Raw JSON report machine-readable
{
"data": {
"repo": {
"topics": [
"cel",
"cli",
"content-detection",
"file-search",
"go",
"mcp",
"mcp-server"
],
"is_fork": false,
"size_kb": 25969,
"has_wiki": true,
"homepage": "https://richardwooding.github.io/file-search-on/",
"languages": {
"Go": 3359748,
"CSS": 8890,
"HTML": 3511,
"Shell": 42509,
"Swift": 3066,
"Python": 56856,
"Mermaid": 1143,
"Makefile": 816,
"JavaScript": 25221,
"Go Template": 10207
},
"pushed_at": "2026-07-27T04:18:06Z",
"created_at": "2026-05-03T14:53:08Z",
"owner_type": "User",
"updated_at": "2026-07-20T22:16:01Z",
"description": "File content type aware search with attribute and cel support",
"is_archived": false,
"is_disabled": false,
"license_spdx": "MIT",
"default_branch": "main",
"license_spdx_raw": "MIT",
"primary_language": "Go",
"significant_languages": [
"Go"
]
},
"owner": {
"blog": null,
"name": "Richard Wooding",
"type": "User",
"login": "richardwooding",
"company": "spandigital.com",
"location": "South Africa",
"followers": 28,
"avatar_url": "https://avatars.githubusercontent.com/u/373901?v=4",
"created_at": "2010-08-23T21:21:10Z",
"is_verified": null,
"public_repos": 72,
"account_age_days": 5816
},
"license": {
"state": "standard",
"spdx_id": "MIT",
"raw_spdx": "MIT",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v0.119.3",
"kind": "patch",
"published_at": "2026-07-20T22:21:53Z"
},
{
"tag": "v0.119.2",
"kind": "patch",
"published_at": "2026-07-14T09:44:58Z"
},
{
"tag": "v0.119.1",
"kind": "patch",
"published_at": "2026-07-10T14:53:28Z"
},
{
"tag": "v0.119.0",
"kind": "minor",
"published_at": "2026-07-10T13:02:21Z"
},
{
"tag": "v0.118.0",
"kind": "minor",
"published_at": "2026-07-03T07:43:42Z"
},
{
"tag": "v0.117.3",
"kind": "patch",
"published_at": "2026-06-30T12:39:27Z"
},
{
"tag": "v0.117.2",
"kind": "patch",
"published_at": "2026-06-27T22:14:50Z"
},
{
"tag": "v0.117.1",
"kind": "patch",
"published_at": "2026-06-27T16:18:17Z"
},
{
"tag": "v0.117.0",
"kind": "minor",
"published_at": "2026-06-27T14:40:42Z"
},
{
"tag": "v0.116.0",
"kind": "minor",
"published_at": "2026-06-26T16:20:11Z"
},
{
"tag": "v0.115.0",
"kind": "minor",
"published_at": "2026-06-26T15:05:52Z"
},
{
"tag": "v0.114.2",
"kind": "patch",
"published_at": "2026-06-26T12:48:19Z"
},
{
"tag": "v0.114.1",
"kind": "patch",
"published_at": "2026-06-26T08:52:04Z"
},
{
"tag": "v0.114.0",
"kind": "minor",
"published_at": "2026-06-25T14:10:49Z"
},
{
"tag": "v0.113.0",
"kind": "minor",
"published_at": "2026-06-25T12:12:19Z"
},
{
"tag": "v0.112.0",
"kind": "minor",
"published_at": "2026-06-25T09:53:04Z"
},
{
"tag": "v0.111.0",
"kind": "minor",
"published_at": "2026-06-24T07:41:49Z"
},
{
"tag": "v0.110.1",
"kind": "patch",
"published_at": "2026-06-23T13:17:39Z"
},
{
"tag": "v0.110.0",
"kind": "minor",
"published_at": "2026-06-23T08:57:16Z"
},
{
"tag": "v0.109.0",
"kind": "minor",
"published_at": "2026-06-20T21:38:19Z"
},
{
"tag": "v0.108.1",
"kind": "patch",
"published_at": "2026-06-16T16:08:36Z"
},
{
"tag": "v0.108.0",
"kind": "minor",
"published_at": "2026-06-16T15:02:55Z"
},
{
"tag": "v0.107.0",
"kind": "minor",
"published_at": "2026-06-16T14:09:34Z"
},
{
"tag": "v0.106.0",
"kind": "minor",
"published_at": "2026-06-16T13:29:07Z"
},
{
"tag": "v0.105.0",
"kind": "minor",
"published_at": "2026-06-16T12:42:39Z"
},
{
"tag": "v0.104.0",
"kind": "minor",
"published_at": "2026-06-16T11:32:26Z"
},
{
"tag": "v0.103.0",
"kind": "minor",
"published_at": "2026-06-16T09:51:20Z"
},
{
"tag": "v0.102.1",
"kind": "patch",
"published_at": "2026-06-15T10:55:39Z"
},
{
"tag": "v0.102.0",
"kind": "minor",
"published_at": "2026-06-15T09:59:41Z"
},
{
"tag": "v0.101.4",
"kind": "patch",
"published_at": "2026-06-15T07:24:11Z"
},
{
"tag": "v0.101.3",
"kind": "patch",
"published_at": "2026-06-15T06:55:00Z"
},
{
"tag": "v0.101.2",
"kind": "patch",
"published_at": "2026-06-14T15:33:41Z"
},
{
"tag": "v0.101.1",
"kind": "patch",
"published_at": "2026-06-14T08:21:18Z"
},
{
"tag": "v0.101.0",
"kind": "minor",
"published_at": "2026-06-14T05:19:56Z"
},
{
"tag": "v0.100.1",
"kind": "patch",
"published_at": "2026-06-14T04:35:28Z"
},
{
"tag": "v0.100.0",
"kind": "minor",
"published_at": "2026-06-13T23:35:13Z"
},
{
"tag": "v0.99.0",
"kind": "minor",
"published_at": "2026-06-13T21:22:09Z"
},
{
"tag": "v0.98.0",
"kind": "minor",
"published_at": "2026-06-13T20:54:08Z"
},
{
"tag": "v0.97.0",
"kind": "minor",
"published_at": "2026-06-13T20:03:51Z"
},
{
"tag": "v0.96.0",
"kind": "minor",
"published_at": "2026-06-13T18:58:59Z"
},
{
"tag": "v0.95.2",
"kind": "patch",
"published_at": "2026-06-13T18:26:43Z"
},
{
"tag": "v0.95.1",
"kind": "patch",
"published_at": "2026-06-13T12:06:19Z"
},
{
"tag": "v0.95.0",
"kind": "minor",
"published_at": "2026-06-13T11:14:34Z"
},
{
"tag": "v0.94.0",
"kind": "minor",
"published_at": "2026-06-13T10:10:00Z"
},
{
"tag": "v0.93.0",
"kind": "minor",
"published_at": "2026-06-12T15:08:33Z"
},
{
"tag": "v0.92.0",
"kind": "minor",
"published_at": "2026-06-12T13:21:39Z"
},
{
"tag": "v0.91.1",
"kind": "patch",
"published_at": "2026-06-11T13:04:57Z"
},
{
"tag": "v0.91.0",
"kind": "minor",
"published_at": "2026-06-11T08:55:15Z"
},
{
"tag": "v0.90.1",
"kind": "patch",
"published_at": "2026-06-11T05:51:57Z"
},
{
"tag": "v0.90.0",
"kind": "minor",
"published_at": "2026-06-11T05:12:28Z"
},
{
"tag": "v0.89.0",
"kind": "minor",
"published_at": "2026-06-11T03:58:29Z"
},
{
"tag": "v0.88.0",
"kind": "minor",
"published_at": "2026-06-11T03:09:08Z"
},
{
"tag": "v0.87.0",
"kind": "minor",
"published_at": "2026-06-10T15:58:55Z"
},
{
"tag": "v0.86.0",
"kind": "minor",
"published_at": "2026-06-10T14:59:53Z"
},
{
"tag": "v0.85.0",
"kind": "minor",
"published_at": "2026-06-10T13:31:25Z"
},
{
"tag": "v0.84.0",
"kind": "minor",
"published_at": "2026-06-10T12:02:33Z"
},
{
"tag": "v0.83.0",
"kind": "minor",
"published_at": "2026-06-10T10:22:22Z"
},
{
"tag": "v0.82.1",
"kind": "patch",
"published_at": "2026-06-06T22:38:05Z"
},
{
"tag": "v0.82.0",
"kind": "minor",
"published_at": "2026-06-06T10:52:09Z"
},
{
"tag": "v0.81.0",
"kind": "minor",
"published_at": "2026-06-05T08:49:38Z"
},
{
"tag": "v0.80.0",
"kind": "minor",
"published_at": "2026-06-04T20:28:24Z"
},
{
"tag": "v0.79.0",
"kind": "minor",
"published_at": "2026-06-04T19:29:07Z"
},
{
"tag": "v0.78.1",
"kind": "patch",
"published_at": "2026-06-04T18:22:18Z"
},
{
"tag": "v0.78.0",
"kind": "minor",
"published_at": "2026-06-04T17:56:11Z"
},
{
"tag": "v0.77.0",
"kind": "minor",
"published_at": "2026-06-04T15:15:36Z"
},
{
"tag": "v0.76.0",
"kind": "minor",
"published_at": "2026-06-04T10:43:15Z"
},
{
"tag": "v0.75.1",
"kind": "patch",
"published_at": "2026-06-04T08:20:36Z"
},
{
"tag": "v0.75.0",
"kind": "minor",
"published_at": "2026-06-02T22:01:13Z"
},
{
"tag": "v0.74.1",
"kind": "patch",
"published_at": "2026-06-02T21:18:07Z"
},
{
"tag": "v0.74.0",
"kind": "minor",
"published_at": "2026-06-02T20:51:47Z"
},
{
"tag": "v0.73.0",
"kind": "minor",
"published_at": "2026-06-02T15:50:05Z"
},
{
"tag": "v0.72.0",
"kind": "minor",
"published_at": "2026-06-02T14:33:22Z"
},
{
"tag": "v0.71.0",
"kind": "minor",
"published_at": "2026-06-02T09:55:41Z"
},
{
"tag": "v0.70.2",
"kind": "patch",
"published_at": "2026-06-02T07:20:58Z"
},
{
"tag": "v0.70.1",
"kind": "patch",
"published_at": "2026-06-01T10:50:15Z"
},
{
"tag": "v0.70.0",
"kind": "minor",
"published_at": "2026-05-30T21:15:21Z"
},
{
"tag": "v0.69.0",
"kind": "minor",
"published_at": "2026-05-30T16:23:12Z"
},
{
"tag": "v0.68.0",
"kind": "minor",
"published_at": "2026-05-30T12:29:20Z"
},
{
"tag": "v0.67.0",
"kind": "minor",
"published_at": "2026-05-30T10:14:26Z"
},
{
"tag": "v0.66.0",
"kind": "minor",
"published_at": "2026-05-30T09:27:54Z"
},
{
"tag": "v0.65.0",
"kind": "minor",
"published_at": "2026-05-30T07:41:17Z"
},
{
"tag": "v0.64.0",
"kind": "minor",
"published_at": "2026-05-29T11:39:18Z"
},
{
"tag": "v0.63.0",
"kind": "minor",
"published_at": "2026-05-27T17:04:43Z"
},
{
"tag": "v0.62.0",
"kind": "minor",
"published_at": "2026-05-27T15:30:05Z"
},
{
"tag": "v0.61.0",
"kind": "minor",
"published_at": "2026-05-27T12:03:01Z"
},
{
"tag": "v0.60.0",
"kind": "minor",
"published_at": "2026-05-27T09:26:46Z"
},
{
"tag": "v0.59.0",
"kind": "minor",
"published_at": "2026-05-27T05:34:13Z"
},
{
"tag": "v0.58.0",
"kind": "minor",
"published_at": "2026-05-26T21:26:50Z"
},
{
"tag": "v0.57.0",
"kind": "minor",
"published_at": "2026-05-26T20:59:16Z"
},
{
"tag": "v0.56.0",
"kind": "minor",
"published_at": "2026-05-26T20:35:13Z"
},
{
"tag": "v0.55.0",
"kind": "minor",
"published_at": "2026-05-26T20:06:58Z"
},
{
"tag": "v0.54.1",
"kind": "patch",
"published_at": "2026-05-26T12:58:23Z"
},
{
"tag": "v0.54.0",
"kind": "minor",
"published_at": "2026-05-26T08:10:37Z"
},
{
"tag": "v0.53.0",
"kind": "minor",
"published_at": "2026-05-25T17:33:04Z"
},
{
"tag": "v0.52.0",
"kind": "minor",
"published_at": "2026-05-25T13:03:42Z"
},
{
"tag": "v0.51.0",
"kind": "minor",
"published_at": "2026-05-25T11:27:39Z"
},
{
"tag": "v0.50.0",
"kind": "minor",
"published_at": "2026-05-25T10:54:12Z"
},
{
"tag": "v0.49.0",
"kind": "minor",
"published_at": "2026-05-24T19:02:49Z"
},
{
"tag": "v0.48.0",
"kind": "minor",
"published_at": "2026-05-24T09:01:52Z"
},
{
"tag": "v0.47.0",
"kind": "minor",
"published_at": "2026-05-23T19:13:13Z"
}
],
"recent_commits": [
{
"oid": "3699a2cbb97c4a51c19fbe11d86375e84e54dd05",
"body": "Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore(deps): bump codemetrics to v0.12.2, treesitter-symbols to v0.6.2",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-07-20T22:15:46Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "7333abeddaf5300b892934092b1e76e14fd4a62a",
"body": "Bumps the minor-and-patch group with 6 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [github.com/alecthomas/kong](https://github.com/alecthomas/kong) | `1.15.0` | `1.16.0` |\n| [github.com/richardwooding/c2pa](https://github.com/richardwooding/c2pa) | `0.2.0` | `0.3.0` |\n| [github.com/richa\n[…]\nion-update:semver-minor\n dependency-group: minor-and-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): Bump the minor-and-patch group with 6 updates (#564)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-20T22:12:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6f9dd9631b10f857ff0e9bab56b15b8a9c11245a",
"body": "Bumps [actions/setup-go](https://github.com/actions/setup-go) from 6 to 7.\n- [Release notes](https://github.com/actions/setup-go/releases)\n- [Commits](https://github.com/actions/setup-go/compare/v6...v7)\n\n---\nupdated-dependencies:\n- dependency-name: actions/setup-go\n dependency-version: '7'\n depen\n[…]\nirect:production\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): Bump actions/setup-go from 6 to 7 (#565)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-20T22:12:50Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "304437e9a7849b0a0068bcee53d74efdf0244149",
"body": "An interactive case study at /anatomy/: the walk → extract → index →\nanalyse pipeline as clickable layers, one chip per richardwooding/*\ndependency, with a detail panel showing what each library powers\n(attributes and MCP tools), which were extracted from this codebase,\nand links to ports and the live WASM demos. Linked from the main nav.\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: add the anatomy page — one tool, eleven libraries (#563)",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-07-16T15:31:41Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "def6c0ef73d30e0bd23762ac574d2114e9994919",
"body": "A pinned go-version silently falls behind when go.mod's requirement is\nbumped, and setup-go@v6 (GOTOOLCHAIN=local) no longer auto-upgrades the\ntoolchain to compensate — this broke bggclient and duckdb-mcp CI.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "ci: take Go version from go.mod instead of pinning",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-07-14T10:05:49Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "aa3d7b93b101252ae4865a4e5441b55b492c8b6b",
"body": "A pinned go-version silently falls behind when go.mod's requirement is\nbumped, and setup-go@v6 (GOTOOLCHAIN=local) no longer auto-upgrades the\ntoolchain to compensate — this broke bggclient and duckdb-mcp CI.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "ci: take Go version from go.mod instead of pinning",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-07-14T10:05:46Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "2146c2213c733c6a213a5e78d013144301e721bf",
"body": "A pinned go-version silently falls behind when go.mod's requirement is\nbumped, and setup-go@v6 (GOTOOLCHAIN=local) no longer auto-upgrades the\ntoolchain to compensate — this broke bggclient and duckdb-mcp CI.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "ci: take Go version from go.mod instead of pinning",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-07-14T10:05:43Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "5d2897c8c0a352593316c269d1d9fad6e48001b1",
"body": "…8871a (#562)\n\nCo-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(site): sync gloam assets to f5ac1871af22055721843d5ba24b1c89497…",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-07-14T09:33:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8cba2f3aca69457536a2a36baeb0e786cf69ecab",
"body": "Bumps the minor-and-patch group with 1 update: [github.com/richardwooding/go-coupling](https://github.com/richardwooding/go-coupling).\n\n\nUpdates `github.com/richardwooding/go-coupling` from 0.3.0 to 0.3.1\n- [Release notes](https://github.com/richardwooding/go-coupling/releases)\n- [Commits](https://g\n[…]\nion-update:semver-patch\n dependency-group: minor-and-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): Bump github.com/richardwooding/go-coupling (#561)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-14T09:30:32Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bccf7ed71443d5fe0670569b0e3f23ef9ed04369",
"body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 7.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/v4...v7)\n\n---\nupdated-dependenc\n[…]\nirect:production\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): Bump actions/checkout from 4 to 7 (#560)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-14T09:30:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f163b11e6aa561a3e52c1c48151098ca17c50358",
"body": "… updates (#559)\n\n---\nupdated-dependencies:\n- dependency-name: github.com/google/cel-go\n dependency-version: 0.29.2\n dependency-type: direct:production\n update-type: version-update:semver-patch\n dependency-group: minor-and-patch\n- dependency-name: github.com/richardwooding/go-coupling\n dependen\n[…]\nion-update:semver-minor\n dependency-group: minor-and-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): Bump the minor-and-patch group across 1 directory with 6…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-10T14:36:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "31c43038d6e85d5e25aefbb2de30f4ce42e1d6f3",
"body": "…r v0.22.5) (#557)\n\nPropagates the gotreesitter v0.20.9 -> v0.22.5 upgrade (indirect, via the\ntree-sitter chain) and folds in Dependabot #556:\n- codemetrics v0.8.0 -> v0.12.0\n- treesitter-symbols v0.5.0 -> v0.6.0\n- projectdetect v0.5.0 -> v0.6.0\n- cel-go v0.28.1 -> v0.29.1, go-toml/v2 v2.4.2 -> v2.4.3\nbuild, vet, and content-package tests pass.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore: bump codemetrics/treesitter-symbols/projectdetect (gotreesitte…",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-07-10T12:56:13Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "31a3e29db296639ede7a0b7c9063b6626f2359c2",
"body": "* refactor: point direct dep at renamed module codemetrics@v0.8.0\n\ngo-codemetrics was renamed to codemetrics (github.com/richardwooding/codemetrics).\nUpdate the direct import in internal/content/source_symbols_go.go, require\ncodemetrics v0.8.0, and refresh prose in sourcetype.go and CLAUDE.md.\n\nThe \n[…]\n.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "refactor: update direct dep to renamed module codemetrics@v0.8.0 (#555)",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-07-10T12:48:11Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "d6daecd2baaecd1cfd014cb2e5ca0ce7bbce7c11",
"body": "Add the GTM container snippet (head loader + noscript fallback) for\nportfolio analytics. Container GTM-NB62JPNJ.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat: install Google Tag Manager",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-07-09T10:40:11Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "33f5ebc125130bfe7186a83905422af169119575",
"body": "Single-page site for file-search-on built as a linked gloam consumer:\nvendored gloam.css/gloam.js + weekly gloam-sync, a Pages deploy workflow,\nfull OpenGraph/Twitter tags with a branded og.png, and an interactive\n\"query by content family\" hero terminal.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: add gloam-styled GitHub Pages site",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-07-09T09:40:30Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "7beda7f81072f00478f08ca760352c6364b9be31",
"body": "…) (#554)\n\nSwift cognitive complexity shipped with #491 (closed) and is confirmed\nworking in v0.118.0 — verified against real Swift trees. Three spots\nstill claimed it was omitted for Swift; the README and examples were\nalready updated but these lagged:\n\n- internal/mcpserver/server.go: the `complexi\n[…]\nguage with no cognitive spec. No behaviour change.\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: Swift cognitive complexity is live (drop stale \"omitted\" caveat…",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-07-03T08:07:31Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "413ec2d595f6bc4226230e38628f672cdd43876e",
"body": "Updates the tree-sitter symbol/metrics stack to pick up gotreesitter\nv0.20.9 (transitive):\n\n- github.com/richardwooding/treesitter-symbols v0.4.0 -> v0.4.1\n- github.com/richardwooding/go-codemetrics v0.5.0 -> v0.5.1\n- github.com/odvcencio/gotreesitter (indirect) v0.20.8 -> v0.20.9\n\nv0.20.9 recove\n[…]\nomatic + cognitive complexity for\nthose languages.\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore(deps): bump gotreesitter v0.20.9 stack (#553)",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-07-03T07:32:17Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "edd0f8ee2c8e4d2fa4f2fb01f8603cd1a89422d9",
"body": "…stack (#551)\n\n* feat: Swift cognitive complexity + coupling; bump gotreesitter stack\n\nBump the tree-sitter analysis stack to pick up the gotreesitter v0.20.7\ngrammar fixes and the new downstream features:\n\n go-codemetrics v0.4.1 -> v0.5.0 (Swift cognitive spec)\n treesitter-symbols v0.3.1 -> v\n[…]\n.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat: Swift cognitive complexity + coupling via gotreesitter v0.20.8 …",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-07-02T09:02:30Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "b2a85b8d60339fc04dede5854d0ccb09cd78b249",
"body": "Bumps the minor-and-patch group with 1 update: [github.com/andybalholm/brotli](https://github.com/andybalholm/brotli).\n\n\nUpdates `github.com/andybalholm/brotli` from 1.2.1 to 1.2.2\n- [Commits](https://github.com/andybalholm/brotli/compare/v1.2.1...v1.2.2)\n\n---\nupdated-dependencies:\n- dependency-name\n[…]\nion-update:semver-patch\n dependency-group: minor-and-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): Bump github.com/andybalholm/brotli (#550)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-30T12:28:32Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a7f2576fa4ccd0eef3a36b1032ee2968dd351006",
"body": null,
"is_bot": false,
"headline": "chore(dependabot): group minor and patch updates (#549)",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-30T10:34:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9fddcdee18a48af77ca4280c6f17559bb4b48025",
"body": "…mmar) (#548)\n\nSwift cognitive is consistently null (not a partial mix) — the upstream\ntree-sitter-swift grammar mis-parses `else if` chains, so a cognitive\nnumber would be unreliable for real code. Document the root cause and the\nupstream blocker in the README + source-code examples so the `—` colu\n[…]\nfort.\n\nRefs #491, #522; upstream gotreesitter#131.\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: explain why Swift cognitive complexity is omitted (upstream gra…",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-30T08:42:14Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "2a62f916d327df3b359aa70263e9484c468fd804",
"body": "…547)\n\nPulls gotreesitter v0.20.5 → v0.20.6 (indirect) — parser-recovery correctness +\nforest/performance improvements. No API change; content extraction baselines\n(all 16 tree-sitter languages) and the search suites pass unchanged.\n\nNote: Swift cognitive complexity remains unavailable (nil) — that'\n[…]\nly, #522). Swift cyclomatic is computed as before.\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore(deps): bump treesitter-symbols v0.3.1, go-codemetrics v0.4.1 (#…",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-29T12:00:55Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "7abd1abfe8160c4521247e32a425bcac274d930c",
"body": "Bumps the minor-and-patch group with 1 update: [golang.org/x/tools](https://github.com/golang/tools).\n\n\nUpdates `golang.org/x/tools` from 0.46.0 to 0.47.0\n- [Release notes](https://github.com/golang/tools/releases)\n- [Commits](https://github.com/golang/tools/compare/v0.46.0...v0.47.0)\n\n---\nupdated-d\n[…]\nion-update:semver-minor\n dependency-group: minor-and-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): Bump golang.org/x/tools in the minor-and-patch group (#546)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-29T11:27:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "23dbe00b69531e1e631f3a2ba2950760ff60a148",
"body": "Replace internal/hashset with github.com/richardwooding/go-hashset@v0.1.0 — the\nsame NSRL / threat-intel hash allowlist-denylist extracted to its own module\n(in-memory + bbolt, MD5/SHA-1/SHA-256). The package was already fully generic\n(bbolt-only, zero file-search-on coupling), so this is a pure imp\n[…]\nnown_good / is_known_bad predicates are unchanged.\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "refactor: consume go-hashset, retire internal/hashset (#545)",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-27T22:02:53Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "d0330176599b0d167ef4a5ada23b705187c0fc21",
"body": "Replace internal/sarif with github.com/richardwooding/go-sarif@v0.1.0 — the same\nSARIF 2.1.0 emitter extracted to its own minimal, zero-dependency module. The\npackage hardcoded the file-search-on tool identity; the library takes it as a\nsarif.Tool, so writeSARIF (cmd/file-search-on/sarif_out.go) now\n[…]\nsame driver name, schema,\nrule ids, and locations.\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "refactor: consume go-sarif, retire internal/sarif (#544)",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-27T16:07:23Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "d1772c4996840874a0d7cc13f74eaa420e90e8fb",
"body": "Now that v0.117.0 ships the --baseline flag, the self-review gate only fails on\ncomplexity new or worsened vs the PR base — no longer blocked on pre-existing\ndebt in touched files.\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "ci: enable baseline mode on the review gate (#538) (#543)",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-27T14:47:11Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "11c131092b0e3aa30703190a9103995aee44c2b4",
"body": "…ity (#542)\n\n* feat(review): baseline-aware gate — fail only on new/worsened complexity (#538)\n\nAdd ReviewConfig.BaselineOnly: when set, the complexity / cognitive gate only\nflags functions whose metric is NEW or WORSENED versus the base ref. A function\nalready over the ceiling at baseline, unchange\n[…]\n.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(review): baseline-aware gate — fail only on new/worsened complex…",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-27T14:30:42Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "14aa96a496d89eab39cc2de5c54b2c99b7a00342",
"body": "…h (#540) (#541)\n\nReplace file-search-on's in-repo tree-sitter harness with one\ntreesitter-symbols.Extract call per non-Go source file. That single parse now\nyields functions, type_names, imports, references, call_edges, method_owners,\npackage, relative_imports, exported_symbols AND per-function com\n[…]\nich all consume the ts attributes) pass unchanged.\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "refactor(content): consume treesitter-symbols for the tree-sitter pat…",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-27T14:08:36Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "7e5c10b37b9c02ed150bff767c2d95a5ff174ae8",
"body": "…ers (#539)\n\nReplace the in-repo multi-language coupling/cycles implementation with\ngithub.com/richardwooding/go-coupling@v0.1.0 (extracted in #532). buildImportGraph\nnow walks (keeping ctx/Options/Excludes/cancellation + the per-file attribute\nextraction), collects []coupling.File from the results,\n[…]\n passes unchanged against the library-backed impl.\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "refactor(search): consume go-coupling, retire internal coupling adapt…",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-27T13:25:51Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "7402e8ce65fce0d39dcea60f84e8117791b064ae",
"body": "…536)\n\nReplace the in-repo Go cyclomatic + cognitive complexity implementation with\ngithub.com/richardwooding/go-codemetrics@v0.2.0 (extracted in #530). The\nlibrary's AST-level Cyclomatic(*ast.BlockStmt) / Cognitive(*ast.FuncDecl)\nhelpers reuse extractGoSymbols' existing parse — no second parse on t\n[…]\ner cognitive path stays in-repo (tracked by #535).\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "refactor(content): consume go-codemetrics for Go complexity (#534) (#…",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-26T21:23:29Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "10d7c02dd4c43b0101e773cf20d3f0a34939d929",
"body": "…bols_go (#537)\n\n* refactor(content): decompose 3 over-threshold funcs in source_symbols_go\n\nPre-existing complexity debt surfaced by the review gate. Behaviour-preserving\ndecomposition (existing extraction tests pin functions/types/imports/refs/\nedges/complexity rows):\n\n- extractGoSymbols (cog 38 -\n[…]\n.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "refactor(content): decompose 3 over-threshold functions in source_sym…",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-26T21:16:21Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "ff7ec721b5dbf94545108a04495d04921fa4c6ac",
"body": "After the codeql-action v4 bump, the review run still warned that\nactions/checkout@v4 targets Node 20 (forced onto Node 24). v7 targets Node 24\nand matches the version used across the repo's other workflows. Also bump the\nREADME + example snippets so consumers don't inherit the warning.\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "ci: bump actions/checkout v4 -> v7 (clear Node 20 deprecation) (#529)",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-26T16:08:32Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "df8c74f2125990d9797c270df88445d9855b4eaa",
"body": "The v3 SARIF-upload action triggers two deprecation warnings in every review\nrun: \"CodeQL Action v3 will be deprecated in December 2026\" and \"Node 20 is\nbeing deprecated\" (v3 runs on Node 20). v4 is the current GA major and runs on\nNode 24, clearing both. Inputs (sarif_file, category) are unchanged.\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(action): bump codeql-action/upload-sarif v3 -> v4 (#528)",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-26T16:02:23Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "f4daa50984da0a264879f07ac9fc624c1e467b9c",
"body": "Run the repo's own Marketplace review-gate action on pull requests via\n`uses: ./`, uploading complexity / cognitive-complexity / dead-code findings\nto Code Scanning as SARIF. Uses the local action ref (not @v0.115.0, which\npredates action.yml) so the gate reflects the action on the PR branch.\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "ci: add self-review gate workflow (dogfood action.yml) (#527)",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-26T15:53:06Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "aa3ebeda8629e1b8adda2f63171128881f0e88b2",
"body": "* feat(action): add Marketplace review-gate GitHub Action\n\nComposite action wrapping `file-search-on review`: downloads the matching\nrelease binary, runs the diff-scoped review gate on the runner (the published\nOCI image can't run `review`, which shells out to git), and uploads findings\nto Code Scan\n[…]\n.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(action): Marketplace review-gate GitHub Action (#525)",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-26T15:42:19Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "f7125fbf7845ccdc2b92ecff4552b62f82c50a48",
"body": "* feat(coupling): support C/C++ via the #include graph (#521)\n\nC/C++ has no language-level module system pre-C++20 — the dependency graph IS\nthe #include graph — so coupling uses the directory-module model: node = a\nfile's directory. One adapter spans both \"c\" and \"cpp\" (a .h header detects as\n\"c\" e\n[…]\n.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(coupling): support C/C++ via the #include graph (#521) (#524)",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-26T14:56:04Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "a257706abe87e6c46bd0e8d18adbe4ae9da0d6f3",
"body": "* feat(coupling): support Ruby gems (#519)\n\nRuby has no file-level package declaration, so coupling uses the directory-\nmodule model (like JS/TS): node = a file's directory. But Ruby resolution is\ntrickier — both `require \"gem/foo\"` (load-path, relative to lib/) and\n`require_relative \"foo\"` (file-re\n[…]\n.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(coupling): support Ruby gems (#519) (#523)",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-26T14:15:02Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "f8277a1675f4b55b3a882b1366bf441c66d9f6c7",
"body": "* feat(coupling): support Perl ecosystem (#467)\n\nPerl has real `package Foo::Bar;` namespaces (::-separated) and we already\nextract its `use` imports, so it maps directly onto the existing\npackageDeclAdapter — the same declared-package model as the JVM family / PHP.\n\n- source_symbols_treesitter.go: \n[…]\n.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(coupling): support Perl ecosystem (#467) (#518)",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-26T13:54:48Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "21564a7a360d06e6fc5303e8679136bb5d6b776b",
"body": "WalkStream was cognitive 159 / cyclomatic 67 / 375 lines — the second #512\nhotspot, and goroutine + channel + multi-point-cancellation code. Pure\nbehavior-preserving extraction (every ctx.Done() check preserved verbatim),\ngated by the #337 robustness invariants plus the cancellation / symlink /\nmult\n[…]\ntesWith landed in #516; this is the last hotspot).\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "refactor(search): decompose WalkStream (#512) (#517)",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-26T12:36:42Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "0fda66ef8572f6b980bfe400165793d61b3f256b",
"body": "* refactor(celexpr): decompose BuildAttributesWith (#512)\n\nThe central attribute orchestrator was cognitive 236 / cyclomatic 104 / 495\nlines — the #512 hotspot. Pure behavior-preserving extraction (no logic or\norder change), verified by the full suite incl. the #337 robustness invariants\n(TestWalk_G\n[…]\n.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "refactor(celexpr): decompose BuildAttributesWith (#512) (#516)",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-26T12:24:20Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "2770f312fd002b253d98bcf3ebe0df5e0a9959ba",
"body": "… (#512) (#515)\n\nUnusedExports regressed to cognitive complexity 104 (cyclomatic 51) when the\n#504/#505/#511 boundary logic was added. Extract three behavior-preserving\nhelpers to flatten the deeply-nested aggregation loop:\n\n- exportedChecker: the visibility predicate (exported_symbols attr vs name\n\n[…]\nremain\ntracked there as separately-reviewed work).\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "refactor(unused_exports): extract helpers to cut cognitive complexity…",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-26T11:25:10Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "27b9c9f31c290e621f9f956b7592b724f590a9cc",
"body": "…ary (#511) (#514)\n\nFourth dogfooding false-positive class. Symbols exported solely so an external\n`foo_test` package can call them (celexpr.Levenshtein / Soundex / Ngrams /\nNgramSimilarity / PointInPolygon, …) were flagged as unexport candidates: the\n`<pkg>_test` file lives in the same directory, s\n[…]\nexempt,\nInternalOnly still flagged).\n\nCloses #511.\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(unused_exports): treat external _test package refs as cross-bound…",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-26T11:16:57Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "8396333bef7130908b5abc992074e6d41dc20e17",
"body": "* test(search): cover match_from.go projection helpers (#510)\n\nDogfooding coverage_gaps showed the Match projection helpers at 0% coverage —\nthey build the search / read_attributes wire output for whole content families.\nAdd table-driven MatchFrom tests for the science-data, font, computed-attribute\n[…]\n.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "test(search): cover match_from.go projection helpers (#510) (#513)",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-26T11:05:47Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "ff128468a8d57e2d352904eff94e24e3ef557cbb",
"body": "Third dogfooding false-positive class. test_gaps reported MCP tool handlers\n(searchHandler, etc.) as untested: a test drives them via client.CallTool(name),\nso the handler function name never appears in a *_test file. They're registered\nas values (the AddTool pattern), already captured by the #504 h\n[…]\nested function in the same file is still reported.\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(test_gaps): exclude value-registered handlers (#506) (#509)",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-25T18:45:31Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "48a3aed9c44304352669fd79145f876d72393090",
"body": "* fix(unused_exports): exempt first-party interface methods (#505)\n\nSecond dogfooding false-positive class: methods that satisfy a first-party\ninterface (e.g. the content.ContentType family — Attributes / MagicBytes /\nName / Extensions / Filenames / MatchMagic) were flagged as unexport\ncandidates wh\n[…]\n.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(unused_exports): exempt first-party interface methods (#505) (#508)",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-25T18:33:02Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "678a138772e57970cc00045204c1b852051ddbc8",
"body": "* fix(unused_exports): exempt AddTool[In,Out]-bound types (#504)\n\nRunning unused_exports on file-search-on's own MCP-server code flagged\n~100 false positives: every XxxInput / XxxOutput struct. They're only\nreferenced within internal/mcpserver, but can't be unexported because\nmcp.AddTool[In,Out] ref\n[…]\n.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(unused_exports): exempt AddTool[In,Out]-bound types (#504) (#507)",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-25T15:37:00Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "7108f37e6692e86837b2ea70bf7a2b870cdeb78c",
"body": "Add a Profiling cell to the Capabilities panel. When the server was\nstarted with --pprof, it shows an \"enabled\" pill plus quick links to the\nmounted endpoints (index / heap / goroutines / 30s CPU profile) and the\nready-to-paste `go tool pprof <url>` command; links resolve via\nnew URL(..., window.loc\n[…]\ntacked base branch\nwas deleted on the #501 merge.)\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(monitor): surface pprof profiling in the dashboard UI (#503)",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-25T13:54:36Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "cc373aa1914bc9aab3740c8266cf04e1f75a8bc1",
"body": "…endpoints (#501)\n\n* feat(profiling): integrate pprof — file-based flags + live dashboard endpoints\n\nTwo complementary profiling surfaces:\n\nPart A — root CLI flags (--cpuprofile / --memprofile / --trace) that wrap\nany subcommand via a startProfiling helper around kctx.Run(). Teardown is\nexplicit (no\n[…]\n.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(profiling): integrate pprof — file-based flags + live dashboard …",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-25T13:47:24Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "168f46729abd1fc3cb47742eede5cb8b959b947e",
"body": "…analysis (#500)\n\n* docs(skill): update file-search-on-mcp skill for 43 tools incl. code analysis\n\nThe MCP server now exposes 43 tools but the skill documented only 40.\nDocument the three new code-analysis tools and fix two drifted entries:\n\n- trace — callers + callees + optional impact closure in o\n[…]\n.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(skill): update file-search-on-mcp skill for 43 tools incl. code …",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-25T13:03:21Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "643e696b18d7a038048efdd00bc209429f3cb009",
"body": "…skip (#478) (#499)\n\n* feat(projects): bump projectdetect to v0.4.0; thread excludes + .git-skip into project walks (#478)\n\nprojectdetect v0.4.0 ships the exclusion hooks we requested\n(projectdetect#5): a SkipDir predicate + Excludes on FindOptions/\nResolveOptions, and — the headline — VCS metadata \n[…]\n.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(projects): bump projectdetect to v0.4.0; thread excludes + .git-…",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-25T12:04:30Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "69b345a8ac990933d1dc422463c91c5b472387be",
"body": "…b (#498)\n\nThe projectdetect 0.1.0 → 0.3.0 bump (#462) added 10 project-type\ndetectors (php, swift, scala-sbt, scala-mill, cmake, autotools, r, zig,\nperl, matlab) and a HasSubdirGlob indicator kind — all flow through\nautomatically (registered built-ins / YAML loader), so detect-project /\nfind-projec\n[…]\ndir_glob *.xcodeproj). No code change — docs only.\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: reflect projectdetect 0.3.0 — 28 project types + has_subdir_glo…",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-25T11:37:39Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "577f320f1a0ee1cf8f16e793ab0e0241139d6f37",
"body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/v6...v7)\n\n---\nupdated-dependenc\n[…]\nirect:production\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): Bump actions/checkout from 6 to 7 (#461)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-25T11:24:17Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0058249415cb53218df3bd44a0f849c712fa654e",
"body": "… updates (#462)\n\nBumps the minor-and-patch group with 6 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [github.com/pelletier/go-toml/v2](https://github.com/pelletier/go-toml) | `2.3.1` | `2.4.2` |\n| [github.com/richardwooding/projectdetect](https://github.com/richardwood\n[…]\nion-update:semver-minor\n dependency-group: minor-and-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): Bump the minor-and-patch group across 1 directory with 6…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-25T11:23:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c6f01b77805ec5957eb37c055494cd1a7c9b8ad1",
"body": "Pulls in the grammar-recovery fixes (v0.20.3):\n- Swift: functions whose if/while condition contains a comparison\n operator no longer collapse into an ERROR tree (re-parsed with\n synthetic parens) — more Swift functions now extract symbols /\n complexity that previously errored out.\n- C#: namespace\n[…]\nift cognitive complexity remains\ntracked in #491.)\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore(deps): bump odvcencio/gotreesitter v0.20.2 → v0.20.5 (#497)",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-25T11:14:50Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "a2a163c9bf7a03ffea678f156be4bde9e5252eca",
"body": "The review gate scored only cyclomatic complexity; cognitive complexity\n(now computed for Go + most tree-sitter languages) is a distinct, often\nbetter signal — it weights nesting, so it catches deeply-nested code a\nmodest cyclomatic count misses.\n\n- ReviewConfig.MaxCognitive (default 15): a changed-\n[…]\nsses. README / examples /\nMCP description updated.\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(review): add cognitive-complexity gate (--max-cognitive) (#496)",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-25T10:00:18Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "8737a392124d9625b0272b42d48913e9539bd84e",
"body": "…#491) (#495)\n\n* feat(complexity): cognitive complexity for Ruby/Scala/R/MATLAB/Perl (#491)\n\nEnables the tree-sitter cognitive walk for five more languages, leaving\nonly Swift unsupported (15 of 16 tree-sitter languages + Go).\n\n- Skip anonymous token nodes in the walk: Ruby names the if/while keywor\n[…]\n.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(complexity): cognitive complexity for Ruby/Scala/R/MATLAB/Perl (…",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-25T09:43:00Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "ec8d51c183e4efa2d504328e3fed16e8a96e4528",
"body": "… (#494)\n\n* feat(complexity): cognitive complexity for C/C++/C#/Kotlin/PHP (#491)\n\nEnables the tree-sitter cognitive-complexity walk for five more\nlanguages, bringing the total to 10 of 16 (plus Go).\n\nReworks `else if` detection to be parent-driven: while AT an if node,\ntag its else-branch if-child'\n[…]\n.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(complexity): cognitive complexity for C/C++/C#/Kotlin/PHP (#491)…",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-25T09:21:17Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "e6db0e57e08bf87d24261618399e6996e277be72",
"body": "…91) (#493)\n\n* feat(complexity): cognitive complexity for Python/JS/TS/Java/Rust (#491)\n\nExtends the cognitive-complexity metric (shipped precise for Go in #485)\nto the tree-sitter languages via a generic nesting-aware tree walk —\nthe counterpart to source_cognitive_go.go.\n\ninternal/content/source_c\n[…]\n.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(complexity): cognitive complexity for Python/JS/TS/Java/Rust (#4…",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-25T08:50:46Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "1fdc20f201d87bd8952b6942af00d404c0eb16f4",
"body": "…lomatic (#485) (#492)\n\n* feat(complexity): SonarSource cognitive complexity (Go) alongside cyclomatic (#485)\n\nAdds the nesting-weighted cognitive-complexity metric to the per-function\ncomplexity rows. Unlike cyclomatic complexity (flat decision-point count),\ncognitive complexity weights nested cont\n[…]\n.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(complexity): SonarSource cognitive complexity (Go) alongside cyc…",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-24T22:26:39Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "a215af6760cbd65a645fd6a9cc9b4e6721758ed8",
"body": "…84) (#490)\n\n* feat(review): diff-scoped review gate with pass/warn/fail verdict (#484)\n\nAdds a `review` command (CLI + MCP) that resolves the files changed in\nthe git diff, runs the per-file analyses scoped to them, and emits\nfindings plus an overall pass/warn/fail verdict. The exit code makes it\na\n[…]\n.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(review): diff-scoped review gate with pass/warn/fail verdict (#4…",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-24T20:35:23Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "187daeeb40576531322b2a3642960735d96b4532",
"body": "Adds two \"Under the hood\" slides (shared symbol graph + tool→algorithm\ntable) to the code-quality-tools deck, and brings the now-stale facts up\nto date:\n\n- coupling spans 7 ecosystems (Go, Rust, JVM, C#, Python, JS/TS, PHP),\n selected by build manifest — no longer Go+Rust / \"via #467\"\n- symbol extr\n[…]\nanguages via pure-Go tree-sitter\n (was an inexact \"18 …\")\n- algorithms table gains a `circular` row (Tarjan SCC, shipped in #481)\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(deck): add under-the-hood slides; refresh coupling/language facts",
"author_name": "Richard Wooding",
"author_login": null,
"committed_at": "2026-06-24T20:03:37Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "57ac98c654befbb31d7dc5b76761a6ffb2c47b1c",
"body": "…unctions (#483) (#489)\n\nCompletes SARIF 2.1.0 coverage for the analysis commands, reusing\ninternal/sarif.Write. Mapping per command:\n\n- coverage-gaps → coverage-gap rule, warning, line region (start/end)\n- unused-exports → unused-export rule, note, file-level (no region)\n- duplicate-functions \n[…]\n cycle is a node set with no single file\nlocation.\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(output): -o sarif for coverage-gaps, unused-exports, duplicate-f…",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-24T20:01:11Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "b540d51713cea831abe3055129f8c3495d3d6407",
"body": "New internal/sarif package + -o sarif on complexity / dead-code / find-matches, for GitHub Code Scanning ingest. URIs forward-slashed; write errors surfaced. Refs #483 (coverage-gaps/unused-exports/duplicate-functions are a follow-up).",
"is_bot": false,
"headline": "feat(output): SARIF 2.1.0 output for analysis commands (#488)",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-24T19:50:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b6c06d6460cfb3f8a45cfb8363290f83fac0e1b1",
"body": "Add trace <symbol> (CLI + MCP) — callers + callees in one view over a single CodeGraph build, optional --impact-depth closure. Reuses WhoCalls/Calls/Impact. From the fallow gap analysis. Closes #482.",
"is_bot": false,
"headline": "feat(codegraph): unified trace (callers + callees) (#487)",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-24T15:49:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fc55220e500390581b10f4dfad4016bbb8ed1b4e",
"body": "Detect dependency cycles (Tarjan SCC) over the shared first-party import graph extracted from coupling — multi-language (Go/Rust/JVM/C#/Python/JS-TS/PHP). CLI circular + MCP circular. Cycles render as member sets. From the fallow gap analysis. Closes #481.",
"is_bot": false,
"headline": "feat(codegraph): circular-dependency detection (#486)",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-24T15:29:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "392738c9379a1b8774372c1f49ec510cea6b30c0",
"body": "… (#479)\n\nPrune .git from every walk (CLI + MCP) via a default pattern in newExcluder, gated by Options.IncludeGitDir; walk root exempt. Opt-in --include-git / include_git on search + find-matches only. Semantic-index fingerprint also skips .git. projectdetect walk tracked in #478. Robustness nit (Watch Roots fallback) tracked in #480.",
"is_bot": false,
"headline": "feat(walk): skip .git by default in all walkers; opt-in --include-git…",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-24T14:34:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fe8bef88864446470ca5f3f52dd39ceeaabc136e",
"body": "PHP namespace coupling via packageDeclAdapter with a parameterised backslash separator; longestPackagePrefix gains a sep arg and trims a leading separator (fully-qualified \\App\\Foo). Selected by composer.json (before package.json). Verified against guzzle + Carbon. Coupling now 9 languages. Addresses Gemini review (leading-backslash FQNs). Refs #467.",
"is_bot": false,
"headline": "feat(coupling): PHP namespace support (#476)",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-24T13:06:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "de2570be8454f919692d048a59cf39f5b0a78dda",
"body": "Kotlin and Scala reuse the packageDeclAdapter (same JVM package model as Java); the adapter now matches a set of languages so one JVM adapter covers Java/Kotlin/Scala. Detection adds sbt + Mill. Verified against okio/scopt/os-lib. Refs #467.",
"is_bot": false,
"headline": "feat(coupling): Kotlin + Scala (JVM family), sbt/Mill detection (#475)",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-24T12:51:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9d2895147b9d402a423a05172a14543faf62ade8",
"body": "isCSharpRoot now also checks the root's immediate subdirectories (single ReadDir each, filename-predicate matching) so a Src/-nested solution is detected when pointing -d at the repo root. Newtonsoft.Json now graphs from its root. Addresses Gemini review (one ReadDir per dir). Refs #467.",
"is_bot": false,
"headline": "feat(coupling): detect C# solutions nested under a subdirectory (#474)",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-24T12:26:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "265065a2c9f9ad519548aa57529d82e3e7a077cc",
"body": "Capture relative imports (dots preserved) into a builder-internal relative_imports attribute and resolve them against the importing file's package, so idiomatic Python packages (flask) produce a real coupling graph instead of an empty one. Addresses Gemini review (per-file alloc removed; double-parse tracked as a follow-up). Refs #467.",
"is_bot": false,
"headline": "feat(coupling): count Python relative imports (#473)",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-24T12:12:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ca7ffda08a9260efec1b0908dd7bd9ba28ad069e",
"body": "Add JS/TS coupling at directory-module granularity (manifest: package.json/tsconfig.json; first-party = relative imports resolved to target dirs; bare specifiers external). Generalises the adapter interface's language() to a matchesLanguage() predicate. Next step of #467. Addresses Gemini review (resolve dir-vs-file via the node set, not os.Stat).",
"is_bot": false,
"headline": "feat(coupling): JS/TS directory-module support (#472)",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-24T11:41:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d058f162fbb39c7deb0384381e12e5652dff67fd",
"body": "Add Python (package) coupling via a path-deriving pythonCouplingAdapter (import root = src/ or root; first-party = packages the tree occupies; absolute imports only). Shares the longest-prefix matcher with Java/C#. Next step of #467.",
"is_bot": false,
"headline": "feat(coupling): package-level Python support (#471)",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-24T11:19:16Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "98f79b0770202e5b83f7b86ec47cf5d4c1d6419b",
"body": "Add C# (namespace) coupling, generalising the Java adapter into a reusable packageDeclAdapter. Manifest-selected (.sln/.slnx/.csproj/props); first-party = namespaces the tree declares. Next step of #467. Addresses Gemini review (glob-free root detection, .slnx).",
"is_bot": false,
"headline": "feat(coupling): package-level C# support (#470)",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-24T11:07:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e7963a275373abe56453e1f90aafa81749e59a98",
"body": "Add Java to coupling at package granularity (manifest-selected; first-party = packages the tree declares). Evolves the couplingAdapter seam to a two-pass node-set model, behaviour-preserving for Go/Rust. Next step of #467. Addresses Gemini review (longest-prefix static-import resolution).",
"is_bot": false,
"headline": "feat(coupling): package-level Java support (#469)",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-24T10:43:38Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "63009311f18ae88edeb7a9ce2c3fbc341d60a12b",
"body": "…468)\n\nRefactor coupling behind a couplingAdapter seam and add a Rust crate-level adapter (manifest-selected: go.mod -> packages, Cargo.toml -> crates). First step of #467. Addresses Gemini review (cached cwd, state reset).",
"is_bot": false,
"headline": "feat(coupling): crate-level Rust support via per-language adapters (#…",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-24T10:18:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5cfe4a04a8ebbf4ded56239cc7927bd2cb3d80ed",
"body": "Add CLI wrappers for the two MCP tools that lacked a counterpart (validate_expr, index_stats), backfill the README Subcommands table so every subcommand is documented, and add a SPAN-branded Marp deck. Addresses Gemini review (embed-error surfacing, churn-owners deck fix).",
"is_bot": false,
"headline": "feat(cli): add validate + index-stats, close CLI/MCP parity gap (#466)",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-24T07:32:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c9026ab036773e18e7573de491aae79d817b4e77",
"body": "…freeze the server (#464) (#465)\n\nThe MCP server's `--warm` flag auto-enables the watch-index background\nwatcher, which recursively registers the whole tree with fsnotify. On\nmacOS/BSD the kqueue backend opens one descriptor per watched directory\nAND per file, so an idle server on a ~4k-file repo he\n[…]\no ~4,160 bounded FDs with\n0 descriptors into .git.\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(watch): skip .git and cap descriptor budget so watch-index can't …",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-23T13:07:14Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "d922a1794a52a7e263d4c1aafc9424fa9ef559ba",
"body": "…(#463)\n\n* feat(playground): semantic search mode + scrollable attributes panel\n\nAdd an opt-in semantic-search mode to the `playground` TUI, activated by\n--embedding-model. A natural-language query box (embedded via Ollama)\nranks files by cosine `similarity`; the CEL box then filters that ranked\nsna\n[…]\n.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(playground): semantic search mode + scrollable attributes panel …",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-23T08:47:01Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "054b34bacb396b2a434cc631bdd83c029ccc90cf",
"body": "Add a `playground` subcommand: a Bubble Tea TUI that snapshots a directory\nonce and filters that snapshot live as you type a CEL expression, over the\nsame attribute vocabulary `search` uses. The match list and a per-file\nattribute panel update on every keystroke; `tab` toggles an attribute\ncheat-she\n[…]\n subcommand + recipe rows; examples/playground.md.\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(playground): interactive CEL-filtering TUI subcommand (#460)",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-20T21:27:59Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "c6c5fe8b5325ac50430c34d6292cb2e9473e418d",
"body": "…ng/projectdetect (#459)\n\ninternal/projecttype is now the standalone module\ngithub.com/richardwooding/projectdetect@v0.1.0 (extracted with history via\ngit subtree split). The 13 consumers (cmd / search / celexpr / mcpserver /\nmonitor) import the new path; internal/projecttype is deleted.\n\nCEL indica\n[…]\ne\nas before. CLAUDE.md architecture notes updated.\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "refactor: consume project-type detection from github.com/richardwoodi…",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-16T15:59:22Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "6aa12fb6f4d9fc674aa35689259725ede7063084",
"body": "…PI (#458)\n\nExported API used only by external callers is dead_code's dominant false\npositive (a library's public surface looks unused from inside the analysed\ntree) — in both the name-based and the --resolve Go path. Add an opt-in\nfilter to drop exported/public symbols (functions, methods, types).\n\n[…]\nCP\nignore_exported drops the exported seed symbol.\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(dead_code): --ignore-exported / ignore_exported to hide public A…",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-16T14:53:17Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "3b20f4f892a13a7308cf636611496d3574e3bf9d",
"body": "…) (#447) (#457)\n\nPhase 3 follow-up, reusing the goresolve engine (#456) for the remaining\nlookups. Extends goresolve with a precise call graph: every call site is\nattributed to its enclosing function and its type-resolved callee, so a\ncall through an interface is credited to the exact symbol — no s\n[…]\nveClosure, against self-contained fixture modules.\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(who_calls,impact): opt-in type-resolved Go call graph (--resolve…",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-16T13:59:34Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "c75c408ea104149752542ed46e695194a1bd6e12",
"body": "…47) (#456)\n\nPhase 3 of #443 — the precision win. dead_code's name-based matching\nunder-reports: a call to bare `Foo` keeps every same-named method alive,\nso genuinely-dead code hides behind name collisions (on this repo,\nname-based found 3 dead Go funcs; type resolution finds the real set).\n\nNew in\n[…]\nmbiguated, against self-contained fixture modules.\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(dead_code): opt-in type-resolved Go analysis via go/packages (#4…",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-16T13:18:54Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "c09d6516161b6c968de2c7cb46498cf92f3b62f1",
"body": "…es (#445) (#455)\n\nPhase 1 of #443, completing the breadth: owner qualification now spans Go\n(stdlib AST, #453/#454) plus the class-based tree-sitter languages.\n\nNew tsMethodOwners walks each method-definition node up to its enclosing\ntype container (parent-walk over the parse tree, per-language nod\n[…]\nl loudly rather than silently yielding no owners).\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(content): method-owner qualification for the tree-sitter languag…",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-16T12:33:10Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "4d1c3adeac17a7409dcc226ef2202752f3dd2528",
"body": "…erences (#445) (#454)\n\nPhase 1 of #443, continuing #453 (find_definition owners) across the rest\nof the Go lookup tools.\n\n- dead_code: SymbolDef now carries Owner (the dead symbol's owning type),\n and owner is part of the dedup identity — a dead method reports e.g.\n Owner=\"Lonely\".\n- who_calls / \n[…]\nerences report \"String is a method on:\nIndicator\".\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(codegraph): surface method owners in dead_code / who_calls / ref…",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-16T12:19:09Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "de24cfd32c7ba2fab5a7c32b45e801681a699b98",
"body": "… (#445) (#453)\n\nPhase 1 of #443 (qualified names), first slice. find_definition collapsed\nsame-named methods on different types — two `String()` methods read as\nindistinguishable rows with no hint of which type each belongs to.\n\nCapture each Go method's owning type (receiver, pointer/generic unwrap\n[…]\ndefinition String` now reports `Indicator.String`.\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(codegraph): qualify Go methods by owning type in find_definition…",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-16T11:53:13Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "79fdfbb9cfe5ca87f0c16eb2baf5199509c60d43",
"body": "…ass/constant) (#444) (#452)\n\nPhase 0 of #443. tsTypeRefQuery lacked JavaScript and Ruby, so type usages\nin those languages never counted as references — a class used only via\n`new Foo()` (JS) or a class referenced only as a superclass / constant\nreceiver (Ruby `class X < Base`, `Helper.go`) read as\n[…]\ned to TestExtractTreeSitterTypeRefs for js + ruby.\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(content): type-usage refs for JavaScript (new) and Ruby (supercl…",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-16T11:22:43Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "e6a6067b2f06ef6aa5fa686503639afbf374c969",
"body": "…x Perl method-call refs (#444) (#451)\n\nPhase 0 of #443. dead_code and test_gaps only considered definitions in\nrefExtractionLangs (9 languages); a definition in any other language was\nsilently excluded (it would always look \"dead\"). But all 16 tree-sitter\nlanguages carry a tsRefQuery — their call s\n[…]\nises a `$self->process()`\nmethod call in wantRefs.\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(codegraph): enable dead_code/test_gaps for 8 more languages + fi…",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-16T11:15:09Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "80a64f2ef808748cfc92c1ae104ebde3f10d1e1b",
"body": "…444) (#450)\n\nPhase 0 of the code-intelligence epic (#443). Guards against the class of\nsilent regression that has shipped repeatedly — C# complexity was 0 for\nevery file (#439), JS dropped CommonJS imports — by asserting, per wired\nlanguage, that a representative snippet still extracts the code-int\n[…]\nCode/OpenSource stays the manual end-to-end check.\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "test(content): cross-language symbol-extraction fidelity benchmark (#…",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-16T10:59:57Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "eb00355cf8ac3d59bbd845fc01d517e4e9229520",
"body": "Closes #441. c2pa v0.2.0 (bumped in #436) added a full pure-Go verifier\nalongside the existing unverified Read. Surface it as four opt-in attrs:\n\n c2pa_valid passed full validation (COSE sig + cert chain vs\n embedded C2PA trust list + hash bindings + RFC 3161)\n\n[…]\ncontainer; e2e confirmed the flag gates the attrs.\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(c2pa): opt-in verified C2PA attributes (--verify-c2pa) (#442)",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-16T09:41:21Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "7751ac531ce8b2ce765d84c357fff7baa1a48e0a",
"body": "Bumps the minor-and-patch group with 4 updates: [github.com/richardwooding/c2pa](https://github.com/richardwooding/c2pa), [golang.org/x/image](https://github.com/golang/image), [golang.org/x/mod](https://github.com/golang/mod) and [golang.org/x/sys](https://github.com/golang/sys).\n\n\nUpdates `github.\n[…]\nion-update:semver-minor\n dependency-group: minor-and-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): Bump the minor-and-patch group with 4 updates (#436)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-15T13:52:58Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e6aadc7eed1fd0f97c1bf38fa4c203361210db36",
"body": "…e() imports (#439)\n\nDogfooding against ~/Code/OpenSource (34 OSS projects, all 17 languages)\nsurfaced cyclomatic complexity silently returning nothing for several\ntree-sitter languages, and JS/TS missing CommonJS imports.\n\n- C#: the decision query referenced node \"for_each_statement\", but the\n gra\n[…]\nrate tree and yield 0 symbols. Tracked separately.\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(content): repair complexity for C#/PHP/Perl/R and CommonJS requir…",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-15T10:46:21Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "911c3856a3094b131564d1ddb592f679cbcb016b",
"body": "…s (#438)\n\nThe dotnet project type matched only *.csproj / *.fsproj / *.vbproj /\n*.sln. Microsoft's newer XML solution format *.slnx is a distinct suffix\n(filepath.Match(\"*.sln\", \"Foo.slnx\") is false), so it slipped through —\nand modern SDK-style repos increasingly keep only a .slnx plus\nDirectory.*\n[…]\nplus a layout regression test mirroring that root.\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(projecttype): detect .slnx solutions and modern .NET root marker…",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-15T09:51:31Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "bd4b96ef08e62e3998cbf83a8e7ddeabc6f05659",
"body": "…t hang the walk (#437)\n\nThe nightly FuzzReadMP4VideoInfo run failed with \"context deadline\nexceeded\" (no crasher written) — the signature of a single input that\nloops without progress until the 5-minute fuzztime budget expires.\n\nreadVisualSampleEntryChildren and the non-vide/non-soun fall-through i\n[…]\n execs/sec (vs\n~5k/sec while stuck) with no hangs.\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(content): bound MP4 sample-entry box loops so a size-0 child can'…",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-15T07:15:08Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "4616a730e4024ceb8f6208b0f009f907bea601d2",
"body": "…#435)\n\nThe is_source AttributeDoc in celexpr.Schema() listed only 17 of the 30\nregistered source languages — C#, PHP, Perl, R, MATLAB, Ada, SQL, Visual\nBasic, Fortran, Assembly, and Pascal were missing. This string feeds both\nthe CLI --list output and the MCP list_attributes tool, so a client using\n[…]\nlanguage without updating the\ndoc string fails CI.\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(schema): is_source doc string omitted C# and 10 other languages (…",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-15T05:15:01Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "d812fdadf8d891fb8c4c8ad79f31613840f07b5a",
"body": "Self-dogfooding with 0.101.1 (dead_code now accurate after init/main\nexclusion, value-refs, and type usages), the one genuine candidate was\nsearch.ValidGroupBys() — an exported accessor over the validGroupBys map,\nreferenced only in a doc comment, never called. Its own doc claimed it was\n\"useful for\n[…]\ne methods / test-used exports / the test fixture).\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "refactor(search): remove dead ValidGroupBys accessor (#434)",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-14T15:25:11Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "95d6bc404218e5f136bef4cb23860bc079fe30f4",
"body": "…can't hang the walk (#432) (#433)\n\nCross-language OSS dogfooding hung on real Swift: every code-graph tool\ntimed out on Alamofire. Root cause (timed) — the gotreesitter Swift grammar\nparses catastrophically slowly on certain constructs: AFError.swift (37 KB /\n874 lines) took 3m5s in pool.Parse whil\n[…]\nuite green; vet, go fix, lint clean.\n\nCloses #432.\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(content): bound tree-sitter parse time so a pathological grammar …",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-14T07:59:34Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "597cb8364544ffd0ce43b60eedbcf7e0ad23b5bd",
"body": "…is output (#430) (#431)\n\nRanked code-analysis output is easily swamped by machine-generated files\n(protobuf, oapi-codegen, mocks) — they're large + mechanically complex, so\nthey crowd out the hand-written signal. Dogfooding complexity on a real\nproject, the entire top-N was oapi.gen.go until I manu\n[…]\nnder -race; vet,\ngo fix, lint clean.\n\nCloses #430.\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(search): hint to exclude generated code when it dominates analys…",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-14T05:08:02Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "a4d9648d3064e861be973ec536e75c1d121311f0",
"body": "The cross-language rollout (#409) generalized unused_exports to 9 languages,\nbut the CLI table printer kept a Go-era early-return: when there's no go.mod\n(res.Module == \"\") it printed \"no go.mod found … resolves first-party Go\npackages only\" and returned — so for every Python / Rust / TS / Java / C#\n[…]\noverride\nheuristics).\n\nvet, lint, cmd tests clean.\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(cli): unused-exports table hid all output for non-Go projects (#429)",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-14T04:26:52Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "4cf8e366cf0661d855493563d39038f106601683",
"body": "…gation) (#409) (#428)\n\nThe default-public languages: visibility is public unless a private /\ninternal / protected modifier says otherwise, which tree-sitter can't match\npositively. So this adds the inverse — tsNonExportedQuery captures the\nNON-public defs (name + modifier text), and exported_symbol\n[…]\nptions, README,\nexamples, MCP skill (both copies).\n\nCo-authored-by: Richard Wooding <richardwooding@Richards-Virtual-Machine.local>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(content): unused_exports — add Kotlin / Scala (default-public ne…",
"author_name": "Richard Wooding",
"author_login": "richardwooding",
"committed_at": "2026-06-13T23:00:14Z",
"body_truncated": true,
"is_coding_agent": true
}
],
"releases_count": 100,
"commits_last_year": 376,
"latest_release_at": "2026-07-20T22:21:53Z",
"latest_release_tag": "v0.119.3",
"releases_from_tags": false,
"days_since_last_push": 0,
"active_weeks_last_year": 13,
"days_since_latest_release": 6,
"mean_days_between_releases": 2.7
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": true,
"health_percentage": 85,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": true
},
"ecosystem": {
"packages": [
{
"name": "github.com/richardwooding/file-search-on",
"exists": true,
"license": null,
"keywords": [],
"ecosystem": "go",
"matches_repo": true,
"registry_url": "https://pkg.go.dev/github.com/richardwooding/file-search-on",
"is_deprecated": false,
"latest_version": "v0.119.3",
"repository_url": "https://github.com/richardwooding/file-search-on",
"versions_count": 152,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": null,
"first_published_at": null,
"latest_published_at": "2026-07-20T22:15:46Z",
"latest_version_yanked": null,
"days_since_latest_publish": 6
}
]
},
"popularity": {
"forks": 1,
"stars": 5,
"watchers": 0,
"fork_history": {
"days": [
{
"date": "2026-07-27",
"count": 1
}
],
"complete": true,
"collected": 1,
"total_forks": 1
},
"star_history": null,
"open_issues_and_prs": 18
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [
"examples"
],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": true,
"bootstrap_files": [
"Makefile"
],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [],
"toolchain_manifests": [
"go.mod"
],
"largest_source_bytes": 99028,
"source_files_sampled": 591,
"oversized_source_files": 2,
"agent_instruction_files": [
"CLAUDE.md"
],
"agent_instruction_max_bytes": 18267
},
"dependencies": {
"manifests": [
"go.mod"
],
"advisories": {
"error": null,
"scope": "repository_graph",
"source": "osv",
"findings": [
{
"name": "golang.org/x/crypto",
"direct": false,
"version": "v0.53.0",
"severity": "unknown",
"ecosystem": "go",
"cvss_score": null,
"advisory_ids": [
"GO-2026-5932"
],
"fixed_version": null,
"advisory_count": 1,
"oldest_advisory_days": 19
}
],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {
"unknown": 1
},
"advisory_count": 1,
"affected_count": 1,
"assessed_count": 81,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"go"
],
"dependencies": [
{
"name": "github.com/alecthomas/kong",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.16.0"
},
{
"name": "github.com/andybalholm/brotli",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.2.2"
},
{
"name": "github.com/charmbracelet/bubbles",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.0.0"
},
{
"name": "github.com/charmbracelet/bubbletea",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.3.10"
},
{
"name": "github.com/charmbracelet/lipgloss",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.1.0"
},
{
"name": "github.com/dhowden/tag",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20240417053706-3d75831295e8"
},
{
"name": "github.com/djherbis/times",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.6.0"
},
{
"name": "github.com/evanoberholster/imagemeta",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.0.0"
},
{
"name": "github.com/fsnotify/fsnotify",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.10.1"
},
{
"name": "github.com/google/cel-go",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.29.2"
},
{
"name": "github.com/ledongthuc/pdf",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20250511090121-5959a4027728"
},
{
"name": "github.com/modelcontextprotocol/go-sdk",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.6.1"
},
{
"name": "github.com/pelletier/go-toml/v2",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v2.4.3"
},
{
"name": "github.com/richardwooding/bm25",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.1.0"
},
{
"name": "github.com/richardwooding/c2pa",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.3.0"
},
{
"name": "github.com/richardwooding/codemetrics",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.12.2"
},
{
"name": "github.com/richardwooding/fingerprint",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.1.0"
},
{
"name": "github.com/richardwooding/gitmeta",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.1.0"
},
{
"name": "github.com/richardwooding/go-coupling",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.3.1"
},
{
"name": "github.com/richardwooding/go-hashset",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.1.0"
},
{
"name": "github.com/richardwooding/go-sarif",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.1.0"
},
{
"name": "github.com/richardwooding/ollamaembed",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.1.0"
},
{
"name": "github.com/richardwooding/projectdetect",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.7.0"
},
{
"name": "github.com/richardwooding/treesitter-symbols",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.6.2"
},
{
"name": "github.com/sabhiram/go-gitignore",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20210923224102-525f6e181f06"
},
{
"name": "go.etcd.io/bbolt",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.5.0"
},
{
"name": "golang.org/x/image",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.44.0"
},
{
"name": "golang.org/x/mod",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.38.0"
},
{
"name": "golang.org/x/sys",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.47.0"
},
{
"name": "golang.org/x/tools",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.48.0"
},
{
"name": "gopkg.in/yaml.v3",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v3.0.1"
},
{
"name": "howett.net/plist",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.0.1"
},
{
"name": "modernc.org/sqlite",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.54.0"
}
],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "github.com/alecthomas/kong",
"direct": true,
"version": "v1.16.0",
"ecosystem": "go"
},
{
"name": "github.com/andybalholm/brotli",
"direct": true,
"version": "v1.2.2",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/bubbles",
"direct": true,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/bubbletea",
"direct": true,
"version": "v1.3.10",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/lipgloss",
"direct": true,
"version": "v1.1.0",
"ecosystem": "go"
},
{
"name": "github.com/dhowden/tag",
"direct": true,
"version": "v0.0.0-20240417053706-3d75831295e8",
"ecosystem": "go"
},
{
"name": "github.com/djherbis/times",
"direct": true,
"version": "v1.6.0",
"ecosystem": "go"
},
{
"name": "github.com/evanoberholster/imagemeta",
"direct": true,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/fsnotify/fsnotify",
"direct": true,
"version": "v1.10.1",
"ecosystem": "go"
},
{
"name": "github.com/google/cel-go",
"direct": true,
"version": "v0.29.2",
"ecosystem": "go"
},
{
"name": "github.com/ledongthuc/pdf",
"direct": true,
"version": "v0.0.0-20250511090121-5959a4027728",
"ecosystem": "go"
},
{
"name": "github.com/modelcontextprotocol/go-sdk",
"direct": true,
"version": "v1.6.1",
"ecosystem": "go"
},
{
"name": "github.com/pelletier/go-toml/v2",
"direct": true,
"version": "v2.4.3",
"ecosystem": "go"
},
{
"name": "github.com/richardwooding/bm25",
"direct": true,
"version": "v0.1.0",
"ecosystem": "go"
},
{
"name": "github.com/richardwooding/c2pa",
"direct": true,
"version": "v0.3.0",
"ecosystem": "go"
},
{
"name": "github.com/richardwooding/codemetrics",
"direct": true,
"version": "v0.12.2",
"ecosystem": "go"
},
{
"name": "github.com/richardwooding/fingerprint",
"direct": true,
"version": "v0.1.0",
"ecosystem": "go"
},
{
"name": "github.com/richardwooding/gitmeta",
"direct": true,
"version": "v0.1.0",
"ecosystem": "go"
},
{
"name": "github.com/richardwooding/go-coupling",
"direct": true,
"version": "v0.3.1",
"ecosystem": "go"
},
{
"name": "github.com/richardwooding/go-hashset",
"direct": true,
"version": "v0.1.0",
"ecosystem": "go"
},
{
"name": "github.com/richardwooding/go-sarif",
"direct": true,
"version": "v0.1.0",
"ecosystem": "go"
},
{
"name": "github.com/richardwooding/ollamaembed",
"direct": true,
"version": "v0.1.0",
"ecosystem": "go"
},
{
"name": "github.com/richardwooding/projectdetect",
"direct": true,
"version": "v0.7.0",
"ecosystem": "go"
},
{
"name": "github.com/richardwooding/treesitter-symbols",
"direct": true,
"version": "v0.6.2",
"ecosystem": "go"
},
{
"name": "github.com/sabhiram/go-gitignore",
"direct": true,
"version": "v0.0.0-20210923224102-525f6e181f06",
"ecosystem": "go"
},
{
"name": "go.etcd.io/bbolt",
"direct": true,
"version": "v1.5.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/image",
"direct": true,
"version": "v0.44.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/mod",
"direct": true,
"version": "v0.38.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/sys",
"direct": true,
"version": "v0.47.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/tools",
"direct": true,
"version": "v0.48.0",
"ecosystem": "go"
},
{
"name": "gopkg.in/yaml.v3",
"direct": true,
"version": "v3.0.1",
"ecosystem": "go"
},
{
"name": "howett.net/plist",
"direct": true,
"version": "v1.0.1",
"ecosystem": "go"
},
{
"name": "modernc.org/sqlite",
"direct": true,
"version": "v1.54.0",
"ecosystem": "go"
},
{
"name": "cel.dev/expr",
"direct": false,
"version": "v0.25.1",
"ecosystem": "go"
},
{
"name": "github.com/antlr4-go/antlr/v4",
"direct": false,
"version": "v4.13.1",
"ecosystem": "go"
},
{
"name": "github.com/atotto/clipboard",
"direct": false,
"version": "v0.1.4",
"ecosystem": "go"
},
{
"name": "github.com/aymanbagabas/go-osc52/v2",
"direct": false,
"version": "v2.0.1",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/colorprofile",
"direct": false,
"version": "v0.4.1",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/x/ansi",
"direct": false,
"version": "v0.11.6",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/x/cellbuf",
"direct": false,
"version": "v0.0.15",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/x/term",
"direct": false,
"version": "v0.2.2",
"ecosystem": "go"
},
{
"name": "github.com/clipperhouse/displaywidth",
"direct": false,
"version": "v0.9.0",
"ecosystem": "go"
},
{
"name": "github.com/clipperhouse/stringish",
"direct": false,
"version": "v0.1.1",
"ecosystem": "go"
},
{
"name": "github.com/clipperhouse/uax29/v2",
"direct": false,
"version": "v2.5.0",
"ecosystem": "go"
},
{
"name": "github.com/dustin/go-humanize",
"direct": false,
"version": "v1.0.1",
"ecosystem": "go"
},
{
"name": "github.com/erikgeiser/coninput",
"direct": false,
"version": "v0.0.0-20211004153227-1c3628e74d0f",
"ecosystem": "go"
},
{
"name": "github.com/fxamacker/cbor/v2",
"direct": false,
"version": "v2.9.2",
"ecosystem": "go"
},
{
"name": "github.com/google/jsonschema-go",
"direct": false,
"version": "v0.4.3",
"ecosystem": "go"
},
{
"name": "github.com/google/uuid",
"direct": false,
"version": "v1.6.0",
"ecosystem": "go"
},
{
"name": "github.com/lucasb-eyer/go-colorful",
"direct": false,
"version": "v1.3.0",
"ecosystem": "go"
},
{
"name": "github.com/mattn/go-isatty",
"direct": false,
"version": "v0.0.20",
"ecosystem": "go"
},
{
"name": "github.com/mattn/go-localereader",
"direct": false,
"version": "v0.0.1",
"ecosystem": "go"
},
{
"name": "github.com/mattn/go-runewidth",
"direct": false,
"version": "v0.0.19",
"ecosystem": "go"
},
{
"name": "github.com/muesli/ansi",
"direct": false,
"version": "v0.0.0-20230316100256-276c6243b2f6",
"ecosystem": "go"
},
{
"name": "github.com/muesli/cancelreader",
"direct": false,
"version": "v0.2.2",
"ecosystem": "go"
},
{
"name": "github.com/muesli/termenv",
"direct": false,
"version": "v0.16.0",
"ecosystem": "go"
},
{
"name": "github.com/ncruces/go-strftime",
"direct": false,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/odvcencio/gotreesitter",
"direct": false,
"version": "v0.42.0",
"ecosystem": "go"
},
{
"name": "github.com/philhofer/fwd",
"direct": false,
"version": "v1.2.0",
"ecosystem": "go"
},
{
"name": "github.com/pkg/errors",
"direct": false,
"version": "v0.9.1",
"ecosystem": "go"
},
{
"name": "github.com/remyoudompheng/bigfft",
"direct": false,
"version": "v0.0.0-20230129092748-24d4a6f8daec",
"ecosystem": "go"
},
{
"name": "github.com/rivo/uniseg",
"direct": false,
"version": "v0.4.7",
"ecosystem": "go"
},
{
"name": "github.com/segmentio/asm",
"direct": false,
"version": "v1.1.3",
"ecosystem": "go"
},
{
"name": "github.com/segmentio/encoding",
"direct": false,
"version": "v0.5.4",
"ecosystem": "go"
},
{
"name": "github.com/tinylib/msgp",
"direct": false,
"version": "v1.6.3",
"ecosystem": "go"
},
{
"name": "github.com/veraison/go-cose",
"direct": false,
"version": "v1.3.0",
"ecosystem": "go"
},
{
"name": "github.com/x448/float16",
"direct": false,
"version": "v0.8.4",
"ecosystem": "go"
},
{
"name": "github.com/xo/terminfo",
"direct": false,
"version": "v0.0.0-20220910002029-abceb7e1c41e",
"ecosystem": "go"
},
{
"name": "github.com/yosida95/uritemplate/v3",
"direct": false,
"version": "v3.0.2",
"ecosystem": "go"
},
{
"name": "go.yaml.in/yaml/v3",
"direct": false,
"version": "v3.0.4",
"ecosystem": "go"
},
{
"name": "golang.org/x/crypto",
"direct": false,
"version": "v0.53.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/exp",
"direct": false,
"version": "v0.0.0-20240823005443-9b4947da3948",
"ecosystem": "go"
},
{
"name": "golang.org/x/oauth2",
"direct": false,
"version": "v0.35.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/sync",
"direct": false,
"version": "v0.22.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/text",
"direct": false,
"version": "v0.40.0",
"ecosystem": "go"
},
{
"name": "google.golang.org/genproto/googleapis/api",
"direct": false,
"version": "v0.0.0-20240826202546-f6391c0de4c7",
"ecosystem": "go"
},
{
"name": "google.golang.org/genproto/googleapis/rpc",
"direct": false,
"version": "v0.0.0-20240826202546-f6391c0de4c7",
"ecosystem": "go"
},
{
"name": "google.golang.org/protobuf",
"direct": false,
"version": "v1.36.10",
"ecosystem": "go"
},
{
"name": "modernc.org/libc",
"direct": false,
"version": "v1.74.1",
"ecosystem": "go"
},
{
"name": "modernc.org/mathutil",
"direct": false,
"version": "v1.7.1",
"ecosystem": "go"
},
{
"name": "modernc.org/memory",
"direct": false,
"version": "v1.11.0",
"ecosystem": "go"
}
],
"collected": true,
"truncated": false,
"total_count": 81,
"direct_count": 33,
"indirect_count": 48
}
},
"maintainership": {
"issues": {
"open_prs": 1,
"merged_prs": 370,
"open_issues": 17,
"closed_ratio": 0.91,
"closed_issues": 172,
"closed_unmerged_prs": 5
},
"bus_factor": 1,
"bot_contributors": 3,
"top_contributors": [
{
"type": "User",
"login": "richardwooding",
"commits": 352,
"avatar_url": "https://avatars.githubusercontent.com/u/373901?v=4"
}
],
"contributors_sampled": 1,
"top_contributor_share": 1
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"ci.yml",
"fuzz.yml",
"gloam-sync.yml",
"pages.yml",
"release.yml",
"review.yml"
],
"has_docs_dir": true,
"linter_configs": [
".golangci.yml"
],
"has_editorconfig": true,
"has_linter_config": true,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"go.sum"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 0,
"reason": "branch protection not enabled on development/release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 10,
"reason": "24 out of 24 merged PRs checked by a CI test -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/22 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 3,
"reason": "project has 1 contributing companies or organizations -- score normalized to 3",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 10,
"reason": "project is fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 0,
"reason": "project was created within the last 90 days. Please review its contents carefully",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": 10,
"reason": "packaging workflow detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 0,
"reason": "dependency not pinned by hash detected -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 10,
"reason": "SAST tool is run on all commits",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 10,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": 0,
"reason": "Project has not signed or included provenance with any releases.",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 9,
"reason": "1 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "3699a2cbb97c4a51c19fbe11d86375e84e54dd05",
"ran_at": "2026-07-27T06:12:24Z",
"aggregate_score": 5.5,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": true,
"has_dependabot_config": true
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-27T04:51:17Z",
"oldest_open_prs": [
{
"number": 566,
"created_at": "2026-07-27T04:18:06Z",
"last_comment_at": null,
"last_comment_author": null
}
],
"last_merged_pr_at": "2026-07-20T22:12:56Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": [
{
"number": 9,
"created_at": "2026-05-03T17:41:11Z",
"last_comment_at": "2026-06-04T18:46:18Z",
"last_comment_author": "richardwooding"
},
{
"number": 70,
"created_at": "2026-05-05T16:02:42Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 169,
"created_at": "2026-05-21T21:30:46Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 203,
"created_at": "2026-05-25T12:52:14Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 227,
"created_at": "2026-05-27T14:41:53Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 228,
"created_at": "2026-05-27T14:42:11Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 229,
"created_at": "2026-05-27T14:42:29Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 231,
"created_at": "2026-05-27T15:23:19Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 232,
"created_at": "2026-05-27T15:23:30Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 234,
"created_at": "2026-05-27T15:24:00Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 440,
"created_at": "2026-06-15T10:45:35Z",
"last_comment_at": "2026-07-02T09:07:39Z",
"last_comment_author": "richardwooding"
},
{
"number": 467,
"created_at": "2026-06-24T09:47:53Z",
"last_comment_at": "2026-06-24T13:09:54Z",
"last_comment_author": "richardwooding"
},
{
"number": 477,
"created_at": "2026-06-24T13:12:36Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 480,
"created_at": "2026-06-24T14:30:31Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 526,
"created_at": "2026-06-26T15:31:43Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 533,
"created_at": "2026-06-26T16:56:48Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 552,
"created_at": "2026-07-02T09:08:48Z",
"last_comment_at": null,
"last_comment_author": null
}
]
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/richardwooding/file-search-on",
"host": "github.com",
"name": "file-search-on",
"owner": "richardwooding"
},
"metrics": {
"overall": {
"key": "overall",
"band": "moderate",
"name": "Overall health",
"note": null,
"notes": [],
"value": 67,
"inputs": {
"security": 64,
"vitality": 74,
"community": 41,
"governance": 58,
"engineering": 94
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 74,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "moderate",
"name": "Development activity",
"note": null,
"notes": [],
"value": 63,
"inputs": {
"commits_last_year": 376,
"human_commit_share": 0.89,
"days_since_last_push": 0,
"active_weeks_last_year": 13
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "13/52 weeks with commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 13
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "376 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 376
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "project was created within the last 90 days. Please review its contents carefully",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"releases_count": 100,
"latest_release_tag": "v0.119.3",
"releases_from_tags": false,
"days_since_latest_release": 6,
"mean_days_between_releases": 2.7
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "100 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 100
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 6 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 6
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~2.7 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 2.7
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "repository_too_young",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "at_risk",
"name": "Community & Adoption",
"value": 41,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "critical",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 10,
"inputs": {
"forks": 1,
"stars": 5,
"watchers": 0,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "5 stars",
"points": 9.8,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 5
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "1 forks",
"points": 0,
"status": "missed",
"details": [
{
"code": "forks",
"params": {
"count": 1
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "0 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 0
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "good",
"name": "Community health",
"note": null,
"notes": [],
"value": 77,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": true,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (MIT)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "MIT"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 18,
"status": "met",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 6.3,
"status": "met",
"details": [],
"max_points": 6.3
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "moderate",
"name": "Sustainability & Governance",
"value": 58,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 13,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 1,
"top_contributor_share": 1
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 100% of commits",
"points": 0,
"status": "missed",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 100
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "1 contributors",
"points": 1.4,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 1
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 1 contributing companies or organizations -- score normalized to 3",
"points": 3,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "good",
"name": "Issue & PR responsiveness",
"note": null,
"notes": [],
"value": 80,
"inputs": {
"merged_prs": 370,
"open_issues": 17,
"closed_issues": 172,
"issue_closed_ratio": 0.91,
"closed_unmerged_prs": 5
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "91% of issues closed",
"points": 42.5,
"status": "partial",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 91
}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "370/375 decided PRs merged",
"points": 37.7,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 370,
"decided": 375
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/22 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "moderate",
"name": "Ownership & stewardship",
"note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"verified_domain"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 57,
"inputs": {
"followers": 28,
"owner_type": "User",
"is_verified": null,
"owner_login": "richardwooding",
"public_repos": 72,
"account_age_days": 5816
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "personal (user) account",
"points": 10,
"status": "partial",
"details": [
{
"code": "owner_personal",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": "not applicable to user accounts",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_applicable_to_user_accounts",
"params": {}
}
],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "28 followers of richardwooding",
"points": 10.5,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 28,
"login": "richardwooding"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "72 public repos, account ~15 yr old",
"points": 25,
"status": "met",
"details": [
{
"code": "public_repos",
"params": {
"count": 72
}
},
{
"code": "account_age_years",
"params": {
"years": 15
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"github.com/richardwooding/file-search-on"
],
"ecosystems": "go",
"any_deprecated": false,
"min_days_since_publish": 6
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on go",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "go"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 6 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 6
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "152 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 152
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "excellent",
"name": "Engineering Quality",
"value": 94,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "excellent",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": true,
"has_linter_config": true,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "6 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 6
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": ".golangci.yml",
"points": 16,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".golangci.yml"
}
}
],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 6.4,
"status": "met",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "24 out of 24 merged PRs checked by a CI test -- score normalized to 10",
"points": 20,
"status": "met",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "excellent",
"name": "Documentation",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"topics": [
"cel",
"cli",
"content-detection",
"file-search",
"go",
"mcp",
"mcp-server"
],
"has_wiki": true,
"homepage": "https://richardwooding.github.io/file-search-on/",
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": "https://richardwooding.github.io/file-search-on/",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": "7 topics",
"points": 10,
"status": "met",
"details": [
{
"code": "topics_count",
"params": {
"count": 7
}
}
],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "moderate",
"name": "Security",
"value": 64,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "moderate",
"name": "Security posture",
"note": null,
"notes": [],
"value": 55,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 18,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 0,
"scorecard_aggregate": 5.5
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection not enabled on development/release branches",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "24 out of 24 merged PRs checked by a CI test -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/22 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 1 contributing companies or organizations -- score normalized to 3",
"points": 0.8,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is fuzzed",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "project was created within the last 90 days. Please review its contents carefully",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is run on all commits",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "1 existing vulnerabilities detected",
"points": 6.8,
"status": "partial",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "excellent",
"name": "Dependency advisories",
"note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 81 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"indirect_dependencies_free_of_known_advisories",
"no_advisories_left_outstanding"
]
}
},
{
"code": "weights_renormalized",
"params": {}
},
{
"code": "advisories_scope_repository",
"params": {
"assessed": 81
}
},
{
"code": "advisories_repo_graph_caveat",
"params": {}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 100,
"inputs": {
"source": "osv",
"advisories": 1,
"affected_packages": 1,
"assessed_packages": 81,
"unassessed_packages": 0,
"affected_by_severity": "unknown 1",
"direct_affected_packages": 0
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "no direct dependency carries a known advisory",
"points": 35,
"status": "met",
"details": [
{
"code": "no_direct_advisories",
"params": {}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "transitive set not separable from development and test dependencies in this scope",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_scope_not_separable",
"params": {}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "no advisory carries a publication date",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_no_publication_date",
"params": {}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "excellent",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 81,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 2
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "excellent",
"name": "AI Readiness",
"value": 86,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "excellent",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 85,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 1,
"agent_instruction_files": [
"CLAUDE.md"
],
"agent_instruction_max_bytes": 18267
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "CLAUDE.md",
"points": 45,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "CLAUDE.md"
}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "89 of 89 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 89,
"sampled": 89
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "excellent",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"go.sum"
],
"has_dockerfile": false,
"typed_language": true,
"bootstrap_files": [
"Makefile"
],
"has_devcontainer": false,
"has_linter_config": true,
"typecheck_configs": [],
"agent_commit_share": 0.74,
"toolchain_manifests": [
"go.mod"
],
"dependency_bot_commit_share": 0.1
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "Makefile",
"points": 18,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Makefile"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": ".golangci.yml",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".golangci.yml"
}
}
],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "Go (statically typed)",
"points": 11,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "74 of the last 100 commits agent-authored or agent-credited",
"points": 10,
"status": "met",
"details": [
{
"code": "agent_authored_commits",
"params": {
"count": 74,
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "10 of the last 100 commits are automated dependency updates",
"points": 8,
"status": "met",
"details": [
{
"code": "dependency_bot_commits",
"params": {
"count": 10,
"sampled": 100
}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"primary_language": "Go",
"largest_source_bytes": 99028,
"source_files_sampled": 591,
"oversized_source_files": 2
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Go (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "2/591 source files over 60KB",
"points": 54.8,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 591,
"oversized": 2
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "moderate",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 60,
"inputs": {
"example_dirs": [
"examples"
],
"has_mcp_signal": true,
"api_schema_files": []
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 20,
"status": "met",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": "examples",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "examples"
}
}
],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
],
"report_type": "repository",
"generated_at": "2026-07-27T06:12:42.489559Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/r/richardwooding/file-search-on.svg",
"full_name": "richardwooding/file-search-on",
"license_state": "standard",
"license_spdx": "MIT"
}