throwing the\ntransient 'Unauthenticated: no verified user identity'. Strict specs count\nthat console error as a failure. Barely visible locally, it dominated C\n[…]\natches what ships. Local runs unchanged (reuse the dev server).\n- search-projects-org: waitForURL inner timeout 3s -> 5s (it's the\n  click-retry cadence inside a 20s .toPass, not the assertion bound).",
          "is_bot": false,
          "headline": "fix(e2e): eliminate pre-auth Convex query race + run gate on prod bui…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-10T15:44:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "647b9076844727b31d4a7e067d9f9aac7e784097",
          "body": "…(#96)\n\n* feat(ci): e2e deploy gate, strict deploy ordering, Node 22\n\n- New e2e job on main pushes: deploys the new convex functions to an\n  isolated e2e deployment, runs the full Playwright suite (1 worker,\n  2 retries), and BLOCKS every deploy when it fails. Fails loudly when\n  the e2e secrets are\n[…]\nright.config.ts already applies both when CI is set, but the gate's\nserial-run + retry contract now lives at the callsite too, so a config\nrefactor can't silently reintroduce the parallel-load flakes.",
          "is_bot": false,
          "headline": "feat(ci): e2e deploy gate, strict deploy ordering, Node 22 (v1.29.0) …",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-10T14:43:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d1dc1d1f2011431341b00c09b84b3d4f8e37be46",
          "body": "…emoval (v1.28.2) (#95)\n\n* refactor(convex): extract shared helpers into convex/lib with compat barrels\n\n- lib/identity.ts, lib/users.ts, lib/rateLimits.ts, lib/audit.ts,\n  lib/authHelpers.ts, lib/authz.ts, lib/roleCompat.ts\n- registered queries getMyPermissions + resolveLegacyRoles move to\n  featur\n[…]\nonolith, verified against d116ad5), surfaced by Greptile\nreview; break instead falls through to the shared record-processed step.\nFailure paths still skip recording so Polar retries can succeed later.",
          "is_bot": false,
          "headline": "refactor(convex): feature-based backend structure, dedup, dead-code r…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-10T13:33:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3ea40452e3f9154a1ea1ef908931ac576badd406",
          "body": "…(#94)\n\n* fix: resolve Sentry issue backlog across web/cli/extension (v1.33.1, cli 1.15.1, ext 1.9.1)\n\nWeb (@envpilot/web 1.33.1):\n- error-messages: isTierLimitError matched neither actual backend wording\n  ('Limit reached (n/m). Upgrade your tier' / 'requires a higher tier') —\n  expected tier-limit\n[…]\nirect shape gets the session-expired\n  message; other non-JSON responses report their status (P2)\n- console-health spec: replace fixed 3s settles with networkidle + 1s\n  grace (saves ~6s per run) (P2)",
          "is_bot": false,
          "headline": "fix: resolve Sentry issue backlog across web/cli/extension (v1.33.1) …",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-09T21:43:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1f9cf8fe617c17f53f522c0880bea66aa3f1f383",
          "body": "* feat: auth error boundary with dedicated error page\n\n- AuthErrorPage component: terminal-themed full-page error with\n  collapsible details, Try Again / Sign In Again links, and\n  contact support section (syntaxlabtechnology@gmail.com)\n- AuthErrorBoundary: client-side ErrorBoundary that detects\n  a\n[…]\n\n- handleRetry clears any pending auto-retry timer so a manual retry can't race\n  a deferred setState against a freshly-caught error\n\n---------\n\nCo-authored-by: CommandCodeBot <noreply@commandcode.ai>",
          "is_bot": false,
          "headline": "feat: auth error boundary with dedicated error page (v1.33.0) (#93)",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-09T19:42:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2945131a0a74bb45322d23266ab55dd55a2b0cbc",
          "body": "The npm registry strips the scope from tarball filenames for scoped\npackages. @envpilot/cli publishes to .../cli-{version}.tgz, not\n.../envpilot-cli-{version}.tgz. The old URL caused every Homebrew\nformula fetch to 404.\n\nThis fix was on PR #92 but only the retry commit made it in — the\nURL fix commit was orphaned during merge. Cherry-picking now.\n\nCo-authored-by: CommandCodeBot <noreply@commandcode.ai>",
          "is_bot": false,
          "headline": "fix: correct npm tarball URL for scoped packages",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-09T16:39:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5cbebf6527a38c6b395ee72979e66c9cbf1fd5e7",
          "body": "The npm registry can return 404 for up to ~45 seconds after publish\ndue to CDN propagation. The single-shot curl -fsSL was failing with\nexit code 22, causing the entire deploy-homebrew workflow to error out.\n\nNow retries 5 times with exponential backoff (3, 6, 9, 12, 15 s —\n~45 s total) before giving up. Uses a temp file for the download to\navoid piping issues with set -euo pipefail.\n\nCo-authored-by: CommandCodeBot <noreply@commandcode.ai>",
          "is_bot": false,
          "headline": "fix: retry npm tarball fetch on 404 (propagation delay) (#92)",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-09T16:23:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "17cc02d3efc8f18d7484b407c8fa2a35ee5091c8",
          "body": "* feat(cli): Homebrew distribution via existing homebrew-apps tap\n\nAdds a formula generator script and CI workflow that publishes the\nenvpilot CLI formula to the existing rafay99-epic/homebrew-apps tap\nwhenever a new version is published to npm. The monorepo stays private\n— only the npm tarball URL \n[…]\n\nof raw ${{ inputs.version }}, preventing injection from workflow_dispatch.\n\nCo-authored-by: CommandCodeBot <noreply@commandcode.ai>\n\n---------\n\nCo-authored-by: CommandCodeBot <noreply@commandcode.ai>",
          "is_bot": false,
          "headline": "feat(cli): Homebrew distribution via existing homebrew-apps tap (#91)",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-09T16:09:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cb1eb8088912297a2cc50c4613afb63cb0741dd5",
          "body": "…is the single backend) (#86)\n\n# Stage 3 — WorkOS Vault crypto moved into Convex\n\nConvex becomes the **single backend**. Plaintext secret values now travel to Convex, which encrypts them into WorkOS Vault and stores only the opaque `vaultRef`. The web app no longer holds vault crypto — `apps/web/src\n[…]\nxes + `vaultReveal` functions.\n\n---\n_Merged `main` (through #90) — CLI/extension auth + version-enforcement fixes — and resolved version conflicts. cubic review issues addressed in follow-up commits._",
          "is_bot": false,
          "headline": "feat(vault): Stage 3 — WorkOS Vault crypto moved into Convex (Convex …",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-06T07:59:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7a6ed461a62d48b01717f186397e7d8965a21323",
          "body": "…#90)\n\n* fix(ci): build CLI/extension directly (not turbo) + guard the embed\n\nThe published 1.13.0 CLI / 1.8.0 extension STILL shipped an empty WorkOS client\nid despite the secret resolving on the build step. Root cause: `bunx turbo\nbuild` did not propagate WORKOS_CLIENT_ID / NEXT_PUBLIC_CONVEX_URL \n[…]\nterministic: derive the exact filename\nfrom package.json version instead of `ls | head` (alias-fragile and could grab a\nstale VSIX). Verified locally: both checks pass against the packaged 1.8.1 VSIX.",
          "is_bot": false,
          "headline": "fix(ci): build CLI/extension directly (not turbo) + guard the embed (…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-06T01:57:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a5ae155a233496e4fc5e03b19f7494cb1ddaf07a",
          "body": "…ock) (#89)\n\n* feat(versioning): two-tier client version enforcement (warn + hard-block)\n\nForce CLI/extension users onto supported versions so stale clients can't call\nserver/Convex contracts that were removed (e.g. the Stage 2 auth cutover).\n\nServer (source of truth: apps/web/src/lib/versions.ts):\n\n[…]\nent always runs against the\nlast-known cached min/latest.\n\ncubic P2 (repeated 3s CLI hangs on network failure) was already addressed in\n176ebb2 — lastVersionCheck is written up front before the fetch.",
          "is_bot": false,
          "headline": "feat(versioning): two-tier client version enforcement (warn + hard-bl…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-06T01:17:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "07d968bed91b34f360510a8004a6a48bac862a12",
          "body": "…on (#88)\n\n* fix(ci): embed WORKOS_CLIENT_ID + Convex URL in published CLI/extension builds\n\nThe device-flow auth (Stage 2) reads a build-time-baked WorkOS client id and\nConvex URL: tsup/esbuild `define` replace `__WORKOS_CLIENT_ID__` / `__CONVEX_URL__`\nfrom `process.env.WORKOS_CLIENT_ID` / `NEXT_PU\n[…]\nPUBLIC_CONVEX_URL), referenced via ${{ secrets.* }}.\nKeeps them out of the committed YAML and masked in CI logs. They remain\nembedded in the published CLI/extension artifacts at runtime (unavoidable).",
          "is_bot": false,
          "headline": "fix(ci): embed WorkOS client id + Convex URL in published CLI/extensi…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-06T00:49:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5d6c044d8c3b8e45b76af6e89642c998fe4810c5",
          "body": "…eak dev login) (#87)\n\nThe prod emergency fix hardcoded the PROD WorkOS client id in auth.config.ts.\nThat file deploys to BOTH Convex deployments, so the dev/staging deployment\nstarted trusting the PROD client — every dev CLI/extension/web JWT (issued for\nthe STAGING client) then failed with 'No aut\n[…]\nthis reaches prod: the prod Convex deployment MUST have\nWORKOS_CLIENT_ID set (the Convex CLI rejects a push referencing an unset env\nvar). It should be client_01KHWDD75944NBADKY0ANTRXR8 (the prod id).",
          "is_bot": false,
          "headline": "fix(auth): auth.config resolves WORKOS_CLIENT_ID per-deployment (unbr…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-05T23:57:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "58a6582ae83e690a7a0d9580a5eb967d3f5bf433",
          "body": null,
          "is_bot": false,
          "headline": "auth:fix",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-05T22:58:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "964e95fd683a608bf1305f675ea936eeec684bd9",
          "body": "…vex WebSocket (#85)\n\n## What\n\nCompletes Stage 2 by migrating the **VS Code extension** off the homegrown/deleted token auth onto the WorkOS AuthKit device flow — the mirror of the CLI cutover (#84). This closes the breakage that #84 introduced: the extension was calling backend routes/functions tha\n[…]\nubic.dev/buttons/review-in-cubic-light.svg\"><img alt=\"Review in cubic\" src=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"></picture></a>\n\n<!-- End of auto-generated description by cubic. -->",
          "is_bot": false,
          "headline": "feat(extension): Stage 2 — WorkOS device-flow auth, authenticated Con…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-05T21:30:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a7acf6edd96380fd3e9322366193f92cbe1df62b",
          "body": "…ken bridge removed (#84)\n\n* feat(auth): Stage 2 — WorkOS device-flow auth for CLI, ForToken bridge removed\n\nBackend:\n- cliSessions + pendingExtensionAuthSessions deleted (tables + module);\n  cliTokens repurposed as a display/revoke device-session record\n  (optional tokens, sessionId + clientType ad\n[…]\n from identity resolution\n- deviceSessions.revoke queries the by_user_active index instead of loading\n  all rows and filtering in memory\n\nVerified live: revoke lifecycle + vault happy path both green.",
          "is_bot": false,
          "headline": "feat(cli): Stage 2 — WorkOS device-flow auth, direct-to-Convex, ForTo…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-05T19:34:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ce89d94bddc02089b4652614548126b5cc236e69",
          "body": "… (Stage 1) (#83)\n\n## What\n\nCloses the platform's biggest security hole: **every Convex function trusted a client-supplied `userId` arg**, so anyone who reached the public Convex deployment could impersonate any user. After this PR, every function derives its actor from a **verified identity** — a W\n[…]\nubic.dev/buttons/review-in-cubic-light.svg\"><img alt=\"Review in cubic\" src=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"></picture></a>\n\n<!-- End of auto-generated description by cubic. -->",
          "is_bot": false,
          "headline": "feat(auth): Convex auth cutover — server-verified identity everywhere…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-05T13:02:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9b48c886d74b44e91593571af65521ae1dc2aa8c",
          "body": "The cleanup-dead-data runMigration handler shipped in #81 but had no\nentry in listMigrations, so it never rendered as a card in the admin\nmigrations page — runnable via API only, invisible in the UI. Added its\ncatalog entry under One-Time Migrations so it can be run from the panel.",
          "is_bot": false,
          "headline": "fix(admin): surface cleanup-dead-data in the migrations panel (#82)",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-05T03:05:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aae6fb39aa6211fc51233371b6abcc150f6ebe80",
          "body": "* perf: Convex usage optimization + dead-code purge (-3,400 lines)\n\nThree-agent audit (hot path, crons/gating, long tail + dead code) →\nranked fixes, every diff reviewed, zero behavior change for live flows.\n\nRead-cost fixes:\n- globalSearchWithAccess: capped per-project reads (was unbounded full-doc\n[…]\nlus shared-fixture pollution (leftover E2E\naccounts hitting the free 5-account limit, which correctly disables Add\nAccount — enforcement working as intended), not product regressions.\n\n* fixing format",
          "is_bot": false,
          "headline": "perf: Convex usage optimization + dead-code purge (−3,500 lines) (#81)",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-05T02:54:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7df9b31b10bd08f711fd3868a0bc739ea8ee223a",
          "body": "…urge) (#80)\n\n* feat: vault GC — deletion becomes real (7-day trash, then permanent purge)\n\nBefore this, nothing ever deleted a WorkOS Vault object: 'deleted'\nsecrets lived in the vault forever, and deletion was an indefinite\nsoft-hide with no user-facing restore either.\n\nNew model (user-confirmed):\n[…]\nbut that would range-scan every\ntenant's deleted rows and filter projectId in memory — the compound\nindex is strictly better.)\n\nVerified live: trash-restore e2e round-trips pass through the new\nindex.",
          "is_bot": false,
          "headline": "feat: vault GC — deletion becomes real (7-day trash, then permanent p…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-04T14:54:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5b8673b47a82bbc785ecb73e7078485784d2648b",
          "body": "Users previously got zero feedback when an action failed — no toast\nsystem existed at all (the one toast component was dead code). Now:\n\n- sonner Toaster mounted globally (dark theme, bottom-right)\n- The Convex client error bridge toasts every mutation/action failure:\n  expected tier-limit/permissio\n[…]\nueRestored.\n- In-app changelog entry (v1.27.0) publishing the statement about the\n  legacy version limitation and the new rollback guarantees.\n\nVersions: web 1.27.0, root 1.21.0 (minor — new feature).",
          "is_bot": false,
          "headline": "feat(web): error toast notifications + honest rollback disclosure (#79)",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-04T13:52:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f1f103dfe32db7e69bfb756d5771917505e1fefe",
          "body": "…(#78)\n\n* fix(hardening): real vault version rollback + twin parity fixes for variables/accounts\n\nVault versioning (the headline fix): web PATCH value updates now mint a\nNEW vault object per change (the pattern the CLI bulk-push already used)\ninstead of overwriting in place. Every variableVersions r\n[…]\nects\n  (authorization/validation) after a new vault object was minted for the\n  value, best-effort deleteSecret the orphan before rethrowing — same\n  compensation pattern as the accounts create route.",
          "is_bot": false,
          "headline": "fix: real vault version rollback + variables/accounts twin hardening …",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-04T13:27:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bd1f92663f140f9e86d4bbc44ff93875da22b989",
          "body": "* feat(observability): complete Sentry coverage across web API, Convex client, CLI, and extension\n\nWeb API routes: add reportApiError() (report-only, skips expected tier/authz\nerrors) and insert it into ~60 previously-silent catch blocks across 55 route\nfiles (vault, billing, cli/*, extension/*, and\n[…]\ny disabled. Verified by\nrebuilding both packages through 'turbo build' and grepping the dist\noutput for the baked-in DSN (missing before, present after).\nENVPILOT_SERVER_URL added for the same reason.",
          "is_bot": false,
          "headline": "feat(observability): complete Sentry coverage across all surfaces (#77)",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-04T12:41:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7b97023dfc8b5b162847a9189f8891669f64651b",
          "body": "* feat(usage): shared accounts in the usage dashboard meters\n\n- getExtendedUsage now returns sharedAccounts (countActiveAccounts, fetched in\n  parallel with the other org counts)\n- usage page: shared_accounts / shared_accounts_limit added to the Security\n  feature catalog, free/pro value maps (free \n[…]\ncost — the index already narrows rows)\n\nCLI/extension usage routes intentionally unchanged — shared accounts are\nweb-only.\n\n* chore(release): web 1.25.0, root 1.19.0 — usage meters for shared accounts",
          "is_bot": false,
          "headline": "feat(usage): Shared Accounts in the usage dashboard meters (#76)",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-03T17:59:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2162334d34fca9407fe7803c75357b3ed021f1d4",
          "body": "…under projects (#75)\n\n* feat(web): shared account credentials under projects — vault-encrypted storage, RBAC parity, internal & external sharing\n\n- New projectAccounts + accountPermissions tables; username & password stored\n  encrypted in WorkOS Vault (JSON payload), Convex holds only vault refs\n- \n[…]\npassword when the block is hidden so a prior\n  unmask doesn't persist into the next reveal\n- drop unused required organizationId from createAccountSchema (org is resolved\n  server-side from projectId)",
          "is_bot": false,
          "headline": "feat: Shared Accounts — vault-encrypted credential storage & sharing …",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-03T17:01:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5ae00dbe6ec03402c0ca6005ceb92a5602fe278f",
          "body": "Introduce a shared GitHub Actions setup composite (.github/actions/setup/action.yml) and a new orchestrated CI pipeline (.github/workflows/ci.yml) that detects changed scopes, runs scoped quality checks, builds artifacts, and calls reusable deploy workflows. Add reusable deploy workflows for Convex,\n[…]\nubic.dev/buttons/review-in-cubic-light.svg\"><img alt=\"Review in cubic\" src=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"></picture></a>\n\n<!-- End of auto-generated description by cubic. -->",
          "is_bot": false,
          "headline": "Add reusable CI workflows and setup action (#74)",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-03T08:03:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f3b6c98394ccfd6d4dd697c3a53b9006112a5342",
          "body": "* feat(vscode): unified RBAC + brutal-review fixes + optimization\n\nUnify the VS Code extension with the web/CLI role model and fix a batch of\nreal bugs found in a full audit. Server changes are additive so old installed\nextensions keep working.\n\nServer (/api/extension/*): add unifiedRole, assigned, \n[…]\n before responding\n  (the CLI route already did), maps duplicate-pending to 409 instead of a\n  raw 500, and maps authorization/scope rejections to 403 via the shared\n  isAuthorizationError classifier.",
          "is_bot": false,
          "headline": "VS Code extension: unified RBAC, brutal-review fixes, optimization (#73)",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-03T01:39:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fc9e4af79e7f543badd527428d8003a4156e9bdb",
          "body": "## Summary\nBrings the CLI onto the unified role model, rewrites `envpilot run`, and fixes a batch of real bugs found in a three-part audit (RBAC, general quality, `run` deep-dive). **Server changes are additive**, so already-installed CLIs keep working.\n\n## Server (`/api/cli/*`, additive)\nAdds `unif\n[…]\nubic.dev/buttons/review-in-cubic-light.svg\"><img alt=\"Review in cubic\" src=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"></picture></a>\n\n<!-- End of auto-generated description by cubic. -->",
          "is_bot": false,
          "headline": "CLI: unified RBAC, envpilot run rewrite, and bug fixes (#71)",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-02T20:00:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4354f3686cf1eb90d9da8f1b50b0b9b2bdbcea29",
          "body": "…#72)\n\nRedesigns the shared email helpers in `convex/emails.ts` so every transactional email matches Envpilot's dark terminal brand identity — signature green accent, terminal-window chrome, and the `$ envpilot` prompt wordmark (mirroring `apps/web` `globals.css` + the landing-page `TerminalFrame`).\n[…]\nubic.dev/buttons/review-in-cubic-light.svg\"><img alt=\"Review in cubic\" src=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"></picture></a>\n\n<!-- End of auto-generated description by cubic. -->",
          "is_bot": false,
          "headline": "feat(emails): rebrand transactional emails with dark terminal theme (…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-02T19:53:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e0818f7f50001a1c3dc25da37309dee0e5dd47c1",
          "body": "…ex cost fixes (#70)\n\n* feat(rbac): unified organization-wide role system\n\nReplace the three overlapping role layers (org roles, project roles,\nvariable permission levels) with ONE role per user:\n\n  owner > project_manager > team_lead > developer\n\n- projectMembers is now a pure scope assignment (no \n[…]\ne selector, and validation are unchanged — only the container swapped.\nUtility dialogs (confirm, export, keyboard help, variable history) keep their\ncentered-modal pattern, which is correct for those.",
          "is_bot": false,
          "headline": "Unified organization-wide RBAC: env scoping, security hardening, Conv…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-02T10:24:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e7a83c3aae38721ca1c13e8f530fb68af4f7cfeb",
          "body": "…dening (#69)\n\nPerformance:\n- Split @sentry/node into a lazily-loaded chunk (activation bundle 2.8MB -> ~1MB)\n- Stop blocking activation on Convex config HTTP call and commit guard git spawns\n- Remove workspaceContains:.env* activation event (onStartupFinished already covers it)\n- Drop redundant val\n[…]\n auth session token) only copied to clipboard when the\n  browser fails to open\n- refreshToken only signs out on 4xx, not on transient network errors\n\nVersions: extension 1.4.1, web 1.14.1, root 1.12.1",
          "is_bot": false,
          "headline": "perf(extension): faster activation and variable loading, security har…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-07-01T20:07:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b6bf5ac016c6602244c124aec21bb35fc31d3319",
          "body": null,
          "is_bot": false,
          "headline": "Update Scarlet Speedster automated PR review workflow",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-06-23T15:42:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e4b38d7087b1491b48f7bded7a4e5db3adb977f6",
          "body": "…s (#67)\n\n* feat(web): marketing redesign with SEO, a11y, performance, and uptime status\n\nMarketing surface overhaul (v1.14.0):\n\nFixes\n- Add /api/auth/me, /docs, /faq, /feed.xml, /llms.txt, /llms-full.txt to\n  middleware unauthenticatedPaths — public pages no longer redirect to\n  sign-in, and client\n[…]\nms prerender\n\nThe deleted root loading.tsx had been providing an implicit Suspense\nboundary; without it, static prerendering of /cli/auth fails the build.\n/extension/auth already had its own boundary.",
          "is_bot": false,
          "headline": "Marketing redesign: SEO fixes, comparison pages, guides, uptime statu…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-06-12T08:33:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "803c0be2f43c439ce147fe0dffacb42766b026cd",
          "body": "The CLI deploy failed with \"missing authentication (run 'bunx npm\nlogin')\" because `bun publish` does not reliably read the ~/.npmrc the\nworkflow wrote. Pass the token through the NPM_CONFIG_TOKEN env var\ninstead, which is bun's supported CI auth path.\n\nBump CLI to 1.7.2 so the deploy-detection (which gates on apps/cli\nchanges + version delta) re-triggers the publish; 1.7.1 was never\npublished and no tag was created since the publish step failed first.",
          "is_bot": false,
          "headline": "fix(ci): authenticate bun publish via NPM_CONFIG_TOKEN (#66)",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-06-08T09:28:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b84f7ba3cb888d2d9eda6d3958ff7d392011ac82",
          "body": "The \"press any key to return\" prompt read raw process.stdin\n(setRawMode + resume + once) after the Ink picker unmounted and a\ncommand ran in a child process with inherited stdio. In that state raw\nmode failed to re-engage and the event loop emptied, surfacing a\n\"Detected unsettled top-level await\" c\n[…]\n(PressAnyKey) so the\nstdin lifecycle stays consistent across renders, and wrap the entry in\nan async main() so an empty event loop can no longer surface the\ntop-level-await warning. Bump CLI to 1.7.1.",
          "is_bot": false,
          "headline": "fix(cli): stop TUI crashing after each command run (#65)",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-06-08T09:09:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0f051b6868ddb7371a29db865225c1d600389c0c",
          "body": "* Add DashboardShell and Convex boundary provider\n\nMove dashboard UI into a new client component (DashboardShell) and simplify the dashboard layout to render that shell. Export a ConvexBoundaryProvider from ConvexClientProvider and use it inside the new shell so client-only pieces (nav, command pale\n[…]\ns sending to Sentry.\n\n* Bump web app version to 1.6.1\n\nUpdate APP_VERSIONS.web from 1.6.0 to 1.6.1 to reflect a new web release. This increments the published web surface version for release tracking.",
          "is_bot": false,
          "headline": "(fix)/sentry fix (#63)",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-04-22T22:31:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "20f45e43eb2b938f00ac940094c861eed9b6b27a",
          "body": "…erts (#62)\n\n* Add anomaly detection system across platform\n\n- Admin dashboard for managing anomaly events, rules, and running test suite\n- Backend detection engine with configurable rules and severity levels\n- Web dashboard pages for anomaly monitoring and rule management\n- Feature registry entries\n[…]\nding; whitelist workoscdn.com in\n  remotePatterns\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add comprehensive anomaly detection system with admin controls and al…",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-04-21T15:21:24Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c7a4a41a9fdee6ddd8565df89b0062449d952f7c",
          "body": null,
          "is_bot": false,
          "headline": "Read me",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-04-17T20:58:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f6b070faea83310161e0f10db79fec322dfbdbe1",
          "body": "- Move FEATURES, ROADMAP, SECURITY-TODO to docs/\n- Update README.md links\n- Remove cleanup.sh",
          "is_bot": false,
          "headline": "Move documentation to docs/ directory",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-04-17T20:55:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4874442130a4a2ec0431849d1d3151dbf09362aa",
          "body": null,
          "is_bot": false,
          "headline": "fixing format",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-04-17T20:50:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fe7cedcfcc796f0f33b1397c3c856c5b998c4dd7",
          "body": "- Merge ci.yml, build-extension.yml, deploy-convex.yml, deploy-extension.yml, and release-cli.yml into single ci-deploy.yml\n- Implement 5-stage pipeline: quality gate → build → detect changes → deploy → release\n- Add automatic version detection and deployment triggers for convex, extension, and CLI\n- Disable old workflow files (.disabled suffix) for reference\n- Remove legacy deployment scripts and .vscode config files\n- Update CLAUDE.md documentation with new development and deployment workflows",
          "is_bot": false,
          "headline": "Consolidate CI/CD workflows into unified pipeline (#61)",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-04-17T20:46:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "169e1ac64bc02fabfb2345c9520e443a7b1b0d09",
          "body": "- Implement safe redirect following that preserves Authorization header for same-site (registrable domain) redirects while stripping for cross-site ones\n- Add normalizeApiUrl() to canonicalize envpilot.dev → www.envpilot.dev in config and commands\n- Validate tokens exist when poll() returns authenti\n[…]\nssion code collision detection to reject all existing codes, not just pending ones\n- Consolidate /api/cli/auth/* endpoints to single route with action query parameter\n- Add interactive CLI test script",
          "is_bot": false,
          "headline": "Fix CLI auth header stripping on apex→www redirects (#60)",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-04-17T18:44:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0c3bdc0141bbbdac1f047ec251e8a8b9f3642b4a",
          "body": null,
          "is_bot": false,
          "headline": "org fix",
          "author_name": "Abdul Rafay",
          "author_login": "rafay99-epic",
          "committed_at": "2026-04-16T22:52:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 79,
      "commits_last_year": 155,
      "latest_release_at": "2026-07-20T09:17:24Z",
      "latest_release_tag": "v1.43.0+311a623",
      "releases_from_tags": false,
      "days_since_last_push": 5,
      "active_weeks_last_year": 13,
      "days_since_latest_release": 5,
      "mean_days_between_releases": 0.2
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 71,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "@envpilot/cli",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "env",
            "environment",
            "variables",
            "cli",
            "dotenv",
            "secrets"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@envpilot/cli",
          "is_deprecated": false,
          "latest_version": "1.19.0",
          "repository_url": "https://github.com/rafay99-epic/envpilot.dev",
          "versions_count": 29,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 2472,
          "first_published_at": "2026-03-10T13:09:08.771000Z",
          "latest_published_at": "2026-07-19T23:20:03.285000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        },
        {
          "name": "envpilot",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": null,
          "registry_url": "https://www.npmjs.com/package/envpilot",
          "is_deprecated": false,
          "latest_version": "1.0.4",
          "repository_url": null,
          "versions_count": 5,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 35,
          "first_published_at": "2015-11-06T19:16:52.064000Z",
          "latest_published_at": "2016-02-07T02:28:22.798000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 3821
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0,
        "collected_at": null
      },
      "open_issues_and_prs": 2
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": true,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "apps/admin/tsconfig.json",
        "apps/blog/tsconfig.json",
        "apps/cli/tsconfig.json",
        "apps/docs/tsconfig.json",
        "apps/vscode-extension/tsconfig.json",
        "apps/web/tsconfig.json",
        "convex/tsconfig.json",
        "packages/github-action/tsconfig.json",
        "packages/ui/tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 76271,
      "source_files_sampled": 697,
      "oversized_source_files": 5,
      "agent_instruction_files": [
        ".agents/skills/vercel-react-best-practices/AGENTS.md",
        "AGENTS.md",
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 105774
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 186,
        "malicious_count": 0,
        "assessed_package": "npm:@envpilot/cli@1.19.0",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "@convex-dev/rate-limiter",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.3.2"
        },
        {
          "name": "@convex-dev/workflow",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.3.5"
        },
        {
          "name": "@convex-dev/workpool",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.4.1"
        },
        {
          "name": "resend",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^6.9.3"
        },
        {
          "name": "@dnd-kit/core",
          "manifest": "apps/admin/package.json",
          "ecosystem": "npm",
          "version_constraint": "^6.3.1"
        },
        {
          "name": "@dnd-kit/utilities",
          "manifest": "apps/admin/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.2.2"
        },
        {
          "name": "@fontsource-variable/geist",
          "manifest": "apps/admin/package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.2.8"
        },
        {
          "name": "@fontsource-variable/geist-mono",
          "manifest": "apps/admin/package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.2.8"
        },
        {
          "name": "@tanstack/react-router",
          "manifest": "apps/admin/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.120.3"
        },
        {
          "name": "@workos-inc/authkit-react",
          "manifest": "apps/admin/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.16.1"
        },
        {
          "name": "class-variance-authority",
          "manifest": "apps/admin/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.7.1"
        },
        {
          "name": "clsx",
          "manifest": "apps/admin/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.1.1"
        },
        {
          "name": "convex",
          "manifest": "apps/admin/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.32.0"
        },
        {
          "name": "date-fns",
          "manifest": "apps/admin/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.1.0"
        },
        {
          "name": "lucide-react",
          "manifest": "apps/admin/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.577.0"
        },
        {
          "name": "react",
          "manifest": "apps/admin/package.json",
          "ecosystem": "npm",
          "version_constraint": "^19.1.0"
        },
        {
          "name": "react-dom",
          "manifest": "apps/admin/package.json",
          "ecosystem": "npm",
          "version_constraint": "^19.1.0"
        },
        {
          "name": "react-markdown",
          "manifest": "apps/admin/package.json",
          "ecosystem": "npm",
          "version_constraint": "^10.1.0"
        },
        {
          "name": "remark-gfm",
          "manifest": "apps/admin/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.0.1"
        },
        {
          "name": "tailwind-merge",
          "manifest": "apps/admin/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.0.2"
        },
        {
          "name": "zustand",
          "manifest": "apps/admin/package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.0.5"
        },
        {
          "name": "@envpilot/ui",
          "manifest": "apps/blog/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "date-fns",
          "manifest": "apps/blog/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.1.0"
        },
        {
          "name": "gray-matter",
          "manifest": "apps/blog/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.0.3"
        },
        {
          "name": "lucide-react",
          "manifest": "apps/blog/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.577.0"
        },
        {
          "name": "next",
          "manifest": "apps/blog/package.json",
          "ecosystem": "npm",
          "version_constraint": "^16.2.10"
        },
        {
          "name": "next-mdx-remote",
          "manifest": "apps/blog/package.json",
          "ecosystem": "npm",
          "version_constraint": "^6.0.0"
        },
        {
          "name": "react",
          "manifest": "apps/blog/package.json",
          "ecosystem": "npm",
          "version_constraint": "^19.2.4"
        },
        {
          "name": "react-dom",
          "manifest": "apps/blog/package.json",
          "ecosystem": "npm",
          "version_constraint": "^19.2.4"
        },
        {
          "name": "rehype-pretty-code",
          "manifest": "apps/blog/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.14.3"
        },
        {
          "name": "remark-gfm",
          "manifest": "apps/blog/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.0.1"
        },
        {
          "name": "shiki",
          "manifest": "apps/blog/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.0.2"
        },
        {
          "name": "zod",
          "manifest": "apps/blog/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.3.6"
        },
        {
          "name": "@sentry/node",
          "manifest": "apps/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^10.43.0"
        },
        {
          "name": "chalk",
          "manifest": "apps/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.3.0"
        },
        {
          "name": "commander",
          "manifest": "apps/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^12.1.0"
        },
        {
          "name": "conf",
          "manifest": "apps/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^13.0.1"
        },
        {
          "name": "convex",
          "manifest": "apps/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.32.0"
        },
        {
          "name": "cross-spawn",
          "manifest": "apps/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^7.0.6"
        },
        {
          "name": "dotenv",
          "manifest": "apps/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^16.4.7"
        },
        {
          "name": "ink",
          "manifest": "apps/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.2.1"
        },
        {
          "name": "inquirer",
          "manifest": "apps/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^12.3.2"
        },
        {
          "name": "open",
          "manifest": "apps/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^10.1.0"
        },
        {
          "name": "ora",
          "manifest": "apps/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^8.1.1"
        },
        {
          "name": "react",
          "manifest": "apps/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^18.3.1"
        },
        {
          "name": "zod",
          "manifest": "apps/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.3.6"
        },
        {
          "name": "@sentry/node",
          "manifest": "apps/vscode-extension/package.json",
          "ecosystem": "npm",
          "version_constraint": "^10.43.0"
        },
        {
          "name": "axios",
          "manifest": "apps/vscode-extension/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.6.2"
        },
        {
          "name": "convex",
          "manifest": "apps/vscode-extension/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.32.0"
        },
        {
          "name": "@envpilot/ui",
          "manifest": "apps/web/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@modelcontextprotocol/sdk",
          "manifest": "apps/web/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.29.0"
        },
        {
          "name": "@polar-sh/sdk",
          "manifest": "apps/web/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.46.6"
        },
        {
          "name": "@sentry/nextjs",
          "manifest": "apps/web/package.json",
          "ecosystem": "npm",
          "version_constraint": "^10"
        },
        {
          "name": "@tanstack/react-hotkeys",
          "manifest": "apps/web/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.4.1"
        },
        {
          "name": "@tanstack/react-query",
          "manifest": "apps/web/package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.90.21"
        },
        {
          "name": "@vercel/analytics",
          "manifest": "apps/web/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.6.1"
        },
        {
          "name": "@workos-inc/authkit-nextjs",
          "manifest": "apps/web/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.14.0"
        },
        {
          "name": "@workos-inc/node",
          "manifest": "apps/web/package.json",
          "ecosystem": "npm",
          "version_constraint": "^8.5.0"
        },
        {
          "name": "canvas-confetti",
          "manifest": "apps/web/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.9.4"
        },
        {
          "name": "class-variance-authority",
          "manifest": "apps/web/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.7.1"
        },
        {
          "name": "clsx",
          "manifest": "apps/web/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.1.1"
        },
        {
          "name": "convex",
          "manifest": "apps/web/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.32.0"
        },
        {
          "name": "date-fns",
          "manifest": "apps/web/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.1.0"
        },
        {
          "name": "framer-motion",
          "manifest": "apps/web/package.json",
          "ecosystem": "npm",
          "version_constraint": "^12.35.2"
        },
        {
          "name": "jose",
          "manifest": "apps/web/package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.10.0"
        },
        {
          "name": "lucide-react",
          "manifest": "apps/web/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.577.0"
        },
        {
          "name": "mcp-handler",
          "manifest": "apps/web/package.json",
          "ecosystem": "npm",
          "version_constraint": "1.1.0"
        },
        {
          "name": "next",
          "manifest": "apps/web/package.json",
          "ecosystem": "npm",
          "version_constraint": "^16.2.10"
        },
        {
          "name": "react",
          "manifest": "apps/web/package.json",
          "ecosystem": "npm",
          "version_constraint": "^19.2.4"
        },
        {
          "name": "react-dom",
          "manifest": "apps/web/package.json",
          "ecosystem": "npm",
          "version_constraint": "^19.2.4"
        },
        {
          "name": "react-markdown",
          "manifest": "apps/web/package.json",
          "ecosystem": "npm",
          "version_constraint": "^10.1.0"
        },
        {
          "name": "recharts",
          "manifest": "apps/web/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.8.0"
        },
        {
          "name": "remark-gfm",
          "manifest": "apps/web/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.0.1"
        },
        {
          "name": "sonner",
          "manifest": "apps/web/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.0.7"
        },
        {
          "name": "tailwind-merge",
          "manifest": "apps/web/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.5.0"
        },
        {
          "name": "zod",
          "manifest": "apps/web/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.3.6"
        },
        {
          "name": "zustand",
          "manifest": "apps/web/package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.0.11"
        },
        {
          "name": "typescript-eslint",
          "manifest": "packages/eslint-config/package.json",
          "ecosystem": "npm",
          "version_constraint": "^8"
        },
        {
          "name": "@actions/core",
          "manifest": "packages/github-action/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.11.1"
        },
        {
          "name": "date-fns",
          "manifest": "packages/ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.1.0"
        },
        {
          "name": "framer-motion",
          "manifest": "packages/ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "^12.35.2"
        },
        {
          "name": "lucide-react",
          "manifest": "packages/ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.577.0"
        },
        {
          "name": "mermaid",
          "manifest": "packages/ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "^11"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "@actions/core",
            "direct": true,
            "version": "^1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "@convex-dev/rate-limiter",
            "direct": true,
            "version": "^0.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "@convex-dev/workflow",
            "direct": true,
            "version": "^0.3.5",
            "ecosystem": "npm"
          },
          {
            "name": "@convex-dev/workpool",
            "direct": true,
            "version": "^0.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "@dnd-kit/core",
            "direct": true,
            "version": "^6.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "@dnd-kit/utilities",
            "direct": true,
            "version": "^3.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "@fontsource-variable/geist",
            "direct": true,
            "version": "^5.2.8",
            "ecosystem": "npm"
          },
          {
            "name": "@fontsource-variable/geist-mono",
            "direct": true,
            "version": "^5.2.8",
            "ecosystem": "npm"
          },
          {
            "name": "@modelcontextprotocol/sdk",
            "direct": true,
            "version": "^1.29.0",
            "ecosystem": "npm"
          },
          {
            "name": "@polar-sh/sdk",
            "direct": true,
            "version": "^0.46.6",
            "ecosystem": "npm"
          },
          {
            "name": "@sentry/nextjs",
            "direct": true,
            "version": "^10",
            "ecosystem": "npm"
          },
          {
            "name": "@sentry/node",
            "direct": true,
            "version": "^10.43.0",
            "ecosystem": "npm"
          },
          {
            "name": "@tanstack/react-hotkeys",
            "direct": true,
            "version": "^0.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "@tanstack/react-query",
            "direct": true,
            "version": "^5.90.21",
            "ecosystem": "npm"
          },
          {
            "name": "@tanstack/react-router",
            "direct": true,
            "version": "^1.120.3",
            "ecosystem": "npm"
          },
          {
            "name": "@vercel/analytics",
            "direct": true,
            "version": "^1.6.1",
            "ecosystem": "npm"
          },
          {
            "name": "@workos-inc/authkit-nextjs",
            "direct": true,
            "version": "^2.14.0",
            "ecosystem": "npm"
          },
          {
            "name": "@workos-inc/authkit-react",
            "direct": true,
            "version": "^0.16.1",
            "ecosystem": "npm"
          },
          {
            "name": "@workos-inc/node",
            "direct": true,
            "version": "^8.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "axios",
            "direct": true,
            "version": "^1.6.2",
            "ecosystem": "npm"
          },
          {
            "name": "canvas-confetti",
            "direct": true,
            "version": "^1.9.4",
            "ecosystem": "npm"
          },
          {
            "name": "chalk",
            "direct": true,
            "version": "^5.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "class-variance-authority",
            "direct": true,
            "version": "^0.7.1",
            "ecosystem": "npm"
          },
          {
            "name": "clsx",
            "direct": true,
            "version": "^2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "commander",
            "direct": true,
            "version": "^12.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "conf",
            "direct": true,
            "version": "^13.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "convex",
            "direct": true,
            "version": "^1.32.0",
            "ecosystem": "npm"
          },
          {
            "name": "cross-spawn",
            "direct": true,
            "version": "^7.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "date-fns",
            "direct": true,
            "version": "^4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "dotenv",
            "direct": true,
            "version": "^16.4.7",
            "ecosystem": "npm"
          },
          {
            "name": "framer-motion",
            "direct": true,
            "version": "^12.35.2",
            "ecosystem": "npm"
          },
          {
            "name": "gray-matter",
            "direct": true,
            "version": "^4.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "ink",
            "direct": true,
            "version": "^5.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "inquirer",
            "direct": true,
            "version": "^12.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "jose",
            "direct": true,
            "version": "^5.10.0",
            "ecosystem": "npm"
          },
          {
            "name": "lucide-react",
            "direct": true,
            "version": "^0.577.0",
            "ecosystem": "npm"
          },
          {
            "name": "mcp-handler",
            "direct": true,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "mermaid",
            "direct": true,
            "version": "^11",
            "ecosystem": "npm"
          },
          {
            "name": "next",
            "direct": true,
            "version": "^16.2.10",
            "ecosystem": "npm"
          },
          {
            "name": "next-mdx-remote",
            "direct": true,
            "version": "^6.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "open",
            "direct": true,
            "version": "^10.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "ora",
            "direct": true,
            "version": "^8.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "react",
            "direct": true,
            "version": "^18.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "react",
            "direct": true,
            "version": "^19.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "react",
            "direct": true,
            "version": "^19.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "react-dom",
            "direct": true,
            "version": "^19.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "react-dom",
            "direct": true,
            "version": "^19.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "react-markdown",
            "direct": true,
            "version": "^10.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "recharts",
            "direct": true,
            "version": "^3.8.0",
            "ecosystem": "npm"
          },
          {
            "name": "rehype-pretty-code",
            "direct": true,
            "version": "^0.14.3",
            "ecosystem": "npm"
          },
          {
            "name": "remark-gfm",
            "direct": true,
            "version": "^4.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "resend",
            "direct": true,
            "version": "^6.9.3",
            "ecosystem": "npm"
          },
          {
            "name": "shiki",
            "direct": true,
            "version": "^4.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "sonner",
            "direct": true,
            "version": "^2.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "tailwind-merge",
            "direct": true,
            "version": "^3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "tailwind-merge",
            "direct": true,
            "version": "^3.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "typescript-eslint",
            "direct": true,
            "version": "^8",
            "ecosystem": "npm"
          },
          {
            "name": "zod",
            "direct": true,
            "version": "^4.3.6",
            "ecosystem": "npm"
          },
          {
            "name": "zustand",
            "direct": true,
            "version": "^5.0.11",
            "ecosystem": "npm"
          },
          {
            "name": "zustand",
            "direct": true,
            "version": "^5.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "@next/bundle-analyzer",
            "direct": false,
            "version": "^16.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "@playwright/test",
            "direct": false,
            "version": "^1.58.2",
            "ecosystem": "npm"
          },
          {
            "name": "@tailwindcss/postcss",
            "direct": false,
            "version": "^4",
            "ecosystem": "npm"
          },
          {
            "name": "@tailwindcss/vite",
            "direct": false,
            "version": "^4.1.7",
            "ecosystem": "npm"
          },
          {
            "name": "@tanstack/react-query-devtools",
            "direct": false,
            "version": "^5.91.3",
            "ecosystem": "npm"
          },
          {
            "name": "@tanstack/router-plugin",
            "direct": false,
            "version": "^1.120.3",
            "ecosystem": "npm"
          },
          {
            "name": "@types/canvas-confetti",
            "direct": false,
            "version": "^1.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "@types/cross-spawn",
            "direct": false,
            "version": "^6.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "@types/node",
            "direct": false,
            "version": "^22",
            "ecosystem": "npm"
          },
          {
            "name": "@types/node",
            "direct": false,
            "version": "^22.10.10",
            "ecosystem": "npm"
          },
          {
            "name": "@types/node",
            "direct": false,
            "version": "^22.15.0",
            "ecosystem": "npm"
          },
          {
            "name": "@types/react",
            "direct": false,
            "version": "^18.3.12",
            "ecosystem": "npm"
          },
          {
            "name": "@types/react",
            "direct": false,
            "version": "^19",
            "ecosystem": "npm"
          },
          {
            "name": "@types/react",
            "direct": false,
            "version": "^19.1.6",
            "ecosystem": "npm"
          },
          {
            "name": "@types/react-dom",
            "direct": false,
            "version": "^19",
            "ecosystem": "npm"
          },
          {
            "name": "@types/react-dom",
            "direct": false,
            "version": "^19.1.6",
            "ecosystem": "npm"
          },
          {
            "name": "@types/vscode",
            "direct": false,
            "version": "^1.85.0",
            "ecosystem": "npm"
          },
          {
            "name": "@vitejs/plugin-react",
            "direct": false,
            "version": "^4.5.2",
            "ecosystem": "npm"
          },
          {
            "name": "@vscode/vsce",
            "direct": false,
            "version": "^3.7.1",
            "ecosystem": "npm"
          },
          {
            "name": "babel-plugin-react-compiler",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "concurrently",
            "direct": false,
            "version": "^9.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "esbuild",
            "direct": false,
            "version": "^0.19.8",
            "ecosystem": "npm"
          },
          {
            "name": "eslint",
            "direct": false,
            "version": "^9",
            "ecosystem": "npm"
          },
          {
            "name": "eslint",
            "direct": false,
            "version": "^9.28.0",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-config-next",
            "direct": false,
            "version": "16.1.6",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-config-next",
            "direct": false,
            "version": "^16.2.10",
            "ecosystem": "npm"
          },
          {
            "name": "nodemailer",
            "direct": false,
            "version": "^9.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "npm-run-all",
            "direct": false,
            "version": "^4.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "prettier",
            "direct": false,
            "version": "^3.6.2",
            "ecosystem": "npm"
          },
          {
            "name": "tailwindcss",
            "direct": false,
            "version": "^4",
            "ecosystem": "npm"
          },
          {
            "name": "tailwindcss",
            "direct": false,
            "version": "^4.1.7",
            "ecosystem": "npm"
          },
          {
            "name": "tsup",
            "direct": false,
            "version": "^8.3.5",
            "ecosystem": "npm"
          },
          {
            "name": "turbo",
            "direct": false,
            "version": "^2",
            "ecosystem": "npm"
          },
          {
            "name": "typescript",
            "direct": false,
            "version": "^5",
            "ecosystem": "npm"
          },
          {
            "name": "typescript",
            "direct": false,
            "version": "^5.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "typescript",
            "direct": false,
            "version": "^5.7.3",
            "ecosystem": "npm"
          },
          {
            "name": "typescript",
            "direct": false,
            "version": "^5.8.3",
            "ecosystem": "npm"
          },
          {
            "name": "vite",
            "direct": false,
            "version": "^6.3.5",
            "ecosystem": "npm"
          },
          {
            "name": "vitest",
            "direct": false,
            "version": "^1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "vitest",
            "direct": false,
            "version": "^3.0.4",
            "ecosystem": "npm"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 100,
        "direct_count": 60,
        "indirect_count": 40
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 2,
        "merged_prs": 147,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 8
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "rafay99-epic",
          "commits": 154,
          "avatar_url": "https://avatars.githubusercontent.com/u/82662797?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "deploy-action.yml",
        "deploy-cli.yml",
        "deploy-convex.yml",
        "deploy-extension.yml",
        "deploy-homebrew.yml",
        "deploy-vercel.yml",
        "version-tracker.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        "eslint.config.mjs"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 9,
            "reason": "29 out of 30 merged PRs checked by a CI test -- score normalized to 9",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 3,
            "reason": "project has 1 contributing companies or organizations -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 4,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "94 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "311a623aa78b20ef168b3f9e779cca4e961d0274",
        "ran_at": "2026-07-25T23:18:51Z",
        "aggregate_score": 3.2,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-20T09:17:27Z",
      "oldest_open_prs": [
        {
          "number": 64,
          "created_at": "2026-05-08T18:38:52Z",
          "last_comment_at": "2026-07-06T08:09:04Z",
          "last_comment_author": "rafay99-epic"
        },
        {
          "number": 157,
          "created_at": "2026-07-20T10:30:13Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-20T09:14:22Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/rafay99-epic/envpilot.dev",
    "host": "github.com",
    "name": "envpilot.dev",
    "owner": "rafay99-epic"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 63,
      "inputs": {
        "security": 46,
        "vitality": 80,
        "community": 39,
        "governance": 54,
        "engineering": 89
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 80,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 73,
            "inputs": {
              "commits_last_year": 155,
              "human_commit_share": 1,
              "days_since_last_push": 5,
              "active_weeks_last_year": 13
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "13/52 weeks with commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 13
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "155 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 155
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 79,
              "latest_release_tag": "v1.43.0+311a623",
              "releases_from_tags": false,
              "days_since_latest_release": 5,
              "mean_days_between_releases": 0.2
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "79 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 79
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~0.2 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 0.2
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 39,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "good",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 70,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 57,
            "inputs": {
              "packages": [
                "@envpilot/cli",
                "envpilot"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 2507
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "2,507 downloads/month across npm",
                "points": 45.3,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 2507,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 54,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 13,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "moderate",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 68,
            "inputs": {
              "merged_prs": 147,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 8
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "147/155 decided PRs merged",
                "points": 36.3,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 147,
                      "decided": 155
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 51,
            "inputs": {
              "followers": 9,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "rafay99-epic",
              "public_repos": 64,
              "account_age_days": 1926
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "9 followers of rafay99-epic",
                "points": 7.2,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 9,
                      "login": "rafay99-epic"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "64 public repos, account ~5 yr old",
                "points": 23.5,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 64
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 5
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "@envpilot/cli",
                "envpilot"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 5
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "2 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 2,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 5 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "29 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 29
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "excellent",
        "name": "Engineering Quality",
        "value": 89,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 82,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "8 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 8
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": "eslint.config.mjs",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.mjs"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "29 out of 30 merged PRs checked by a CI test -- score normalized to 9",
                "points": 18,
                "status": "partial",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "topics": [
                "cli",
                "code",
                "convex",
                "extension",
                "nextjs",
                "role-based-access-control",
                "vs"
              ],
              "has_wiki": true,
              "homepage": "https://envpilot.dev",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://envpilot.dev",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "7 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 46,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Packaging. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "packaging"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 32,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 3.2
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "29 out of 30 merged PRs checked by a CI test -- score normalized to 9",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 2,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "94 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:@envpilot/cli@1.19.0 runtime dependency closure — what installing the published package pulls in — 186 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:@envpilot/cli@1.19.0",
                  "assessed": 186
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 0,
              "affected_packages": 0,
              "assessed_packages": 186,
              "unassessed_packages": 0,
              "affected_by_severity": "none",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "no indirect dependency carries a known advisory",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "no_indirect_advisories",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 186,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 63,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.95,
              "agent_instruction_files": [
                ".agents/skills/vercel-react-best-practices/AGENTS.md",
                "AGENTS.md",
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 105774
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": ".agents/skills/vercel-react-best-practices/AGENTS.md, AGENTS.md, CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".agents/skills/vercel-react-best-practices/AGENTS.md, AGENTS.md, CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "95 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 95,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "at_risk",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 48,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "apps/admin/tsconfig.json",
                "apps/blog/tsconfig.json",
                "apps/cli/tsconfig.json",
                "apps/docs/tsconfig.json",
                "apps/vscode-extension/tsconfig.json",
                "apps/web/tsconfig.json",
                "convex/tsconfig.json",
                "packages/github-action/tsconfig.json",
                "packages/ui/tsconfig.json"
              ],
              "agent_commit_share": 0.02,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": "eslint.config.mjs",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.mjs"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "apps/admin/tsconfig.json, apps/blog/tsconfig.json, apps/cli/tsconfig.json, apps/docs/tsconfig.json, apps/vscode-extension/tsconfig.json, apps/web/tsconfig.json, convex/tsconfig.json, packages/github-action/tsconfig.json, packages/ui/tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "apps/admin/tsconfig.json, apps/blog/tsconfig.json, apps/cli/tsconfig.json, apps/docs/tsconfig.json, apps/vscode-extension/tsconfig.json, apps/web/tsconfig.json, convex/tsconfig.json, packages/github-action/tsconfig.json, packages/ui/tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "2 of the last 100 commits agent-authored or agent-credited",
                "points": 4,
                "status": "partial",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 2,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 76271,
              "source_files_sampled": 697,
              "oversized_source_files": 5
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "5/697 source files over 60KB",
                "points": 54.6,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 697,
                      "oversized": 5
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "critical",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 20,
            "inputs": {
              "example_dirs": [],
              "has_mcp_signal": true,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [],
  "report_type": "repository",
  "generated_at": "2026-07-25T23:19:07.099720Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/r/rafay99-epic/envpilot.dev.svg",
  "full_name": "rafay99-epic/envpilot.dev",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsnpm.