Raw JSON report machine-readable
{
"data": {
"repo": {
"topics": [],
"is_fork": false,
"size_kb": 15375,
"has_wiki": true,
"homepage": null,
"languages": {
"Go": 8092025,
"CSS": 19933,
"PHP": 70222,
"HTML": 257714,
"Shell": 7310,
"Swift": 66565,
"Kotlin": 54796,
"Python": 104262,
"Makefile": 6829,
"Dockerfile": 1990,
"JavaScript": 148244,
"PowerShell": 4965,
"TypeScript": 62072
},
"pushed_at": "2026-07-31T21:34:21Z",
"created_at": "2026-02-22T16:32:38Z",
"owner_type": "User",
"updated_at": "2026-08-01T01:45:20Z",
"description": "The cognitive database. A new class of data storage. Not a vector store, not a graph DB, not a RAG wrapper. Ebbinghaus decay, Hebbian learning, and Bayesian confidence are engine-native primitives. Memories evolve on their own. MCP-native. Single binary.",
"is_archived": false,
"is_disabled": false,
"license_spdx": null,
"default_branch": "develop",
"license_spdx_raw": "NOASSERTION",
"primary_language": "Go",
"significant_languages": [
"Go"
]
},
"owner": {
"blog": null,
"name": "Scrypster",
"type": "User",
"login": "scrypster",
"company": null,
"location": null,
"followers": 38,
"avatar_url": "https://avatars.githubusercontent.com/u/59214607?v=4",
"created_at": "2019-12-25T02:14:45Z",
"is_verified": null,
"public_repos": 7,
"account_age_days": 2410
},
"license": {
"state": "custom",
"spdx_id": null,
"raw_spdx": "NOASSERTION",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v0.9.0",
"kind": "minor",
"published_at": "2026-07-20T22:18:25Z"
},
{
"tag": "v0.8.0",
"kind": "minor",
"published_at": "2026-07-09T19:25:27Z"
},
{
"tag": "v0.7.0",
"kind": "minor",
"published_at": "2026-06-12T12:29:10Z"
},
{
"tag": "v0.6.3",
"kind": "patch",
"published_at": "2026-06-11T12:36:50Z"
},
{
"tag": "v0.6.2",
"kind": "patch",
"published_at": "2026-06-10T20:31:08Z"
},
{
"tag": "v0.6.1",
"kind": "patch",
"published_at": "2026-05-26T18:47:52Z"
},
{
"tag": "v0.6.0",
"kind": "minor",
"published_at": "2026-05-20T13:10:39Z"
},
{
"tag": "v0.5.1",
"kind": "patch",
"published_at": "2026-05-06T12:36:38Z"
},
{
"tag": "v0.5.0",
"kind": "minor",
"published_at": "2026-04-27T22:53:19Z"
},
{
"tag": "v0.4.12-alpha",
"kind": "prerelease",
"published_at": "2026-04-06T16:38:53Z"
},
{
"tag": "v0.4.11-alpha",
"kind": "prerelease",
"published_at": "2026-04-05T15:02:34Z"
},
{
"tag": "v0.4.10",
"kind": "patch",
"published_at": "2026-04-02T22:17:34Z"
},
{
"tag": "v0.4.9-alpha",
"kind": "prerelease",
"published_at": "2026-03-30T15:38:45Z"
},
{
"tag": "v0.4.8-alpha",
"kind": "prerelease",
"published_at": "2026-03-29T15:49:17Z"
},
{
"tag": "v0.4.7-alpha",
"kind": "prerelease",
"published_at": "2026-03-26T15:45:19Z"
},
{
"tag": "v0.4.6-alpha",
"kind": "prerelease",
"published_at": "2026-03-22T03:11:14Z"
},
{
"tag": "v0.4.5-alpha",
"kind": "prerelease",
"published_at": "2026-03-18T03:52:22Z"
},
{
"tag": "v0.4.4-alpha",
"kind": "prerelease",
"published_at": "2026-03-17T03:21:06Z"
},
{
"tag": "v0.4.3-alpha",
"kind": "prerelease",
"published_at": "2026-03-16T03:51:21Z"
},
{
"tag": "v0.4.2-alpha",
"kind": "prerelease",
"published_at": "2026-03-15T03:41:42Z"
},
{
"tag": "v0.4.1-alpha",
"kind": "prerelease",
"published_at": "2026-03-14T00:26:45Z"
},
{
"tag": "v0.4.0-alpha",
"kind": "prerelease",
"published_at": "2026-03-13T02:02:12Z"
},
{
"tag": "v0.3.15-alpha",
"kind": "prerelease",
"published_at": "2026-03-11T14:42:07Z"
},
{
"tag": "v0.3.14-alpha-1",
"kind": "prerelease",
"published_at": "2026-03-10T00:30:20Z"
},
{
"tag": "v0.3.14-alpha",
"kind": "prerelease",
"published_at": "2026-03-09T23:19:05Z"
},
{
"tag": "v0.3.13-alpha",
"kind": "prerelease",
"published_at": "2026-03-09T16:00:45Z"
},
{
"tag": "v0.3.12-alpha",
"kind": "prerelease",
"published_at": "2026-03-09T04:13:08Z"
},
{
"tag": "v0.3.11-alpha",
"kind": "prerelease",
"published_at": "2026-03-07T22:52:56Z"
},
{
"tag": "v0.3.10-alpha",
"kind": "prerelease",
"published_at": "2026-03-07T16:01:34Z"
},
{
"tag": "v0.3.9-alpha",
"kind": "prerelease",
"published_at": "2026-03-06T20:09:28Z"
},
{
"tag": "v0.3.8-alpha",
"kind": "prerelease",
"published_at": "2026-03-06T15:47:21Z"
},
{
"tag": "v0.3.7-alpha",
"kind": "prerelease",
"published_at": "2026-03-06T04:08:40Z"
},
{
"tag": "v0.3.6-alpha",
"kind": "prerelease",
"published_at": "2026-03-05T19:46:28Z"
},
{
"tag": "v0.3.5-alpha",
"kind": "prerelease",
"published_at": "2026-03-05T14:30:56Z"
},
{
"tag": "v0.3.4-alpha",
"kind": "prerelease",
"published_at": "2026-03-05T03:01:20Z"
},
{
"tag": "v0.3.3-alpha",
"kind": "prerelease",
"published_at": "2026-03-04T17:15:43Z"
},
{
"tag": "v0.3.2-alpha",
"kind": "prerelease",
"published_at": "2026-03-03T22:16:07Z"
},
{
"tag": "v0.3.1-alpha",
"kind": "prerelease",
"published_at": "2026-03-03T21:35:36Z"
},
{
"tag": "v0.3.0-alpha",
"kind": "prerelease",
"published_at": "2026-03-02T22:38:22Z"
},
{
"tag": "v0.2.6",
"kind": "patch",
"published_at": "2026-02-28T19:27:31Z"
},
{
"tag": "v0.2.5",
"kind": "patch",
"published_at": "2026-02-27T22:08:45Z"
},
{
"tag": "v0.2.4",
"kind": "patch",
"published_at": "2026-02-27T04:33:14Z"
},
{
"tag": "v0.2.3",
"kind": "patch",
"published_at": "2026-02-26T20:16:17Z"
},
{
"tag": "v0.2.2",
"kind": "patch",
"published_at": "2026-02-26T00:24:29Z"
},
{
"tag": "v0.2.1",
"kind": "patch",
"published_at": "2026-02-25T23:58:27Z"
},
{
"tag": "v0.2.0",
"kind": "minor",
"published_at": "2026-02-25T23:02:39Z"
},
{
"tag": "v0.1.0",
"kind": "minor",
"published_at": "2026-02-24T02:01:01Z"
}
],
"recent_commits": [
{
"oid": "e24b5dcfd3c4a756f3cfbe51f0e36f4351fd14cb",
"body": "…easured recall ceiling (#757)\n\n* fix(storage): weight exactly 1.0 round-tripped to 0 — full-confidence declarations were destroyed\n\nTHE BUG. WeightComplement computed uint32(weight * float32(math.MaxUint32)).\nfloat32(MaxUint32) rounds UP to 2^32 (4294967295 is not representable in\nfloat32), so for \n[…]\nard gap noted for a\nseparate increment), and replication coherence of the compat deletes. G6 is\nsatisfied by the two passes together.\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix: full-confidence weight destruction, evolve provenance, and the m…",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-31T21:34:21Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "88c4d9fb830f8893c8527c58ea43e25394b8d0db",
"body": "…adictions surface, and the write-effort cliff (#754)\n\n* fix(engine): consolidate archived its own survivor and destroyed the fact\n\nConsolidate writes the merged content as a new engram, then soft-deletes every\ninput id. But Write is exact-content deduplicated: when mergedContent matches an\ninput by\n[…]\nrong.\n\nFourth of its shape this week (#744 latency budget, the import-cleanup silent\ntimeout, the abstention harness determinism). Each: a timing assumption that\nreports the wrong cause when violated.",
"is_bot": false,
"headline": "fix: solid ground — consolidate data loss, inverted abstention, contr…",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-31T18:46:41Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3808189c69f4f46b4e2a6bd32ebf205c470eb34e",
"body": "…a timeout as a cleanup bug (#753)\n\nThe wait loop exited silently when its 10s deadline passed and the test then\nasserted that the orphaned vault had been cleaned up — but cleanup only runs\nonce the import job reaches StatusError. On a loaded runner the job had not\nfailed yet, so the assertion fired\n[…]\nflake found this week, after the currency latency budget\n(#744) and the abstention measurement harness. Same root shape each time: a\ntiming assumption that reports the wrong cause when it is violated.",
"is_bot": false,
"headline": "test(engine): stop TestStartImport_OrphanedVaultCleanup misreporting …",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-31T16:21:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ebdc1a12710366aa78b9de13dd99e8993fee2737",
"body": "…premise (#751)\n\nFour independent attempts to make the feature fire, each measured on real data.\nThe mechanism is refuted at its PREMISE rather than at its tuning.\n\n pass 1 does it fire? 0 fires / 37,296 candidate edges (focality\n assumed always-true; still\n[…]\nire') was stated confidently and is refuted by pass 3 — capture quality is\na precondition worth fixing on its own merits, not the lever.\n\nFiled alongside ambient push (#609) in the do-not-reopen list.",
"is_bot": false,
"headline": "docs(decision-record): associative surprise — killed, refuted at its …",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-31T13:30:47Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "887038b0d1895dcafa0243ef398555e6b5cdef6e",
"body": "* fix(cli): handle stale PID file in 'muninn stop'\n\nWhen the daemon crashed or was killed with SIGKILL without cleanup, its\nPID file was left behind pointing at a dead PID. 'muninn stop' then called\nos.FindProcess + Signal on that PID, which on Unix returns \"process already\nfinished\" (kill(2) ESRCH \n[…]\na-bot@users.noreply.github.com>\n\n---------\n\nSigned-off-by: ad-astra-bot <263242209+ad-astra-bot@users.noreply.github.com>\nCo-authored-by: ad-astra-bot <263242209+ad-astra-bot@users.noreply.github.com>",
"is_bot": false,
"headline": "fix(cli): handle stale PID file in 'muninn stop' (#650)",
"author_name": "ad-astra-bot",
"author_login": "ad-astra-bot",
"committed_at": "2026-07-31T13:20:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6f00ea1a354e9fd3d4bd6e4460e389b38b6b9460",
"body": "…es (#747)\n\nmuninn_link(relation=contradicts) applied the confidence penalty TWICE: once\ninside the ContradictWorker's OnFound callback (idempotent per pair since #746),\nand again directly and unconditionally in Link itself. The direct submit was a\nshortcut for immediacy — its comment says 'without \n[…]\nd: the worker timing makes a\nhermetic unit test for this unreliable, so the proof is the live end-to-end run\nabove plus the existing idempotency tests from #746. Full suite green, vet and\ngofmt clean.",
"is_bot": false,
"headline": "fix(engine): declaring a contradiction no longer destroys both memori…",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-31T13:05:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bc276d39b57a7d17f947951902acf270488c9b9f",
"body": "…nd by hands-on AI evaluation (#746)\n\n* fix(cognitive): make the contradiction confidence penalty idempotent per pair (partial)\n\nPARTIAL FIX — the end-to-end bug is NOT yet closed; see the measurement below.\n\nReproduced against a live server: two opposing memories linked with\nmuninn_link(relation=co\n[…]\nsary but nowhere near sufficient, and the\nearlier 'the moat is typed + entity-tagged memories' conclusion was too strong.\n\n---------\n\nCo-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix: agent-experience hardening — six silent-substitution defects fou…",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-31T12:28:53Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "4310d8ef0b6883accf72a1d9e77d02e70150ea56",
"body": "muninn_link's `relation` argument was silently coerced to relates_to when it\nwas not one of the 16 recognized names — the same silent-substitution class as\nthe memory-type downgrade fixed in #742, still live on the verb declarations\ndepend on most.\n\nrelates_to is INERT: it is the one relation with n\n[…]\nid relation\nis ever reported unknown — adding a RelType cannot create a new class of\nsilently-discarded declaration.\n\nRED-sanity checked: the tests fail to build/pass with the handler change\nreverted.",
"is_bot": false,
"headline": "fix(mcp): never silently discard an unrecognized link relation (#745)",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-31T00:43:50Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8b1c940739c48d2b6ec59a99776bfe351d159f57",
"body": "…p of entity coverage) (#743)\n\nmuninn_remember's entities[].type carried a strict 14-value JSON-Schema enum\n(added 2026-06-11). Server-side it was dead weight — normalizeEntityType coerces\nany unrecognized value to \"other\" on every user-facing write path, so the enum\nnever changed what was stored. C\n[…]\n. entity_state/_batch KEEP the enum — those correct the type of an entity\nthat already exists, so there is no capture to suppress.\n\nRED-sanity checked: both tests fail with the schema change reverted.",
"is_bot": false,
"headline": "fix(mcp): drop the entity-type enum from the write paths (it cost 64p…",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-30T23:55:12Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "728b491c6c7aa94e86440b8668fba588605890ab",
"body": "An explicit `type` argument that is not a recognized MemoryType enum name was\nsilently downgraded to TypeFact — the caller's string kept as a cosmetic\nTypeLabel, the memory filed as a plain fact, and nothing told the writer their\ntype had been discarded. That is principle #1 (\"explicit config is nev\n[…]\n is ever reported unknown — so\nadding an enum member cannot silently create a new class of swallowed write\n(principle #6).\n\nRED-sanity checked: the tests fail to build/pass without the handler change.",
"is_bot": false,
"headline": "fix(mcp): never silently swallow an unrecognized memory type (#742)",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-30T23:47:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "dc8e7b5f85a7bd8708fdf871efcd2635faaa9800",
"body": "…r noise (#744)\n\nThe budget is a complexity-blowup detector, not a performance benchmark: it\nexists to catch an accidental O(K^2)-or-worse rewrite of\napplyCurrencyAnnotation, which shows up as orders of magnitude, not percent.\nSet tight, it could only ever report on the runner.\n\nIt duly flaked, fail\n[…]\nlonger can. The failure message now says which of the two it means.\n\nAlso logs the measurement unconditionally, so slow drift stays visible in CI\nlogs while the budget itself stays deliberately loose.",
"is_bot": false,
"headline": "test(engine): stop TestCurrencyAnnotation_Latency flaking on CI runne…",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-30T23:47:07Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4fc9da8ac5fcafd0dc182808cf36568e8c8af50b",
"body": "…ile at write (#741)\n\nThe auto-surfaced MCP instructions (internal/mcp/context.go) and muninn_guide now\nprime every connecting LLM to treat the vault as living memory, not a static store:\nthe moment you write is the moment you know something, so it's the moment to\nreconcile — recall the neighborhood\n[…]\nd; coexisting variants stay). Guidance text only — no\nlogic, no regression, cleanly reversible. World-class behavior does not depend on\nany skill; the reflex ships in the universal on-connect surface.",
"is_bot": false,
"headline": "feat(guide): curator reflex — treat MuninnDB as living memory, reconc…",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-30T23:42:12Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5c111f954683587018c9b33fdd6400c4070fd4f2",
"body": "…(#740)\n\n* fix(recall): degrade LOUDLY on embedding failure (semantic_degraded)\n\nphase6Score's post-load cosine fallback swallowed GetEmbeddings errors silently\n(candidates stayed vectorScore=0, no WARN); phase1 treated an err==nil empty/all-zero\nquery vector identically to a valid one. Both now WAR\n[…]\now-up, kept out to stay a minimal\nincrement); and tighten the field doc (query-granular + coarse: set on any failure\neven if primary vector search worked; caller-supplied embeddings not zero-checked).",
"is_bot": false,
"headline": "fix(recall): degrade loudly on embedding failure (semantic_degraded) …",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-30T18:41:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6ba222063518e26f96c0dd56551b48e95c693a8b",
"body": "…d create (#739)\n\nEvolveAt queued its successor engram via batch.WriteEngram, recording provenance\nOperation:\"create\" for every muninn_evolve. Add StoreBatch.WriteEngramOp(op) so the\nverb is threaded through; EvolveAt now records \"evolve\". Plain remember/tree writes\nare genuine creates and stay \"cre\n[…]\nive, non-behavioral outside provenance.\nRED-first: TestStoreBatch_WriteEngramOp_RecordsRealOperation (failed to compile before\nthe method existed) + a non-regression pin for plain create. -race green.",
"is_bot": false,
"headline": "feat(provenance): record real write verb (evolve) instead of hardcode…",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-30T18:41:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "90a60f89ae9614ff49bc37a0c8566ad609afb272",
"body": "…OG-25) (#738)\n\n* feat(currency): recall-time advisory version-cluster (#712, COG-25) — port + COG-25 leak fix\n\nPort engine_currency.go + test onto clean origin/develop (the prior branch was\n18 commits stale and would have reverted merged work). Wire the four advisory\nannotation fields (possibly_sup\n[…]\nith anchors + all pin-test names), and a\ndrift-and-obligations row recording the MCP+MBP-only annotation surface scope so the\nfields aren't wired into proto/SDK as unpopulated (silently-wrong) schema.",
"is_bot": false,
"headline": "feat(recall): advisory version-cluster annotation — currency (#712, C…",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-30T18:41:23Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "dc3c15a04e4502a7135072585d6548bd07edca92",
"body": "… recall ranking (#713) (#735)\n\nAdds an optional per-vault ExcludeTags list (PlasticityConfig -> ResolvedPlasticity\n-> ActivateRequest). Candidates carrying an excluded tag are dropped from recall\nRANKING before scoring. Ranking-only: the engram is not deleted, not hidden from\ndirect-id or as_of-by-\n[…]\n tag overrides the standing exclude for that\nrequest (caller intent wins). Reuses the existing tag-filter extraction path\n(principle #7). Addresses near-duplicate / auto-generated-tag recall crowding.",
"is_bot": false,
"headline": "feat(recall): per-vault exclude-tags knob — drop configured tags from…",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-30T12:01:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "60ed37b1005e113cf26a0a367e0a25725957349c",
"body": "…iers (#734)\n\nReplace vault-derived test fixture names and vault-name references with\nneutral placeholders. No functional change.",
"is_bot": false,
"headline": "chore(test,docs): use neutral fixtures, remove vault-specific identif…",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-30T11:35:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b2265b69ea33c048f1d98c219f5712343582019d",
"body": "…g (#722 lessons) (#727)\n\nPromotes the multi-round CI-flake hunt from PR #722 into a permanent guide:\nthe five async sources on the write/scoring path that a test asserting on\nrecall/score/count must drain deterministically (never time.Sleep), the\nWaitGroup discipline for adding a new drain, and the\n[…]\nWires a\nstanding obligation into drift-and-obligations.md (#12) so new async workers\nget a drain seam and a table entry, and adds a one-line pointer from\nCLAUDE.md's RED-sanity-check step.\n\nRefs #722.",
"is_bot": false,
"headline": "docs(internals): test hermeticity guide — drain async before assertin…",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-29T21:10:51Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d1d88e81110900307ed74a8089ea36424ccd5601",
"body": "…dings (#714) (#722)\n\n* fix(recall): compute cosine for FTS-only candidates (semantic evidence was silently dropped)\n\nCandidates that entered the result pool only via the FTS path (ftsScore>0)\nkept vectorScore=0 for their entire life in the pipeline: phase3RRF's FTS\nloop never sets vectorScore (only\n[…]\n (previously ~1-3/50 with only the\nlog-drain half of this fix, and failing before any fix). Full package\n`-race` suite and `go build/vet -tags localassets ./...` + `gofmt -l .`\nclean.\n\nRefs #722, #22.",
"is_bot": false,
"headline": "fix(recall): restore post-load cosine — GetEngrams omits ERF v2 embed…",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-29T20:56:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3f9091d5da42f9680fd1bc138787cfe1967674ac",
"body": "…g facts to keep recall clean (#723)\n\nRepeated muninn_remember for the same evolving fact creates unlinked\nengrams with no RelSupersedes edge, so applySupersession has nothing\nto demote and every stale copy stays fully active in recall. Add\nguidance to muninn_guide, the Tips section, and the muninn_remember /\nmuninn_evolve tool descriptions so agents and bulk write pipelines\nevolve instead of re-remembering when a fact is being updated or\nre-asserted.\n\nRefs #713.",
"is_bot": false,
"headline": "docs(guide): use muninn_evolve (not repeated remember) for supersedin…",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-29T18:56:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bcb713f1e4da3768d9083c132dab3c3cf063f72d",
"body": "…e (COG-26) (#718)\n\n* feat(recall): semantic-abstention floor — baseline-rescaled cosine (COG-26)\n\nbge-small-en-v1.5 is strongly anisotropic on real text: an out-of-domain\nquery/passage pair still lands at cosine ~0.45-0.60, not ~0 (measured: 432\nnonsense-query x real-passage pairs, mu=0.450, sigma=\n[…]\nnsense query at cosine ~0.545 abstains — a failure mode\na large, lexically-overlapping battery can't see. Updated all b=0.558 pins\n(baseline_test.go, semantic_baseline_test.go, actr_test.go) to 0.520.",
"is_bot": false,
"headline": "feat(recall): semantic-abstention floor — anisotropy-calibrated cosin…",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-29T16:07:36Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fe5ebf5dc5a05ab3572ec8ebfe19c6e2c00c7e06",
"body": "…nciple #11) (#717)\n\nRecords the lesson from the reliable-colleague work: a threshold/baseline/\nvocabulary a feature needs must be derived from each vault's OWN data\n(self-calibrating, like #711's per-corpus IDF) or exposed as a per-vault\noverride — with model/cold-start defaults as hints, never fix\n[…]\nver for baking a constant into the\nproduct. Adds principle #11 to CLAUDE.md and a decision-record entry\n(semantic-abstention floor self-calibration; #712 currency held for\none-vault-specific markers).",
"is_bot": false,
"headline": "docs: calibration is per-vault and self-derived, never hardcoded (pri…",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-29T16:00:44Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ae6b626932b847d99b53f56b05e018bb382400d6",
"body": "…ersession substitutes atomically under the caller's view (#701)\n\n* fix(engine): factor the shared visibility gate; supersession substitutions become atomic and gated\n\nPost-pipeline injectors have re-opened phase-6 holes three times (#654 meta\nfilters; the #570 review rounds: trust, then lease and v\n[…]\nly.\n\nCo-authored-by: isaac-ranger <isaac-ranger@users.noreply.github.com>\n\n---------\n\nCo-authored-by: MJ Bonanno <mj@scrypster.com>\nCo-authored-by: isaac-ranger <isaac-ranger@users.noreply.github.com>",
"is_bot": false,
"headline": "fix(engine): shared visibility gate for post-pipeline injections; sup…",
"author_name": "isaac-ranger",
"author_login": "isaac-ranger",
"committed_at": "2026-07-29T14:37:57Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bd6c08f56a34bc3d80e6f8a09b3e1e52b6d36b8d",
"body": "…threshold default (#704) (#710)\n\nRecall-mode presets were a SECOND threshold decider after R1's COG-6 coerce:\ntransports stamped ACT-R-calibrated preset thresholds (semantic 0.3, recent\n0.2, deep 0.1) into the request, and the engine's vault-default recall_mode\nblock overrode the leave-0-for-rrf de\n[…]\ne overlay: recency-polluted results);\nACT-R controls byte-identical; DisableHops guard RED-verified; transport\nwire pins for MCP and REST; COG-6 amended.\n\nCo-authored-by: Cairn <cairn@strixhalo.local>",
"is_bot": false,
"headline": "fix(recall): recall-mode presets no longer bypass the rrf mode-aware …",
"author_name": "isaac-ranger",
"author_login": "isaac-ranger",
"committed_at": "2026-07-29T14:11:11Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fd9dddb633724c132312b86135402010e629a053",
"body": "…colleague #711) (#715)\n\n* fix(recall): calibrated FTS relevance replaces tanh(raw BM25) — real abstention (#711)\n\nRoot cause: full_text_relevance was math.Tanh(raw unbounded BM25) at three\nsites in internal/engine/activation/engine.go (computeComponents, computeACTR,\nthe RRF-path reporting site). R\n[…]\ny guarantees [0,1], so revert to the exact state the\nrefute verdict STANDS covered rather than change core-recall tests to\naccommodate optional insurance. Design doc from the prior commit is retained.",
"is_bot": false,
"headline": "fix(recall): calibrated FTS relevance → recall can abstain (reliable-…",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-29T13:50:22Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cdbe355a9592729d5b5d650231916ea802652b05",
"body": "…ype/different-target shape (ranking-honesty R2) (#707)\n\n* fix(contradict): stop fabricating contradictions from same-RelType/different-target writes\n\ninternal/cognitive/contradict.go's processBatch synthesized a 0.8-severity\ncontradiction for ANY two same-RelType associations from one engram to two\n[…]\nams is not reversed (BayesianUpdate not safely invertible\n without the un-persisted pre-penalty value), and why auto-cleanup of stale\n 0x0A markers is unsafe (no severity/type/provenance persisted).",
"is_bot": false,
"headline": "fix(contradict): stop fabricating contradictions from same-relation-t…",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-29T03:33:14Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "10ec9293ce36d04c1f34b22518102baac1fd3607",
"body": "…l (ranking-honesty R1) (#705)\n\n* fix(recall): make the default recall threshold mode-aware (RRF vaults were silently empty)\n\nactivateCore coerced Threshold==0 -> 0.1 on every path BEFORE\nactivation.Run() ever saw the request, making #590's mode-aware default\n(rrf -> 0.001) dead code on every produc\n[…]\n; Go sends 0 (unset). ACT-R\n users are unaffected (0 → engine coerce → 0.1, identical); rrf users now get\n 0.001.\n\nAlso: COG-18 pin citation clarified (test lives in engine_rrf_threshold_test.go).",
"is_bot": false,
"headline": "fix(recall): RRF vaults no longer return silently-empty default recal…",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-29T03:07:23Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e6c05d3a7e6236e62a4fac8dffcb101a66103a39",
"body": "…n focality (#703)\n\nNoticesForRecall computed focality from ALL recall results, including an\narmed intention's own engram — a TypeGoal engram that carries its own cue\nas a first-class entity (Intend writes the cue as an inline entity). That\nlet an intention self-satisfy its own focality two ways: (a\n[…]\norage/mcp unit+race suites green). Needs a follow-up:\neither make the fixture's genuine memories unambiguously discriminative,\nor make topIdx tie-break deterministic and load-independent.\n\nCloses #693",
"is_bot": false,
"headline": "fix(prospective): exclude an armed intention's own engram from its ow…",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-29T02:34:12Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e9cd4e19fa41c46c474cdd2a3d9b11abc4353a60",
"body": "…cores (#698) (#699)\n\n* fix(recall): deterministic tie-break in final result ordering\n\nsort.Slice orders phase6Score's final scored candidates at every scoring\nmode (RRF, CGDN, ACT-R, legacy weighted-sum), comparing only on the\n`final` score. sort.Slice is NOT a stable sort and none of these sites\nh\n[…]\ne\noutput is independent of map order. RED-checked: reverting the comparator\nmakes TestEntityBoost_TiedInjectionsDeterministic fail with the exact\n\"order changed across identical calls\" nondeterminism.",
"is_bot": false,
"headline": "fix(recall): deterministic top-N ordering — ULID tie-break at equal s…",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-29T02:10:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "af4ffff000988a6b7a2964ca28e165983f5582b4",
"body": "…697)\n\nTriggerWorker.vaultWS() reconstructed the Pebble workspace prefix used\nfor store lookups from only the 4-byte routing VaultID, zeroing bytes\n4-7. Real vault prefixes are the full 8-byte SipHash output of\nkeys.VaultPrefix, so any vault whose prefix has non-zero trailing\nbytes caused handleCogn\n[…]\nhas a\nnon-zero tail, writes an engram under it, and asserts a\nThreshold-crossed push is delivered; against the unfixed code it\nfailed because the truncated lookup key missed the metadata.\n\nCloses #692",
"is_bot": false,
"headline": "fix(trigger): carry the full 8-byte vault prefix on trigger events (#…",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-29T01:39:09Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9b81c1e5bf40196fd59a3e7543d16f8cec5cddae",
"body": "…over MCP (#694)\n\nProspective memory: memory that speaks first, without ever polling.\n\n- storage: new 0x2D armed-intention index (ProspectiveIntent; the design\n doc's 0x2C was taken by RawTagRange first). One key per (intention, cue\n entity): ArmIntention / ScanArmedForEntity / MarkIntentionFired \n[…]\nuninn_decide;\nworking-buffer focal cues; semantic (non-entity) cues; notices on\nremember_batch/where_left_off/find_by_entity; contradiction auto-clear;\ngRPC/MBP intention parity; export/clone of 0x2D.",
"is_bot": false,
"headline": "feat(prospective): THE PUSH increment 1 — armed intentions + notices …",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-29T01:19:59Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "28345a98aae4cde6fb18a00fa4e088b781e12f16",
"body": "…rd (#570 follow-up) (#691)\n\nPR #570's entity-boost injection guard fails closed when the lease read\nerrors, but had no covering test since the real store only errors on a\ngenuine read/decode failure, never a missing lease. Adds a minimal\nfault-injection seam (getLeaseForInjection, a package-level func var\ndefaulting to the real GetLease call) so a test can force a lease-read\nerror and assert the candidate is not injected.",
"is_bot": false,
"headline": "test(engine): cover entity-boost injection lease-read fail-closed gua…",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-29T00:24:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d31f58de23bfef6b8f904dd35ab6d48bd88b52d7",
"body": "…first build, vet, adversarial refute, measure, land) (#690)\n\nPersists the loop we've been running so it's repeatable in a new session without\nprompting: measure-don't-claim, defer-if-buggy, honest negative results, Tier-3\nOpus refute, non-gameable acceptance gates, contributor-PR handling, labs-vs-live\ndeploy discipline. Complements review-pr and merge-orchestration.",
"is_bot": false,
"headline": "docs(skill): add /increment — the repeatable build loop (design, RED-…",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-29T00:11:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "24f3b464da916861111b67fb228afd5a1a610d5c",
"body": "…atomic, funded, watermarked (#681)\n\n* fix(engine): carry entity links and relationships across evolve, funding the mention ledgers\n\nFixes #622. Evolve inherited Concept and Tags but wrote no 0x20/0x23 entity\nlinks and no 0x21/0x26 relationship records for the successor, so every\nevolved memory sile\n[…]\nees (protected survive,\nprunable pruned, WARN fires) instead of exact counts. 0/12 flakes after.\n\n---------\n\nCo-authored-by: Cairn <cairn@strixhalo.local>\nCo-authored-by: MJ Bonanno <mj@scrypster.com>",
"is_bot": false,
"headline": "fix(engine,storage): startup repair for evolve-stripped successors — …",
"author_name": "isaac-ranger",
"author_login": "isaac-ranger",
"committed_at": "2026-07-28T23:38:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "59f2959c6d603ae52c39335103ae54dc862b37f5",
"body": "…arried set (#680)\n\n* fix(engine): carry entity links and relationships across evolve, funding the mention ledgers\n\nFixes #622. Evolve inherited Concept and Tags but wrote no 0x20/0x23 entity\nlinks and no 0x21/0x26 relationship records for the successor, so every\nevolved memory silently vanished fro\n[…]\nions cannot pass vacuously), and the inline evolve yields the\nreplacement set only, not a merge.\n\n---------\n\nCo-authored-by: Cairn <cairn@strixhalo.local>\nCo-authored-by: MJ Bonanno <mj@scrypster.com>",
"is_bot": false,
"headline": "feat(mcp,engine): optional inline entities on evolve, replacing the c…",
"author_name": "isaac-ranger",
"author_login": "isaac-ranger",
"committed_at": "2026-07-28T22:56:14Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "dd640dc0b9ee9ed633963489dfef0321ea7274b0",
"body": "* feat(cognition): importance dimension + two-strength decay (increment 1)\n\nImportance is the caller-asserted priority axis (0-1), orthogonal to\nConfidence (truth) and AccessCount (use). Increment 1 of the two-strength\n(Bjork storage/retrieval strength) decay design.\n\nWrite path:\n- mbp.WriteRequest.\n[…]\nCT-R vs weighted_sum vs RRF)\nand must not lower fresh-memory B(M). Also deferred: gRPC proto field and\nweb-console importance display (valid-time #688 set the identical\ngRPC-proto-deferred precedent).",
"is_bot": false,
"headline": "feat(cognition): importance dimension + pruning protection (#689)",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-28T22:23:20Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ec058c53577ebc67d7c78f02fdf19ba8d164e5d9",
"body": "…tion on threshold (#570)\n\n* fix(engine): rarity-weight entity boost, cap accumulation, gate injections on threshold and meta filters, vault-local n\n\nSquash-rebase of the three reviewed commits (416bbc8, 17e4836, d9c1449)\nonto current develop, reconciling with the reflex stack (#685/#688):\n\n- applyE\n[…]\n recall,\nsilent admission via entity boost. Skipping the injection is the safe\ndegrade; a missing lease record is not an error on either path.\n\n---------\n\nCo-authored-by: Cairn <cairn@strixhalo.local>",
"is_bot": false,
"headline": "fix(engine): rarity-weight entity boost, cap accumulation, gate injec…",
"author_name": "isaac-ranger",
"author_login": "isaac-ranger",
"committed_at": "2026-07-28T22:14:44Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fb77813d8dad4ff0347a742975279c2086ff2723",
"body": "…ware recall, valid-time (#688)\n\n* feat(auth): append-only credential mode (read + create-new; no evolve/forget)\n\nAdds auth.ModeAppend: a credential that can recall and remember/remember_batch\nbut is refused any operation that modifies or deletes an existing engram\n(evolve, forget, trust, merge, lin\n[…]\n fact true for a past interval,\ninvalidated later) — real MCP usage invalidates a fact from an earlier session,\nso not_true_since > CreatedAt.\n\n-race clean (engine/storage/mcp); build/vet/gofmt clean.",
"is_bot": false,
"headline": "Land reflex stack: append-mode, tag_filter, dedup-guard, supersedes-a…",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-28T20:59:25Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8f8366bb31db898599553306f857d41b00dca3df",
"body": "…eminders, trust tiering (S0-S8) (#685)\n\n* feat(activation): tag-range index + threshold bypass for filter matches (S1)\n\nAn explicit tag filter defines the candidate SET; the relevance threshold\nonly RANKS within it. Add a RawTagRange (0x2B) index so tag_prefix range\nfilters seed candidates, and byp\n[…]\n(TestEntityBoost_BelowThresholdSeedDoesNotSpread). Interacts with #570's\n entity-boost rework, which rebases on top.\n\nFull build/vet/gofmt clean; -race green across engine/storage/mcp/auth/transport.",
"is_bot": false,
"headline": "feat(reflex): session-start orientation primitives — reinforcement, r…",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-28T13:42:15Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "02890fb6fbef2f9c53a352ea6322ecd4784160d1",
"body": "…ing the mention ledgers (#646)\n\nFixes #622. Evolve inherited Concept and Tags but wrote no 0x20/0x23 entity\nlinks and no 0x21/0x26 relationship records for the successor, so every\nevolved memory silently vanished from FindByEntity and entity scoring from\nthe moment it was evolved.\n\nEvolve now reads\n[…]\nhe predecessor returns 1 with the pair key still present. Carry tests fail on\nthe pre-fix Evolve; the conservation test also fails with funding disabled.\n\nCo-authored-by: Cairn <cairn@strixhalo.local>",
"is_bot": false,
"headline": "fix(engine): carry entity links and relationships across evolve, fund…",
"author_name": "isaac-ranger",
"author_login": "isaac-ranger",
"committed_at": "2026-07-28T13:14:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d5f36e395b1960a70db0d83c6c19866725fb7df0",
"body": "web/ has carried vitest suites for a while — time-utils, plugin-config-utils,\nand worker-status-utils arriving in #645 — that nothing ever executed. CI runs\n`npm run test:e2e` for Playwright but never plain `npm test`, so the JS unit\ncoverage was decorative. It surfaced while reviewing #645, whose n\n[…]\n drift-and-obligations.md, which had itself\ndrifted — it still described govulncheck as unpinned and flagged the Windows\nwrong-model issue, both fixed in #666, and predated the node-sdk job from #672.",
"is_bot": false,
"headline": "ci: run the web console's vitest suite (#679)",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-27T21:00:30Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ac34f54c5c3dccdb18db6f62d5860e6043c96cec",
"body": "Co-authored-by: ferkans-amir <amir.rezaei@tu-berlin.de>\nCo-authored-by: Scrypster <59214607+scrypster@users.noreply.github.com>",
"is_bot": false,
"headline": "docs: fix Title Case heading capitalization in CONTRIBUTING.md (#652)",
"author_name": "amir-rezaei",
"author_login": "amir-rezaei",
"committed_at": "2026-07-27T19:59:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4ea3771b4e26ed2949159393e1ab2072f0dc4b4f",
"body": "Evolve's successor constructor explicitly inherited Concept and Tags but never\nset MemoryType or TypeLabel. Evolve exposes no parameter for either, so they\ntook the Go zero value: MemoryType became Fact. A stored decision or procedure\nwas silently relabelled a fact, and the loss compounded at every \n[…]\nsor's Summary is empty is a regression guard against\nre-introducing the inheritance; it does not fail without the fix.\n\nFixes #653\n\nCo-authored-by: isaac-ranger <isaac-ranger@users.noreply.github.com>",
"is_bot": false,
"headline": "fix(engine): inherit MemoryType and TypeLabel across evolve (#655)",
"author_name": "isaac-ranger",
"author_login": "isaac-ranger",
"committed_at": "2026-07-27T19:25:20Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1af77be6b56fee1e932ff9a17d47ccf7f3442cf0",
"body": "… (#678)\n\nThe presets are hand-duplicated between the Go table and four separate places\nin web/ (_plasticityData, _plasticityColors, plasticityPresetDescription, and\nthe preset cards in index.html). Nothing generates one from the other and\nnothing checked them — drift-and-obligations.md tracks it as\n[…]\nr\nsites, and a preset added to the UI is reported as undefined in Go. Extraction\nfailure is a hard error rather than a silent pass, so the test cannot become\nvacuous if the web files are restructured.",
"is_bot": false,
"headline": "test(auth): pin plasticity preset names across Go and the web console…",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-27T19:06:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "89d69980b2d20c55b85a57ae751a9981b0df74a7",
"body": "…es (#677)\n\nThe live-drift list in drift-and-obligations.md flagged two wrong comments and\ntwo items that are already fixed. Verified each against the code:\n\n- middleware.go said write-only API keys \"cannot authenticate to MCP at all\".\n False: internal/mcp/server.go switches on ModeObserve/ModeWrit\n[…]\ndoc-drift entry itself are marked fixed in the\n live-drift list; the pin landed in #666.\n\nComments only — no behaviour change. Build, vet, gofmt clean; internal/auth and\ninternal/mcp pass with -race.",
"is_bot": false,
"headline": "docs: correct two stale code comments and close out fixed drift entri…",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-27T18:56:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "415179a3729ba98b77161870950de5fd002a3edf",
"body": "awaitFTS was named for a wait it did not perform: it stopped the FTS worker,\nrelied on Stop()'s drain as an implicit flush, and installed a replacement.\nThat was indirect, discarded a live worker pool 52 times per engine suite run,\nand was silently wrong until #675 — a Stop() racing worker startup s\n[…]\n.., internal/storage, internal/mcp all pass with -race.\n - Engine suite runtime is unchanged (31.2s vs ~33.8s baseline) — Flush costs\n less than tearing down and rebuilding a worker pool 52 times.",
"is_bot": false,
"headline": "refactor(fts): add Worker.Flush and make awaitFTS actually await (#676)",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-27T18:46:37Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8ac93e9bca63e717e9935aa72f1fb6baf8fd8007",
"body": "…ed (#675)\n\nWorker.Stop() is documented to \"drain the queue and shut down all worker\ngoroutines\", but it did not always drain. Stop sets `stopped` and only then\ncloses stopCh, while runLoop checked `!stopped` at the *top* of its loop:\n\n for !w.stopped.Load() {\n ... w.run() ...\n }\n\nA gor\n[…]\n with -race.\n\nThis is not test-only. Any Stop() racing worker startup could lose queued index\njobs in production — the same class of silently-wrong result the project treats\nas its worst failure mode.",
"is_bot": false,
"headline": "fix(fts): Stop() must drain the queue even before workers are schedul…",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-27T18:19:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f1fee4da908afbda477d19b3ab283a9a68a69e1c",
"body": "Every action in every workflow targeted Node 20 and was being force-run on\nNode 24 by the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24 env in ci.yml. That shim was\nadded deliberately ahead of the forced migration, but it only silenced the\nwarning in ci.yml — release.yml, publish-sdk.yml, and docker-publish.ym\n[…]\natched.\n\nThe FORCE env is removed since nothing needs it now.\n\nNote: these majors require Actions Runner >= 2.327.1. GitHub-hosted runners are\nwell past that; a self-hosted runner would need checking.",
"is_bot": false,
"headline": "ci: move GitHub Actions to their Node 24 runtimes (#674)",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-27T17:00:52Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4ebeadd429202d1d7a2caf28fe75231bce6f92b5",
"body": "…ts (#673)\n\n.gitignore listed .claude/maintainer/, .claude/skills/triage-issue/, and\n.claude/skills/review-pr/, but not .claude/skills/merge-orchestration/. That\nskill was covered only by .git/info/exclude, which is local and does not\nsurvive a fresh clone — so a re-cloned working copy would have of\n[…]\nn output and screenshots at the workspace root rather than in\nany project, but nothing enforces that from inside this repo.\n\nNo behaviour change for contributors: none of these paths exist in a clone.",
"is_bot": false,
"headline": "chore: ignore the third maintainer-private skill, and scratch artifac…",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-27T16:37:17Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "317054b57626de1bf38f2bdc7b83e8ed93d9f8b4",
"body": "* fix(sdk/node): patch transitive vite, postcss, and esbuild advisories\n\nCloses the last nine open Dependabot alerts, all of them transitive under\nvitest — sdk/node declares only typescript, vitest, and msw.\n\n vite 7.3.1 → 7.3.6 (3 high, 1 medium: path traversal in optimized-dep\n \n[…]\nhich keeps the pipeline inside its ~10 minute budget.\n\nFound while patching the sdk/node advisories in the previous commit: that\nlockfile change would otherwise have landed with no CI coverage at all.",
"is_bot": false,
"headline": "Clear the last 9 Dependabot alerts, and gate the Node SDK in CI (#672)",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-27T16:13:46Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7a23665e4e2d439044063de3ba10fc5cf1b9d317",
"body": "* build(web): migrate Tailwind v3 to v4 (#662)\n\nDependabot's tailwindcss bump (#662) broke the web build, which in turn failed\nthe Go and Windows CI jobs since both run `npm run build`. v4 is a major with a\nmigration, not a version bump: tailwindcss can no longer be used directly as a\nPostCSS plugin\n[…]\n test:e2e`, never vitest for\nweb/. Locally it made a green suite look broken, which is how real failures get\nignored.\n\nNow 2 files, 33 tests, no failures. Playwright still runs via `npm run test:e2e`.",
"is_bot": false,
"headline": "Migrate Tailwind v3 → v4, unblocking #662 (#671)",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-27T15:52:40Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "72822c0b2f2ae65b0900c9bb88a21846b53d1464",
"body": "Bumps [golang.org/x/net](https://github.com/golang/net) from 0.54.0 to 0.55.0.\n- [Commits](https://github.com/golang/net/compare/v0.54.0...v0.55.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/net\n dependency-version: 0.55.0\n dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump golang.org/x/net from 0.54.0 to 0.55.0 (#669)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-27T15:39:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a14cd1cc4b01e05d3f5f47b7082927befaedd3a2",
"body": "Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go) from 1.79.3 to 1.82.1.\n- [Release notes](https://github.com/grpc/grpc-go/releases)\n- [Commits](https://github.com/grpc/grpc-go/compare/v1.79.3...v1.82.1)\n\n---\nupdated-dependencies:\n- dependency-name: google.golang.org/grpc\n dependency-version: 1.82.1\n dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump google.golang.org/grpc from 1.79.3 to 1.82.1 (#668)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-27T15:29:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "38e08aba7b8a37e177d158747fe12a0d5ed25dc8",
"body": "Bumps [picomatch](https://github.com/micromatch/picomatch) from 4.0.3 to 4.0.5.\n- [Release notes](https://github.com/micromatch/picomatch/releases)\n- [Changelog](https://github.com/micromatch/picomatch/blob/master/CHANGELOG.md)\n- [Commits](https://github.com/micromatch/picomatch/compare/4.0.3...4.0.\n[…]\ntch\n dependency-version: 4.0.5\n dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps-dev): bump picomatch from 4.0.3 to 4.0.5 in /sdk/node (#670)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-27T15:24:03Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d337788233de6a54f314e963857940483aa43550",
"body": "Bumps [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) from 3.2.4 to 3.2.6.\n- [Release notes](https://github.com/vitest-dev/vitest/releases)\n- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)\n- [Commits](https://github.com/vitest-dev/vitest/commits\n[…]\nndency-version: 3.2.6\n dependency-type: direct:development\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps-dev): bump vitest from 3.2.4 to 3.2.6 in /sdk/node (#665)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-27T15:22:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "feab297a354fbf610332b08344765184f844e17a",
"body": "Removes [esbuild](https://github.com/evanw/esbuild). It's no longer used after updating ancestor dependencies [esbuild](https://github.com/evanw/esbuild), [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) and [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest). Thes\n[…]\ndency-version: 4.1.10\n dependency-type: direct:development\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump esbuild, vite and vitest in /web (#664)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-27T15:22:20Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c0e28610498c400abb2c039b96e96c978f061198",
"body": "Bumps [golang.org/x/crypto](https://github.com/golang/crypto) from 0.50.0 to 0.52.0.\n- [Commits](https://github.com/golang/crypto/compare/v0.50.0...v0.52.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/crypto\n dependency-version: 0.52.0\n dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump golang.org/x/crypto from 0.50.0 to 0.52.0 (#667)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-27T15:20:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "80983104d39a78ff0474737add28dcd8a29def6d",
"body": "Close three documented gaps: upgrade checksums (#600), Windows CI model drift, and drift guards that never ran",
"is_bot": false,
"headline": "Merge pull request #666 from scrypster/feat/drift-guard-hooks",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-27T15:08:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1e6adef8561068b9667fde3e6f42812a85906734",
"body": "…heck\n\nci.yml's Windows job fetched all-MiniLM-L6-v2 while release.yml ships\nbge-small-en-v1.5 for windows/amd64, so the Windows gate was green against a\nmodel no user ever runs. Both are 384-dimensional, so no dimension guard\ntripped and nothing failed. That is why it survived: the only symptom was\n[…]\nl three YAML files parse, both HuggingFace URLs resolve, and\ngolang.org/x/vuln@v1.6.0 exists on the module proxy. Every embed-asset cache\nkey across ci.yml and release.yml now names bge-small-en-v1.5.",
"is_bot": false,
"headline": "ci: test Windows against the model it actually ships, and pin govulnc…",
"author_name": "MJ Bonanno",
"author_login": "scrypster",
"committed_at": "2026-07-27T14:44:27Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "aed3aec4d25bb765a7a7d372eab69a07bd78f3a6",
"body": "`muninn upgrade` downloaded a release archive and installed it without ever\nchecking it against the `checksums.txt` that release.yml already publishes.\ninstall.sh has verified checksums all along, so the curl|sh path was covered\nand the self-update path was not.\n\nThe ordering made it worse than a mi\n[…]\ned: new tests fail without the fix (compile error), pass with it; the\ndrain test fails when the drain is removed and passes when restored; full\ncmd/muninn suite green under -race; gofmt and vet clean.",
"is_bot": false,
"headline": "fix(cli): verify release checksums before installing an upgrade (#600)",
"author_name": "MJ Bonanno",
"author_login": "scrypster",
"committed_at": "2026-07-27T14:41:58Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "22dc4620ffff23300a2bf1c0a20d76ef04bceaf5",
"body": "…e weakness map\n\nUntil now the only way to report a vulnerability was a public GitHub issue:\nno SECURITY.md, no published contact, and GitHub's private vulnerability\nreporting was disabled. Full disclosure was the default path, by construction.\n\nPrivate vulnerability reporting and Dependabot securit\n[…]\nocs in them were tracked. Both describe features\nthat shipped (association archiving, the Playwright E2E suite), so the comment\nnow says what is actually true instead of the rule quietly not applying.",
"is_bot": false,
"headline": "docs(security): add a security policy and stop signposting the privat…",
"author_name": "MJ Bonanno",
"author_login": "scrypster",
"committed_at": "2026-07-27T14:17:23Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "aa5316b5b8af75e0e04bfe5e355ec3b9295b4248",
"body": "They build ./cmd/eval-bible/... and run scripts/eval-bible-setup.sh, neither\nof which ships in the repo (cmd/eval*/ and scripts/eval-* are gitignored as\ninternal tooling). From a fresh clone all six targets fail. Advertising a\ntarget that cannot run is worse than not listing it.\n\nRestore them alongside the harness if it is ever published.",
"is_bot": false,
"headline": "build: drop the eval-bible targets from the public Makefile",
"author_name": "MJ Bonanno",
"author_login": "scrypster",
"committed_at": "2026-07-27T14:03:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e44a801a9f7e34cedae2ca86bafb574ab3d400cc",
"body": "The two .claude/hookify.*.local.md rule files had never fired. The hookify\nplugin is not installed and the repo has no settings.json, so nothing ever\nexecuted them. drift-and-obligations.md #3 cited the sdk-types file as its\nonly protection against SDK drift, which meant that obligation was unguarde\n[…]\n and would have\n missed any new handler file.\n- CLAUDE.md section 3 told you to build with `go build ./...`, contradicting\n obligation #9 and every CI step, which use `-tags localassets`. Corrected.",
"is_bot": false,
"headline": "chore(tooling): make the drift guards actually run",
"author_name": "MJ Bonanno",
"author_login": "scrypster",
"committed_at": "2026-07-27T14:03:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "df93f5d869f8a8340978a18456863bfe25f082cb",
"body": "…(#559) (#625)\n\n* feat(proto): add AdjustConfidence RPC (#559)\n\n* feat(storage): atomic UpdateConfidenceWithContradiction (#559)\n\n* feat(engine): AdjustConfidence mirrors OnFound (#559)\n\n* feat(grpc): wire AdjustConfidence RPC (#559)\n\n* fix(grpc): map storage.ErrNotFound to NotFound in AdjustConfide\n[…]\n, the\nabsolute-path analogue of the delta-path resurrection test: it fails\n~reliably under -race -count=3 without the lock and passes with it.\n\n---------\n\nCo-authored-by: MJ Bonanno <mj@scrypster.com>",
"is_bot": false,
"headline": "feat(grpc,engine): AdjustConfidence RPC with contradiction signaling …",
"author_name": "Stephen Eaton",
"author_login": "madeinoz67",
"committed_at": "2026-07-22T15:04:15Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d9bef43566d6963cdf9252a74230f4fe7296c244",
"body": "* fix(enrich): preserve transient provider failures\n\n* fix(enrich): classify content 4xx as permanent per-engram to prevent retroactive wedge (#587)\n\n---------\n\nCo-authored-by: MJ Bonanno <mj@scrypster.com>",
"is_bot": false,
"headline": "fix(enrich): preserve transient provider failures (#643)",
"author_name": "Derek Pearson",
"author_login": "dpearson2699",
"committed_at": "2026-07-22T15:03:58Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7e7652a956a21ee0cf2a7830e55a191ee38bacef",
"body": "govulncheck flagged GO-2026-5970 (infinite loop on invalid input in\ngolang.org/x/text < v0.39.0), reachable via keys.NormalizeEntityName ->\nnorm.Form.String. Bump x/text v0.36.0 -> v0.39.0 (go mod tidy pulls a\ntransitive x/sync v0.20.0 -> v0.21.0). govulncheck now reports no called\nvulnerabilities; build and storage/keys/query suites green.",
"is_bot": false,
"headline": "chore(deps): bump golang.org/x/text to v0.39.0 for GO-2026-5970 (#649)",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-22T14:54:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5df82d6cfafe6caaebe755e7c3372eb4f515f5ca",
"body": "chore: reconcile main into develop (close the changelog merge-back gap)",
"is_bot": false,
"headline": "Merge pull request #637 from scrypster/chore/reconcile-main-into-develop",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-20T22:07:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d72e89203ffe35461ded05fd932c200a6a7e3b17",
"body": "…into-develop",
"is_bot": false,
"headline": "Merge remote-tracking branch 'origin/main' into chore/reconcile-main-…",
"author_name": "MJ Bonanno",
"author_login": "scrypster",
"committed_at": "2026-07-20T21:54:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e60f5bdbd358b6b5cf385b75cb09b60815f41e7b",
"body": "- Restore the [0.8.0] section that never merged back to develop, with the\n originally-tagged wording, and remove the false entity-boost recall-flood\n entry (#569 did not make the 0.8.0 cut; PR #570 is still open) — resolves\n #602. Add the missed Google-enrichment truncation fix and file the Go 1.\n[…]\neshold (#590), DeleteEngram race (#594).\n\nNo breaking changes: verified no proto/REST/CLI/wire removals or renames since\nv0.8.0. Every entry maps to a merged PR (independently verified).\n\nCloses #602.",
"is_bot": false,
"headline": "docs(changelog): reconcile 0.8.0 and add 0.9.0 (#635)",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-20T21:52:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "979b0f742f61ff39bc1c454674dbde7bb714799a",
"body": "Post-merge Opus audits of #617 (SSE mk_ re-validation) and #618 (auth\nprefix relocation) confirmed both are safe as merged, but surfaced that\nthese merges left the source-of-truth docs stale. Correcting:\n\n- SEC-10: the mk_ SSE re-validation gap is CLOSED (#617). Both cap_ and\n mk_ cached SSE creden\n[…]\ness tests (no storageMaxPrefix).\n- 0x0C tag index: no longer dead weight, #619 wired ListByTagInRange /\n ListByTagsAllInRange as readers on the tag-scoped recall path.\n\nDocs-only. No behavior change.",
"is_bot": false,
"headline": "docs: sync internals after #617, #618, #619 merged (#633)",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-20T15:03:16Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "eb929604ec156c659f639031e4b0439f4a694abe",
"body": "…(#610) (#613)\n\nA thin client for POST /api/engrams, the online counterpart of the\noffline-only `muninn exec remember`:\n\n muninn remember --concept \"...\" (--content \"...\" | --content-file <path>)\n [--summary ...] [--tags a,b] [--entities Name:type,...]\n [--vault NAME] [--op-id KEY] \n[…]\nore defaults to a sibling file ~/.muninn/api.key with the\nsame 0600 handling rather than reusing mcp.token; the 401 hint text\nspells out the distinction.\n\nCo-authored-by: Cairn <cairn@strixhalo.local>",
"is_bot": false,
"headline": "feat(cli): `muninn remember` — store a memory via the running daemon …",
"author_name": "isaac-ranger",
"author_login": "isaac-ranger",
"committed_at": "2026-07-20T14:59:27Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d657db0021eea7a384299ea0059ae0f25b25c88e",
"body": "…d_by_entity (#616)\n\n* fix(mcp): expose stored memory type on read/recall/where_left_off/find_by_entity\n\nThe engine stores MemoryType and TypeLabel with every engram and the write\npath binds them (muninn_remember 'type'), but no MCP read surface returned\nthem: the mcp.Memory struct had no type field\n[…]\n8 enums). Verified 1:1 against the struct's json tags in both\ndirections.\n\n---------\n\nCo-authored-by: Cairn <cairn@strixhalo.local>\nCo-authored-by: Isaac Ranger <isaac-ranger@users.noreply.github.com>",
"is_bot": false,
"headline": "fix(mcp): expose stored memory type on read/recall/where_left_off/fin…",
"author_name": "isaac-ranger",
"author_login": "isaac-ranger",
"committed_at": "2026-07-20T14:59:20Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ff4a43425c24199c7bb8da64bc98492705e00930",
"body": "Adds docs/internals/review-rubric.md, the gated protocol behind the\ncode-reviewer agent, designed so a review is trustworthy regardless of\nhow strong the model running it is. Judgment is offloaded to mechanical\nevidence (compiler, race detector, RED-sanity revert-and-observe) and to\nobjective routin\n[…]\n issue it missed (a type-alias\npropagation) is now a mechanical grep in G5 so a weak model catches it\ndeterministically. Wires code-reviewer.md to follow the rubric as hard\ngates bounded by the floor.",
"is_bot": false,
"headline": "docs: add the review rubric that makes AI code review dependable (#624)",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-20T14:16:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c05b35b1e70ac55594793610e73d696b883c2ea4",
"body": "…ts (#574)\n\n* feat(storage,engine): persist per-recall surfaced sets as recall events (#573)\n\nEvery recall builds the set of surfaced engrams but discards it after\nthe Hebbian worker folds it into aggregate co-activation weights\n(hebbian.go: \"reserved for future persistence\"). That per-event set is\n\n[…]\n(now in the tree, kept in ClearVault's\nlist) and 0x29 remaining free for recall events.\n\n---------\n\nCo-authored-by: Cairn <cairn@strixhalo.local>\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(storage,engine): persist per-recall surfaced sets as recall even…",
"author_name": "isaac-ranger",
"author_login": "isaac-ranger",
"committed_at": "2026-07-20T14:10:02Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "9868c625047b5c3580ea8199ac4e2cd989022e8b",
"body": "…#607) (#619)\n\n* fix(storage): tag-index scans for tag-scoped recall (newest-first + K-way AND)\n\nTwo changes to the tag index (0x0C) so tag-filtered recall can seed\ncandidates from it instead of relying on FTS/HNSW/decay pools (#607):\n\n- ListByTagInRange now iterates newest-first (Last->Prev) so a t\n[…]\ne ULIDs from CreatedAt (as PebbleStore.WriteEngram does)\nso their tag/time index ordering matches production.\n\n---------\n\nCo-authored-by: ad-astra-bot <263242209+ad-astra-bot@users.noreply.github.com>",
"is_bot": false,
"headline": "fix(recall): seed tag-index candidates for tags_all/tags_any recall (…",
"author_name": "ad-astra-bot",
"author_login": "ad-astra-bot",
"committed_at": "2026-07-18T22:54:25Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c5465d503a33edf3a04a4511314b872307e86638",
"body": "…ation (#611) (#618)\n\n* feat(prefix): cross-package prefix registry (source of truth) (#611)\n\n* fix(auth): relocate auth prefixes 0x11–0x14 → 0x42–0x45 (#611)\n\n* refactor(storage/keys): source prefix bytes from the registry (#611)\n\n* refactor(storage): replace ALL raw prefix-byte literals with regis\n[…]\nuthKey length-collision orphan + recovery refuse-newer (#611)\n\n* fix(migrate): use exact value-length gate in isAuthKey + correct comment (#611)\n\n* style: gofmt prefix.go + migrate.go (CI gate) (#611)",
"is_bot": false,
"headline": "fix(storage/auth): relocate auth prefixes + prefix registry + v3 migr…",
"author_name": "Stephen Eaton",
"author_login": "madeinoz67",
"committed_at": "2026-07-18T22:53:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b8b273df49efef6024080df5fb7b355f7c7acb69",
"body": "…val (RFC #597 inc 3) (#617)\n\n* test(mcp): cover workflow-vault 'already exists' rejection (#614)\n\nfakeEngine.VaultNameExists becomes map-backed (nil-safe) so the handler's\nexistence-guard branch is reachable from tests; new\nTestCreateWorkflowVault_RejectsExistingVault asserts the -32602 rejection.\n\n[…]\ns connect-once vault binding). Removes the\ndead code + its tests; PRESERVES the 6 TestResolveVault_* tests and the live\nmcpSessionHeader constant. Revival (if ever needed) is preserved in git history.",
"is_bot": false,
"headline": "fix(mcp): SSE mk_ re-validation + vault-exists test + session.go remo…",
"author_name": "Stephen Eaton",
"author_login": "madeinoz67",
"committed_at": "2026-07-18T22:51:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "30d1c527e1f59f703495b924e07b07776c2f43d6",
"body": "…in prune, repair small orphan sets on load (#620) (#621)\n\nTwo-part fix for incrementally-inserted nodes accumulating zero in-edges\nand becoming permanently unreachable (recall silently misses them while\nFTS and status stay green):\n\n* Insert: pruneNeighbors now always retains the just-appended edge.\n[…]\nn-disk orphan set that must come back reachable —\nincluding on a second load (repair persistence).\n\nCo-authored-by: Cairn <cairn@strixhalo.local>\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(hnsw): keep late inserts reachable — protect the fresh back-edge …",
"author_name": "isaac-ranger",
"author_login": "isaac-ranger",
"committed_at": "2026-07-18T22:45:34Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "839682b5ad9caeb1e1ed66ed0120cf9024da34bd",
"body": "…w agent (#623)\n\nAdds a repo-resident guardrail layer so contributions stay grounded in\nMuninnDB's core principles and invariants as the project grows.\n\n- CLAUDE.md — the constitution: what MuninnDB is, the core principles\n (each traced to the PR/issue that established it), the verify-don't-assume\n\n[…]\ne review; an independent\nadversarial pass corrected one wrong invariant (the ACT-R content gate is\nweight-driven, defaults 0.35/0.25 — not a fixed constant) and hardened the\nreview agent's guardrails.",
"is_bot": false,
"headline": "docs: add AI-agent working guide, internals reference, and code-revie…",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-18T22:11:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d7c4a4aa2c66e2933643519926227cad9a15b3bb",
"body": "…tion header override (#588) (#604)\n\n* feat(mcp): toolset profiles for tools/list — trim per-session schema overhead (#588)\n\nThe MCP transport advertises all 39 tools on every tools/list: ~41KB of\nschema (~10.3k tokens) loaded into every bounded-context MCP client at\nconnect, used or not. In our dep\n[…]\n@anthropic.com>\n\n---------\n\nCo-authored-by: Cairn <cairn@strixhalo.local>\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>\nCo-authored-by: Scrypster <59214607+scrypster@users.noreply.github.com>",
"is_bot": false,
"headline": "feat(mcp): toolset profiles for tools/list — env default + per-connec…",
"author_name": "isaac-ranger",
"author_login": "isaac-ranger",
"committed_at": "2026-07-16T17:41:28Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "ccefd53dc8ea9341b4142752bafe0bac42e2aac1",
"body": "…) (#612)\n\n* feat(auth): add cap_ capability credential primitive (RFC #597)\n\nMirrors APIKey/keys_store.go with new Pebble prefixes 0x15/0x16.\nCapabilities are scoped (vault+mode), revocable, and require an ExpiresAt\n(bounded lifetime). Distinct credential type from mk_ keys — the foundation\nfor mun\n[…]\nlt tool legitimately returns -32001 'agent vault creation\ndisabled' under the smoke daemon's static-token + opt-in-off setup. Switch to\nmcpToolNoFail and assert the expected opt-in-disabled rejection.",
"is_bot": false,
"headline": "feat(mcp): capability tokens + muninn_create_workflow_vault (RFC #597…",
"author_name": "Stephen Eaton",
"author_login": "madeinoz67",
"committed_at": "2026-07-16T14:34:30Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4b09b33202adfd9faa90f751d917b451d1d571da",
"body": "… Scoring in UI (#590)\n\nmuninndb-8h7: Run() now applies a mode-appropriate default threshold only\non the no-threshold path (RRF=0.001, ACT-R=0.05) and never tramples an\nexplicit user value. Adds a 'Search Scoring' (scoring_fusion) card selector\nto the vault Plasticity panel, wired through loadPlasti\n[…]\nity/\nonPlasticityPresetChange.\n\nCo-authored-by: Awesome <awesome@ai.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>\nCo-authored-by: Scrypster <59214607+scrypster@users.noreply.github.com>",
"is_bot": false,
"headline": "fix(activation): preserve explicit threshold under RRF; expose Search…",
"author_name": "jiessie",
"author_login": "gitssie",
"committed_at": "2026-07-15T02:27:13Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "29faa922b8194430e6ec2713d66039f37a8c80b2",
"body": "… (#594)\n\nDeleteEngram did not take the per-engram casLocks stripe lock that\nCompareAndSet holds across its read-compare-write. A concurrent CAS\ncould read the engram, DeleteEngram could commit its delete batch, and\nthe CAS's later UpdateMetadata/putLease would then land after the delete\n— resurrect\n[…]\na -race resurrection-invariant test.\n\nFixes #586\n\nCo-authored-by: ad-astra-bot <263242209+ad-astra-bot@users.noreply.github.com>\nCo-authored-by: Scrypster <59214607+scrypster@users.noreply.github.com>",
"is_bot": false,
"headline": "fix(storage): serialize DeleteEngram with CompareAndSet's stripe lock…",
"author_name": "ad-astra-bot",
"author_login": "ad-astra-bot",
"committed_at": "2026-07-15T02:27:10Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a455c6f423388fdc1b9d4c7fba5292700aa6f503",
"body": "…l bge-small-en-v1.5 (#601) (#603)\n\nThe four darwin/linux matrix cache_key literals in release.yml and the\nfour linux job keys in ci.yml still said 'minilm-v2', but 'make\nfetch-model' has cached bge-small-en-v1.5 under those keys since the\nmodel swap; release.yml's Windows job already uses the corre\n[…]\nthe adjacent\ncomment), and ci.yml's Windows key, whose job genuinely downloads\nall-MiniLM-L6-v2 so its label matches its bytes.\n\nCo-authored-by: Scrypster <59214607+scrypster@users.noreply.github.com>",
"is_bot": false,
"headline": "ci: rename embed-asset cache keys from stale 'minilm-v2' to the actua…",
"author_name": "Johannes Hauer",
"author_login": "johanneshauer",
"committed_at": "2026-07-15T02:17:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "922b71ae95e5ba3f3e3f141585dab5f898b18323",
"body": "* feat(auth): add working plasticity preset (RFC #597)\n\nDefault-derived cognition (Hebbian + PAS on) with RetentionDays:7 so a\nshared workflow vault auto-evaporates via the existing 60s pruner, and\nBehaviorMode:selective for transient-vault guidance. Purely additive;\nValidPlasticityPreset auto-accep\n[…]\nulti_user pairing, consistent with docs/auth.md. Previously the bullet\nmentioned 'shared workflow scratch vaults' generically; now it explicitly\ndirects operators to pair with multi_user per RFC #597.",
"is_bot": false,
"headline": "feat(auth): add working plasticity preset (RFC #597) (#599)",
"author_name": "Stephen Eaton",
"author_login": "madeinoz67",
"committed_at": "2026-07-15T01:58:35Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e7f4ee5f59d020af35f7f5bf3164f4a677de5f45",
"body": "All CI green. Merging via admin — self-review not permitted for the author's own PR.",
"is_bot": false,
"headline": "Merge pull request #593 from scrypster/chore/stamp-v0.8.0",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-09T19:22:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bdf52a7176d12403b98a5796c53720d4473a743c",
"body": null,
"is_bot": false,
"headline": "docs(changelog): stamp v0.8.0 release",
"author_name": "MJ Bonanno",
"author_login": "scrypster",
"committed_at": "2026-07-09T19:15:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0f67ae4ce682eceee3598053ef092a9009b219e7",
"body": "All CI green on develop HEAD. Merging via admin — self-review not permitted for the author's own PR.",
"is_bot": false,
"headline": "Merge pull request #592 from scrypster/develop",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-09T19:13:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "58df2652d8f12ed425acafd6b90f39f81c5da3a9",
"body": "All CI checks pass, including Vulnerability scan (confirms GO-2026-5856 fix). Merging via admin — self-review not permitted for the author's own PR.",
"is_bot": false,
"headline": "chore(deps): bump Go toolchain to 1.26.5 (#591)",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-09T19:05:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "639f45b5c532e9806c50d9b1c7df447c2a302f58",
"body": "…model (#583) (#589)\n\nVerified both features are correct, safe, and well-tested. Merging.",
"is_bot": false,
"headline": "feat(embed): vault dimension guard (#582) + user-supplied local ONNX …",
"author_name": "Johannes Hauer",
"author_login": "johanneshauer",
"committed_at": "2026-07-09T18:48:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "31da86e72fbe204cd6cbdfbf071ca9c54b5e439e",
"body": "… (#579)\n\nVerified fix is correct and complete, no regressions (see review). Merging via admin — self-review not permitted by GitHub since this is the author's own PR.",
"is_bot": false,
"headline": "fix(web): reset advanced plasticity overrides when panel is collapsed…",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-09T18:48:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2f7347657e210b8557fbbe04cb728f3de51ca262",
"body": "… semantics) (#576)\n\nVerified the two lease-cleanup fixes and re-ran the full suite + race detector on the concurrency-sensitive tests in an isolated worktree — all clean, rebased on develop. Merging.",
"is_bot": false,
"headline": "feat: atomic compare-and-set + ownership lease on engrams (work-queue…",
"author_name": "ad-astra-bot",
"author_login": "ad-astra-bot",
"committed_at": "2026-07-09T18:32:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e17df99010939bba26b0e0f8df574b5a572ff651",
"body": "parseSubcommand joins any two non-flag words (exec read -> exec:read), but\nmain.go's switch only matched bare exec/logs, so every documented two-word\nform of exec and logs died as Unknown command. cluster: already had the\nprefix route; exec: and logs: now match the same pattern. Regression cases\nadd\n[…]\nstore drill (board #1486).\n\nCo-authored-by: Cairn <cairn@strixhalo.local>\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>\nCo-authored-by: Scrypster <59214607+scrypster@users.noreply.github.com>",
"is_bot": false,
"headline": "fix(cli): route joined exec:/logs: tokens to their handlers (#580)",
"author_name": "isaac-ranger",
"author_login": "isaac-ranger",
"committed_at": "2026-07-04T01:37:22Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "1e0e251be5788fc1bd9a15cc7844b4c746e03476",
"body": "#572 (fixing #571) added a fuzzy fallback to muninn_find_by_entity that\nresolves token-level variants of a known entity name (dropped/added\narticles, split/joined words). Its match gate was \"shares at least one\nnon-stopword token with the query\" — permissive enough that a query\nsharing only one toke\n[…]\ne #572 fixed,\nand rejects coincidental single-token overlap on otherwise unrelated\nnames. Jaccard ranking and the lexicographic tie-break are unchanged.\n\nFixes the gap identified during #572's review.",
"is_bot": false,
"headline": "fix(engine): tighten fuzzy entity match to token-set containment (#581)",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-04T01:13:16Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9980f6a922ad01848db17f693c1b49c0ce8cc546",
"body": "…igured provider (#585)\n\nIssue #582: when plugin_config.json names a specific embed provider (e.g.\nollama) and that provider is unreachable at boot, buildEmbedder silently\nfell through to the bundled 384-dim bge-small-en-v1.5 local ONNX model\ninstead of the safe noop (\"semantic similarity disabled\")\n[…]\na real\nlocal-ONNX init; full end-to-end behavior (a real bge-small-en-v1.5\ninit that must not happen) is covered by CI, which builds and tests\nwith -tags localassets and real model assets.\n\nFixes #582",
"is_bot": false,
"headline": "fix(embed): never substitute a different model for an explicitly conf…",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-04T01:12:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ddefabd35ace164a3a8fcee10f6ed6b68f2c59de",
"body": "…only language coverage (#584)\n\nThree docs still named the pre-#455 model (all-MiniLM-L6-v2); the actual\nbundled model has been bge-small-en-v1.5 since the label fix shipped in\nv0.6.3. Correct the name in plugins.md, quickstart.md, and self-hosting.md,\nand add a 'Language Coverage' section documenti\n[…]\nsents on non-English vaults, a\nfive-minute self-test, and how to switch to a multilingual external provider\n(including the reembed requirement).\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(embed): correct the bundled model name and document its English-…",
"author_name": "Johannes Hauer",
"author_login": "johanneshauer",
"committed_at": "2026-07-04T00:29:18Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "b82af1a933abaeec040f1ffe7c061fc1d14b176a",
"body": "…okup (#571) (#572)\n\nfind_by_entity resolves through the entity name hash (NFKC + trim +\nlowercase + SipHash), so any token-level variant of a known entity\nreturns zero results: `knock` misses `The Knock`, `dream-cycle` misses\n`dream cycle`, `TokenArcade` misses `Token Arcade`. A hash index cannot\na\n[…]\nn_0168DVnQZuH6WNWXqxxjweq2\n\nCo-authored-by: Cairn <cairn@strixhalo.local>\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>\nCo-authored-by: Scrypster <59214607+scrypster@users.noreply.github.com>",
"is_bot": false,
"headline": "feat(engine,mcp): fuzzy entity resolve behind exact find_by_entity lo…",
"author_name": "isaac-ranger",
"author_login": "isaac-ranger",
"committed_at": "2026-07-03T21:19:09Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "3474687be654b4a62d3f006dcc642140a0f1012f",
"body": "…32602 messages (#578)\n\nWhen the embedding backend returns connection refused or times out, phase1()\npreviously returned an error that aborted the entire recall. Sessions saw zero\nresults instead of the FTS+decay results that are always available. Fix: log a\nwarning and return the query without an e\n[…]\nthat 'content' must be a non-empty string.\n\nFixes #577\n\nCo-authored-by: schurabot <263242209+schurabot@users.noreply.github.com>\nCo-authored-by: Scrypster <59214607+scrypster@users.noreply.github.com>",
"is_bot": false,
"headline": "fix(recall): BM25 fallback when embed backend unreachable + precise -…",
"author_name": "schurabot",
"author_login": "ad-astra-bot",
"committed_at": "2026-07-03T20:47:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bf57ac9b0fa5a6b567046d140b8aafb4531fef5d",
"body": "… (#575)\n\nAll guidance surfaces (initialize instructions, muninn_guide, tool\ndescriptions, recall hints) steer clients to muninn_where_left_off at\nsession start. Right for a single-user vault; wrong for a vault shared\nby multiple users or agents, where where_left_off/muninn_session return\nvault-glob\n[…]\nw\nmulti_user). The panel merges the loaded raw config into the payload.\n\nDocs: feature-reference + auth tables, openapi PlasticityConfig schema.\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(vault): multi_user setting — shared-vault session-start guidance…",
"author_name": "Johannes Hauer",
"author_login": "johanneshauer",
"committed_at": "2026-07-03T20:27:57Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "423dceb838a52781aa7cc01894e110b76fe66a7c",
"body": "test(storage): fix flaky TestWALSyncer_SyncCountAccurate with onSync hook",
"is_bot": false,
"headline": "Merge pull request #568 from scrypster/fix/wal-syncer-flaky-test",
"author_name": "Scrypster",
"author_login": "scrypster",
"committed_at": "2026-07-01T18:35:32Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 47,
"commits_last_year": 1035,
"latest_release_at": "2026-07-20T22:18:25Z",
"latest_release_tag": "v0.9.0",
"releases_from_tags": false,
"days_since_last_push": 0,
"active_weeks_last_year": 21,
"days_since_latest_release": 11,
"mean_days_between_releases": 11.7
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": true,
"health_percentage": 85,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": true
},
"ecosystem": {
"packages": [
{
"name": "github.com/scrypster/muninndb",
"exists": true,
"license": null,
"keywords": [],
"ecosystem": "go",
"matches_repo": true,
"registry_url": "https://pkg.go.dev/github.com/scrypster/muninndb",
"is_deprecated": false,
"latest_version": "v0.9.0",
"repository_url": "https://github.com/scrypster/muninndb",
"versions_count": 47,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": null,
"first_published_at": null,
"latest_published_at": "2026-07-20T22:15:02Z",
"latest_version_yanked": null,
"days_since_latest_publish": 11
}
]
},
"popularity": {
"forks": 75,
"stars": 318,
"watchers": 12,
"fork_history": {
"days": [
{
"date": "2026-03-03",
"count": 3
},
{
"date": "2026-03-04",
"count": 8
},
{
"date": "2026-03-05",
"count": 12
},
{
"date": "2026-03-06",
"count": 7
},
{
"date": "2026-03-07",
"count": 5
},
{
"date": "2026-03-08",
"count": 4
},
{
"date": "2026-03-09",
"count": 1
},
{
"date": "2026-03-11",
"count": 2
},
{
"date": "2026-03-12",
"count": 1
},
{
"date": "2026-03-14",
"count": 2
},
{
"date": "2026-03-17",
"count": 1
},
{
"date": "2026-03-21",
"count": 1
},
{
"date": "2026-03-24",
"count": 4
},
{
"date": "2026-03-28",
"count": 3
},
{
"date": "2026-03-30",
"count": 1
},
{
"date": "2026-04-02",
"count": 1
},
{
"date": "2026-04-05",
"count": 1
},
{
"date": "2026-04-06",
"count": 1
},
{
"date": "2026-04-13",
"count": 2
},
{
"date": "2026-04-21",
"count": 1
},
{
"date": "2026-04-30",
"count": 1
},
{
"date": "2026-05-06",
"count": 1
},
{
"date": "2026-05-23",
"count": 1
},
{
"date": "2026-05-24",
"count": 1
},
{
"date": "2026-05-25",
"count": 1
},
{
"date": "2026-05-27",
"count": 1
},
{
"date": "2026-05-29",
"count": 1
},
{
"date": "2026-05-31",
"count": 1
},
{
"date": "2026-06-29",
"count": 1
},
{
"date": "2026-07-10",
"count": 1
},
{
"date": "2026-07-23",
"count": 1
},
{
"date": "2026-07-30",
"count": 1
},
{
"date": "2026-07-31",
"count": 1
}
],
"complete": true,
"collected": 74,
"total_forks": 75
},
"star_history": null,
"open_issues_and_prs": 78
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [
"examples"
],
"has_llms_txt": false,
"has_dockerfile": true,
"has_mcp_signal": false,
"bootstrap_files": [
"Makefile"
],
"api_schema_files": [
"internal/transport/rest/openapi.yaml",
"proto/muninn/v1/service.proto"
],
"has_devcontainer": false,
"typecheck_configs": [
"sdk/node/tsconfig.json"
],
"toolchain_manifests": [
"go.mod",
"sdk/go/muninn/go.mod",
"sdk/kotlin/build.gradle.kts"
],
"largest_source_bytes": 178827,
"source_files_sampled": 894,
"oversized_source_files": 13,
"agent_instruction_files": [
"CLAUDE.md"
],
"agent_instruction_max_bytes": 10233
},
"dependencies": {
"manifests": [
"go.mod",
"web/package.json"
],
"advisories": {
"error": null,
"scope": "repository_graph",
"source": "osv",
"findings": [
{
"name": "github.com/klauspost/compress",
"direct": true,
"version": "v1.16.0",
"severity": "unknown",
"ecosystem": "go",
"cvss_score": null,
"advisory_ids": [
"GO-2026-5841"
],
"fixed_version": "1.18.7",
"advisory_count": 1,
"oldest_advisory_days": 4
},
{
"name": "golang.org/x/crypto",
"direct": true,
"version": "v0.52.0",
"severity": "unknown",
"ecosystem": "go",
"cvss_score": null,
"advisory_ids": [
"GO-2026-5932"
],
"fixed_version": null,
"advisory_count": 1,
"oldest_advisory_days": 24
},
{
"name": "golang.org/x/net",
"direct": false,
"version": "v0.55.0",
"severity": "unknown",
"ecosystem": "go",
"cvss_score": null,
"advisory_ids": [
"GO-2026-5942"
],
"fixed_version": "0.56.0",
"advisory_count": 1,
"oldest_advisory_days": 17
}
],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {
"unknown": 3
},
"advisory_count": 3,
"affected_count": 3,
"assessed_count": 329,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 10,
"direct_affected_count": 2
},
"ecosystems": [
"go",
"npm"
],
"dependencies": [
{
"name": "github.com/bits-and-blooms/bloom/v3",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v3.7.1"
},
{
"name": "github.com/cockroachdb/pebble",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.1.5"
},
{
"name": "github.com/dchest/siphash",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.2.3"
},
{
"name": "github.com/google/uuid",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.6.0"
},
{
"name": "github.com/hashicorp/golang-lru/v2",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v2.0.7"
},
{
"name": "github.com/klauspost/compress",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.16.0"
},
{
"name": "github.com/kljensen/snowball",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.10.0"
},
{
"name": "github.com/oklog/ulid/v2",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v2.1.1"
},
{
"name": "github.com/pelletier/go-toml/v2",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v2.2.4"
},
{
"name": "github.com/prometheus/client_golang",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.15.0"
},
{
"name": "github.com/stretchr/testify",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.10.0"
},
{
"name": "github.com/sugarme/tokenizer",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.3.0"
},
{
"name": "github.com/vmihailenco/msgpack/v5",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v5.4.1"
},
{
"name": "github.com/yalue/onnxruntime_go",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.26.0"
},
{
"name": "golang.org/x/crypto",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.52.0"
},
{
"name": "golang.org/x/sync",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.21.0"
},
{
"name": "golang.org/x/sys",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.45.0"
},
{
"name": "golang.org/x/term",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.43.0"
},
{
"name": "golang.org/x/text",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.39.0"
},
{
"name": "golang.org/x/time",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.3.0"
},
{
"name": "google.golang.org/grpc",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.82.1"
},
{
"name": "gopkg.in/yaml.v3",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v3.0.1"
}
],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "github.com/bits-and-blooms/bloom/v3",
"direct": true,
"version": "v3.7.1",
"ecosystem": "go"
},
{
"name": "github.com/cockroachdb/pebble",
"direct": true,
"version": "v1.1.5",
"ecosystem": "go"
},
{
"name": "github.com/dchest/siphash",
"direct": true,
"version": "v1.2.3",
"ecosystem": "go"
},
{
"name": "github.com/google/uuid",
"direct": true,
"version": "v1.6.0",
"ecosystem": "go"
},
{
"name": "github.com/hashicorp/golang-lru/v2",
"direct": true,
"version": "v2.0.7",
"ecosystem": "go"
},
{
"name": "github.com/klauspost/compress",
"direct": true,
"version": "v1.16.0",
"ecosystem": "go"
},
{
"name": "github.com/kljensen/snowball",
"direct": true,
"version": "v0.10.0",
"ecosystem": "go"
},
{
"name": "github.com/oklog/ulid/v2",
"direct": true,
"version": "v2.1.1",
"ecosystem": "go"
},
{
"name": "github.com/pelletier/go-toml/v2",
"direct": true,
"version": "v2.2.4",
"ecosystem": "go"
},
{
"name": "github.com/prometheus/client_golang",
"direct": true,
"version": "v1.15.0",
"ecosystem": "go"
},
{
"name": "github.com/stretchr/testify",
"direct": true,
"version": "v1.10.0",
"ecosystem": "go"
},
{
"name": "github.com/sugarme/tokenizer",
"direct": true,
"version": "v0.3.0",
"ecosystem": "go"
},
{
"name": "github.com/vmihailenco/msgpack/v5",
"direct": true,
"version": "v5.4.1",
"ecosystem": "go"
},
{
"name": "github.com/yalue/onnxruntime_go",
"direct": true,
"version": "v1.26.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/crypto",
"direct": true,
"version": "v0.52.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/sync",
"direct": true,
"version": "v0.21.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/sys",
"direct": true,
"version": "v0.45.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/term",
"direct": true,
"version": "v0.43.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/text",
"direct": true,
"version": "v0.39.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/time",
"direct": true,
"version": "v0.3.0",
"ecosystem": "go"
},
{
"name": "google.golang.org/grpc",
"direct": true,
"version": "v1.82.1",
"ecosystem": "go"
},
{
"name": "gopkg.in/yaml.v3",
"direct": true,
"version": "v3.0.1",
"ecosystem": "go"
},
{
"name": "github.com/beorn7/perks",
"direct": false,
"version": "v1.0.1",
"ecosystem": "go"
},
{
"name": "github.com/bits-and-blooms/bitset",
"direct": false,
"version": "v1.24.2",
"ecosystem": "go"
},
{
"name": "github.com/cespare/xxhash/v2",
"direct": false,
"version": "v2.3.0",
"ecosystem": "go"
},
{
"name": "github.com/cockroachdb/errors",
"direct": false,
"version": "v1.11.3",
"ecosystem": "go"
},
{
"name": "github.com/cockroachdb/fifo",
"direct": false,
"version": "v0.0.0-20240606204812-0bbfbd93a7ce",
"ecosystem": "go"
},
{
"name": "github.com/cockroachdb/logtags",
"direct": false,
"version": "v0.0.0-20230118201751-21c54148d20b",
"ecosystem": "go"
},
{
"name": "github.com/cockroachdb/redact",
"direct": false,
"version": "v1.1.5",
"ecosystem": "go"
},
{
"name": "github.com/cockroachdb/tokenbucket",
"direct": false,
"version": "v0.0.0-20230807174530-cc333fc44b06",
"ecosystem": "go"
},
{
"name": "github.com/datadog/zstd",
"direct": false,
"version": "v1.4.5",
"ecosystem": "go"
},
{
"name": "github.com/davecgh/go-spew",
"direct": false,
"version": "v1.1.1",
"ecosystem": "go"
},
{
"name": "github.com/emirpasic/gods",
"direct": false,
"version": "v1.18.1",
"ecosystem": "go"
},
{
"name": "github.com/getsentry/sentry-go",
"direct": false,
"version": "v0.27.0",
"ecosystem": "go"
},
{
"name": "github.com/gogo/protobuf",
"direct": false,
"version": "v1.3.2",
"ecosystem": "go"
},
{
"name": "github.com/golang/protobuf",
"direct": false,
"version": "v1.5.4",
"ecosystem": "go"
},
{
"name": "github.com/golang/snappy",
"direct": false,
"version": "v0.0.4",
"ecosystem": "go"
},
{
"name": "github.com/kr/pretty",
"direct": false,
"version": "v0.3.1",
"ecosystem": "go"
},
{
"name": "github.com/kr/text",
"direct": false,
"version": "v0.2.0",
"ecosystem": "go"
},
{
"name": "github.com/matttproud/golang_protobuf_extensions",
"direct": false,
"version": "v1.0.4",
"ecosystem": "go"
},
{
"name": "github.com/mitchellh/colorstring",
"direct": false,
"version": "v0.0.0-20190213212951-d06e56a500db",
"ecosystem": "go"
},
{
"name": "github.com/patrickmn/go-cache",
"direct": false,
"version": "v2.1.0+incompatible",
"ecosystem": "go"
},
{
"name": "github.com/pkg/errors",
"direct": false,
"version": "v0.9.1",
"ecosystem": "go"
},
{
"name": "github.com/pmezard/go-difflib",
"direct": false,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/prometheus/client_model",
"direct": false,
"version": "v0.3.0",
"ecosystem": "go"
},
{
"name": "github.com/prometheus/common",
"direct": false,
"version": "v0.42.0",
"ecosystem": "go"
},
{
"name": "github.com/prometheus/procfs",
"direct": false,
"version": "v0.9.0",
"ecosystem": "go"
},
{
"name": "github.com/rivo/uniseg",
"direct": false,
"version": "v0.4.7",
"ecosystem": "go"
},
{
"name": "github.com/rogpeppe/go-internal",
"direct": false,
"version": "v1.9.0",
"ecosystem": "go"
},
{
"name": "github.com/schollz/progressbar/v2",
"direct": false,
"version": "v2.15.0",
"ecosystem": "go"
},
{
"name": "github.com/sugarme/regexpset",
"direct": false,
"version": "v0.0.0-20200920021344-4d4ec8eaf93c",
"ecosystem": "go"
},
{
"name": "github.com/vmihailenco/tagparser/v2",
"direct": false,
"version": "v2.0.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/exp",
"direct": false,
"version": "v0.0.0-20230626212559-97b1e661b5df",
"ecosystem": "go"
},
{
"name": "golang.org/x/net",
"direct": false,
"version": "v0.55.0",
"ecosystem": "go"
},
{
"name": "google.golang.org/genproto/googleapis/rpc",
"direct": false,
"version": "v0.0.0-20260414002931-afd174a4e478",
"ecosystem": "go"
},
{
"name": "google.golang.org/protobuf",
"direct": false,
"version": "v1.36.11",
"ecosystem": "go"
},
{
"name": "@alloc/quick-lru",
"direct": false,
"version": "5.2.0",
"ecosystem": "npm"
},
{
"name": "@emnapi/core",
"direct": false,
"version": "1.11.1",
"ecosystem": "npm"
},
{
"name": "@emnapi/runtime",
"direct": false,
"version": "1.11.1",
"ecosystem": "npm"
},
{
"name": "@emnapi/wasi-threads",
"direct": false,
"version": "1.2.2",
"ecosystem": "npm"
},
{
"name": "@esbuild/aix-ppc64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/android-arm",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/android-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/android-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/darwin-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/darwin-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/freebsd-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/freebsd-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-arm",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-ia32",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-loong64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-mips64el",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-ppc64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-riscv64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-s390x",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/netbsd-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/netbsd-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/openbsd-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/openbsd-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/openharmony-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/sunos-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/win32-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/win32-ia32",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/win32-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@inquirer/ansi",
"direct": false,
"version": "1.0.2",
"ecosystem": "npm"
},
{
"name": "@inquirer/confirm",
"direct": false,
"version": "5.1.21",
"ecosystem": "npm"
},
{
"name": "@inquirer/core",
"direct": false,
"version": "10.3.2",
"ecosystem": "npm"
},
{
"name": "@inquirer/figures",
"direct": false,
"version": "1.0.15",
"ecosystem": "npm"
},
{
"name": "@inquirer/type",
"direct": false,
"version": "3.0.10",
"ecosystem": "npm"
},
{
"name": "@jridgewell/gen-mapping",
"direct": false,
"version": "0.3.13",
"ecosystem": "npm"
},
{
"name": "@jridgewell/remapping",
"direct": false,
"version": "2.3.5",
"ecosystem": "npm"
},
{
"name": "@jridgewell/resolve-uri",
"direct": false,
"version": "3.1.2",
"ecosystem": "npm"
},
{
"name": "@jridgewell/sourcemap-codec",
"direct": false,
"version": "1.5.5",
"ecosystem": "npm"
},
{
"name": "@jridgewell/trace-mapping",
"direct": false,
"version": "0.3.31",
"ecosystem": "npm"
},
{
"name": "@mswjs/interceptors",
"direct": false,
"version": "0.41.3",
"ecosystem": "npm"
},
{
"name": "@napi-rs/wasm-runtime",
"direct": false,
"version": "1.1.6",
"ecosystem": "npm"
},
{
"name": "@open-draft/deferred-promise",
"direct": false,
"version": "2.2.0",
"ecosystem": "npm"
},
{
"name": "@open-draft/logger",
"direct": false,
"version": "0.3.0",
"ecosystem": "npm"
},
{
"name": "@open-draft/until",
"direct": false,
"version": "2.1.0",
"ecosystem": "npm"
},
{
"name": "@oxc-project/types",
"direct": false,
"version": "0.139.0",
"ecosystem": "npm"
},
{
"name": "@playwright/test",
"direct": false,
"version": "1.58.2",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-android-arm64",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-darwin-arm64",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-darwin-x64",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-freebsd-x64",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-linux-arm-gnueabihf",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-linux-arm64-gnu",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-linux-arm64-musl",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-linux-ppc64-gnu",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-linux-s390x-gnu",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-linux-x64-gnu",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-linux-x64-musl",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-openharmony-arm64",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-wasm32-wasi",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-win32-arm64-msvc",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-win32-x64-msvc",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@rolldown/pluginutils",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-android-arm-eabi",
"direct": false,
"version": "4.59.0",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-android-arm64",
"direct": false,
"version": "4.59.0",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-darwin-arm64",
"direct": false,
"version": "4.59.0",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-darwin-x64",
"direct": false,
"version": "4.59.0",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-freebsd-arm64",
"direct": false,
"version": "4.59.0",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-freebsd-x64",
"direct": false,
"version": "4.59.0",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-linux-arm-gnueabihf",
"direct": false,
"version": "4.59.0",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-linux-arm-musleabihf",
"direct": false,
"version": "4.59.0",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-linux-arm64-gnu",
"direct": false,
"version": "4.59.0",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-linux-arm64-musl",
"direct": false,
"version": "4.59.0",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-linux-loong64-gnu",
"direct": false,
"version": "4.59.0",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-linux-loong64-musl",
"direct": false,
"version": "4.59.0",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-linux-ppc64-gnu",
"direct": false,
"version": "4.59.0",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-linux-ppc64-musl",
"direct": false,
"version": "4.59.0",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-linux-riscv64-gnu",
"direct": false,
"version": "4.59.0",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-linux-riscv64-musl",
"direct": false,
"version": "4.59.0",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-linux-s390x-gnu",
"direct": false,
"version": "4.59.0",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-linux-x64-gnu",
"direct": false,
"version": "4.59.0",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-linux-x64-musl",
"direct": false,
"version": "4.59.0",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-openbsd-x64",
"direct": false,
"version": "4.59.0",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-openharmony-arm64",
"direct": false,
"version": "4.59.0",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-win32-arm64-msvc",
"direct": false,
"version": "4.59.0",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-win32-ia32-msvc",
"direct": false,
"version": "4.59.0",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-win32-x64-gnu",
"direct": false,
"version": "4.59.0",
"ecosystem": "npm"
},
{
"name": "@rollup/rollup-win32-x64-msvc",
"direct": false,
"version": "4.59.0",
"ecosystem": "npm"
},
{
"name": "@standard-schema/spec",
"direct": false,
"version": "1.1.0",
"ecosystem": "npm"
},
{
"name": "@tailwindcss/node",
"direct": false,
"version": "4.3.3",
"ecosystem": "npm"
},
{
"name": "@tailwindcss/oxide",
"direct": false,
"version": "4.3.3",
"ecosystem": "npm"
},
{
"name": "@tailwindcss/oxide-android-arm64",
"direct": false,
"version": "4.3.3",
"ecosystem": "npm"
},
{
"name": "@tailwindcss/oxide-darwin-arm64",
"direct": false,
"version": "4.3.3",
"ecosystem": "npm"
},
{
"name": "@tailwindcss/oxide-darwin-x64",
"direct": false,
"version": "4.3.3",
"ecosystem": "npm"
},
{
"name": "@tailwindcss/oxide-freebsd-x64",
"direct": false,
"version": "4.3.3",
"ecosystem": "npm"
},
{
"name": "@tailwindcss/oxide-linux-arm-gnueabihf",
"direct": false,
"version": "4.3.3",
"ecosystem": "npm"
},
{
"name": "@tailwindcss/oxide-linux-arm64-gnu",
"direct": false,
"version": "4.3.3",
"ecosystem": "npm"
},
{
"name": "@tailwindcss/oxide-linux-arm64-musl",
"direct": false,
"version": "4.3.3",
"ecosystem": "npm"
},
{
"name": "@tailwindcss/oxide-linux-x64-gnu",
"direct": false,
"version": "4.3.3",
"ecosystem": "npm"
},
{
"name": "@tailwindcss/oxide-linux-x64-musl",
"direct": false,
"version": "4.3.3",
"ecosystem": "npm"
},
{
"name": "@tailwindcss/oxide-wasm32-wasi",
"direct": false,
"version": "4.3.3",
"ecosystem": "npm"
},
{
"name": "@tailwindcss/oxide-win32-arm64-msvc",
"direct": false,
"version": "4.3.3",
"ecosystem": "npm"
},
{
"name": "@tailwindcss/oxide-win32-x64-msvc",
"direct": false,
"version": "4.3.3",
"ecosystem": "npm"
},
{
"name": "@tailwindcss/postcss",
"direct": false,
"version": "4.3.3",
"ecosystem": "npm"
},
{
"name": "@tybys/wasm-util",
"direct": false,
"version": "0.10.3",
"ecosystem": "npm"
},
{
"name": "@types/chai",
"direct": false,
"version": "5.2.3",
"ecosystem": "npm"
},
{
"name": "@types/deep-eql",
"direct": false,
"version": "4.0.2",
"ecosystem": "npm"
},
{
"name": "@types/estree",
"direct": false,
"version": "1.0.8",
"ecosystem": "npm"
},
{
"name": "@types/estree",
"direct": false,
"version": "1.0.9",
"ecosystem": "npm"
},
{
"name": "@types/statuses",
"direct": false,
"version": "2.0.6",
"ecosystem": "npm"
},
{
"name": "@vitest/expect",
"direct": false,
"version": "3.2.6",
"ecosystem": "npm"
},
{
"name": "@vitest/expect",
"direct": false,
"version": "4.1.10",
"ecosystem": "npm"
},
{
"name": "@vitest/mocker",
"direct": false,
"version": "3.2.6",
"ecosystem": "npm"
},
{
"name": "@vitest/mocker",
"direct": false,
"version": "4.1.10",
"ecosystem": "npm"
},
{
"name": "@vitest/pretty-format",
"direct": false,
"version": "3.2.6",
"ecosystem": "npm"
},
{
"name": "@vitest/pretty-format",
"direct": false,
"version": "3.2.7",
"ecosystem": "npm"
},
{
"name": "@vitest/pretty-format",
"direct": false,
"version": "4.1.10",
"ecosystem": "npm"
},
{
"name": "@vitest/runner",
"direct": false,
"version": "3.2.6",
"ecosystem": "npm"
},
{
"name": "@vitest/runner",
"direct": false,
"version": "4.1.10",
"ecosystem": "npm"
},
{
"name": "@vitest/snapshot",
"direct": false,
"version": "3.2.6",
"ecosystem": "npm"
},
{
"name": "@vitest/snapshot",
"direct": false,
"version": "4.1.10",
"ecosystem": "npm"
},
{
"name": "@vitest/spy",
"direct": false,
"version": "3.2.6",
"ecosystem": "npm"
},
{
"name": "@vitest/spy",
"direct": false,
"version": "4.1.10",
"ecosystem": "npm"
},
{
"name": "@vitest/utils",
"direct": false,
"version": "3.2.6",
"ecosystem": "npm"
},
{
"name": "@vitest/utils",
"direct": false,
"version": "4.1.10",
"ecosystem": "npm"
},
{
"name": "ansi-regex",
"direct": false,
"version": "5.0.1",
"ecosystem": "npm"
},
{
"name": "ansi-styles",
"direct": false,
"version": "4.3.0",
"ecosystem": "npm"
},
{
"name": "assertion-error",
"direct": false,
"version": "2.0.1",
"ecosystem": "npm"
},
{
"name": "cac",
"direct": false,
"version": "6.7.14",
"ecosystem": "npm"
},
{
"name": "chai",
"direct": false,
"version": "5.3.3",
"ecosystem": "npm"
},
{
"name": "chai",
"direct": false,
"version": "6.2.2",
"ecosystem": "npm"
},
{
"name": "check-error",
"direct": false,
"version": "2.1.3",
"ecosystem": "npm"
},
{
"name": "cli-width",
"direct": false,
"version": "4.1.0",
"ecosystem": "npm"
},
{
"name": "cliui",
"direct": false,
"version": "8.0.1",
"ecosystem": "npm"
},
{
"name": "color-convert",
"direct": false,
"version": "2.0.1",
"ecosystem": "npm"
},
{
"name": "color-name",
"direct": false,
"version": "1.1.4",
"ecosystem": "npm"
},
{
"name": "convert-source-map",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "cookie",
"direct": false,
"version": "1.1.1",
"ecosystem": "npm"
},
{
"name": "debug",
"direct": false,
"version": "4.4.3",
"ecosystem": "npm"
},
{
"name": "deep-eql",
"direct": false,
"version": "5.0.2",
"ecosystem": "npm"
},
{
"name": "detect-libc",
"direct": false,
"version": "2.1.2",
"ecosystem": "npm"
},
{
"name": "emoji-regex",
"direct": false,
"version": "8.0.0",
"ecosystem": "npm"
},
{
"name": "enhanced-resolve",
"direct": false,
"version": "5.24.3",
"ecosystem": "npm"
},
{
"name": "es-module-lexer",
"direct": false,
"version": "1.7.0",
"ecosystem": "npm"
},
{
"name": "es-module-lexer",
"direct": false,
"version": "2.3.1",
"ecosystem": "npm"
},
{
"name": "esbuild",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "escalade",
"direct": false,
"version": "3.2.0",
"ecosystem": "npm"
},
{
"name": "estree-walker",
"direct": false,
"version": "3.0.3",
"ecosystem": "npm"
},
{
"name": "expect-type",
"direct": false,
"version": "1.3.0",
"ecosystem": "npm"
},
{
"name": "fdir",
"direct": false,
"version": "6.5.0",
"ecosystem": "npm"
},
{
"name": "fsevents",
"direct": false,
"version": "2.3.2",
"ecosystem": "npm"
},
{
"name": "fsevents",
"direct": false,
"version": "2.3.3",
"ecosystem": "npm"
},
{
"name": "get-caller-file",
"direct": false,
"version": "2.0.5",
"ecosystem": "npm"
},
{
"name": "graceful-fs",
"direct": false,
"version": "4.2.11",
"ecosystem": "npm"
},
{
"name": "graphql",
"direct": false,
"version": "16.13.1",
"ecosystem": "npm"
},
{
"name": "headers-polyfill",
"direct": false,
"version": "4.0.3",
"ecosystem": "npm"
},
{
"name": "is-fullwidth-code-point",
"direct": false,
"version": "3.0.0",
"ecosystem": "npm"
},
{
"name": "is-node-process",
"direct": false,
"version": "1.2.0",
"ecosystem": "npm"
},
{
"name": "jiti",
"direct": false,
"version": "2.7.0",
"ecosystem": "npm"
},
{
"name": "js-tokens",
"direct": false,
"version": "9.0.1",
"ecosystem": "npm"
},
{
"name": "lightningcss",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss",
"direct": false,
"version": "1.33.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-android-arm64",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-android-arm64",
"direct": false,
"version": "1.33.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-darwin-arm64",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-darwin-arm64",
"direct": false,
"version": "1.33.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-darwin-x64",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-darwin-x64",
"direct": false,
"version": "1.33.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-freebsd-x64",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-freebsd-x64",
"direct": false,
"version": "1.33.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-linux-arm-gnueabihf",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-linux-arm-gnueabihf",
"direct": false,
"version": "1.33.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-linux-arm64-gnu",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-linux-arm64-gnu",
"direct": false,
"version": "1.33.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-linux-arm64-musl",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-linux-arm64-musl",
"direct": false,
"version": "1.33.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-linux-x64-gnu",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-linux-x64-gnu",
"direct": false,
"version": "1.33.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-linux-x64-musl",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-linux-x64-musl",
"direct": false,
"version": "1.33.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-win32-arm64-msvc",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-win32-arm64-msvc",
"direct": false,
"version": "1.33.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-win32-x64-msvc",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-win32-x64-msvc",
"direct": false,
"version": "1.33.0",
"ecosystem": "npm"
},
{
"name": "loupe",
"direct": false,
"version": "3.2.1",
"ecosystem": "npm"
},
{
"name": "magic-string",
"direct": false,
"version": "0.30.21",
"ecosystem": "npm"
},
{
"name": "ms",
"direct": false,
"version": "2.1.3",
"ecosystem": "npm"
},
{
"name": "msw",
"direct": false,
"version": "2.12.10",
"ecosystem": "npm"
},
{
"name": "mute-stream",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "nanoid",
"direct": false,
"version": "3.3.16",
"ecosystem": "npm"
},
{
"name": "obug",
"direct": false,
"version": "2.1.4",
"ecosystem": "npm"
},
{
"name": "outvariant",
"direct": false,
"version": "1.4.3",
"ecosystem": "npm"
},
{
"name": "path-to-regexp",
"direct": false,
"version": "6.3.0",
"ecosystem": "npm"
},
{
"name": "pathe",
"direct": false,
"version": "2.0.3",
"ecosystem": "npm"
},
{
"name": "pathval",
"direct": false,
"version": "2.0.1",
"ecosystem": "npm"
},
{
"name": "picocolors",
"direct": false,
"version": "1.1.1",
"ecosystem": "npm"
},
{
"name": "picomatch",
"direct": false,
"version": "4.0.5",
"ecosystem": "npm"
},
{
"name": "playwright",
"direct": false,
"version": "1.58.2",
"ecosystem": "npm"
},
{
"name": "playwright-core",
"direct": false,
"version": "1.58.2",
"ecosystem": "npm"
},
{
"name": "postcss",
"direct": false,
"version": "8.5.23",
"ecosystem": "npm"
},
{
"name": "require-directory",
"direct": false,
"version": "2.1.1",
"ecosystem": "npm"
},
{
"name": "rettime",
"direct": false,
"version": "0.10.1",
"ecosystem": "npm"
},
{
"name": "rolldown",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "rollup",
"direct": false,
"version": "4.59.0",
"ecosystem": "npm"
},
{
"name": "siginfo",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "signal-exit",
"direct": false,
"version": "4.1.0",
"ecosystem": "npm"
},
{
"name": "source-map-js",
"direct": false,
"version": "1.2.1",
"ecosystem": "npm"
},
{
"name": "stackback",
"direct": false,
"version": "0.0.2",
"ecosystem": "npm"
},
{
"name": "statuses",
"direct": false,
"version": "2.0.2",
"ecosystem": "npm"
},
{
"name": "std-env",
"direct": false,
"version": "3.10.0",
"ecosystem": "npm"
},
{
"name": "std-env",
"direct": false,
"version": "4.2.0",
"ecosystem": "npm"
},
{
"name": "strict-event-emitter",
"direct": false,
"version": "0.5.1",
"ecosystem": "npm"
},
{
"name": "string-width",
"direct": false,
"version": "4.2.3",
"ecosystem": "npm"
},
{
"name": "strip-ansi",
"direct": false,
"version": "6.0.1",
"ecosystem": "npm"
},
{
"name": "strip-literal",
"direct": false,
"version": "3.1.0",
"ecosystem": "npm"
},
{
"name": "tagged-tag",
"direct": false,
"version": "1.0.0",
"ecosystem": "npm"
},
{
"name": "tailwindcss",
"direct": false,
"version": "4.3.3",
"ecosystem": "npm"
},
{
"name": "tapable",
"direct": false,
"version": "2.3.3",
"ecosystem": "npm"
},
{
"name": "tinybench",
"direct": false,
"version": "2.9.0",
"ecosystem": "npm"
},
{
"name": "tinyexec",
"direct": false,
"version": "0.3.2",
"ecosystem": "npm"
},
{
"name": "tinyexec",
"direct": false,
"version": "1.2.4",
"ecosystem": "npm"
},
{
"name": "tinyglobby",
"direct": false,
"version": "0.2.15",
"ecosystem": "npm"
},
{
"name": "tinyglobby",
"direct": false,
"version": "0.2.17",
"ecosystem": "npm"
},
{
"name": "tinypool",
"direct": false,
"version": "1.1.1",
"ecosystem": "npm"
},
{
"name": "tinyrainbow",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "tinyrainbow",
"direct": false,
"version": "3.1.0",
"ecosystem": "npm"
},
{
"name": "tinyspy",
"direct": false,
"version": "4.0.4",
"ecosystem": "npm"
},
{
"name": "tldts",
"direct": false,
"version": "7.0.25",
"ecosystem": "npm"
},
{
"name": "tldts-core",
"direct": false,
"version": "7.0.25",
"ecosystem": "npm"
},
{
"name": "tough-cookie",
"direct": false,
"version": "6.0.1",
"ecosystem": "npm"
},
{
"name": "tslib",
"direct": false,
"version": "2.8.1",
"ecosystem": "npm"
},
{
"name": "type-fest",
"direct": false,
"version": "5.4.4",
"ecosystem": "npm"
},
{
"name": "typescript",
"direct": false,
"version": "5.9.3",
"ecosystem": "npm"
},
{
"name": "until-async",
"direct": false,
"version": "3.0.2",
"ecosystem": "npm"
},
{
"name": "vite",
"direct": false,
"version": "7.3.6",
"ecosystem": "npm"
},
{
"name": "vite",
"direct": false,
"version": "8.1.5",
"ecosystem": "npm"
},
{
"name": "vite-node",
"direct": false,
"version": "3.2.4",
"ecosystem": "npm"
},
{
"name": "vitest",
"direct": false,
"version": "3.2.6",
"ecosystem": "npm"
},
{
"name": "vitest",
"direct": false,
"version": "4.1.10",
"ecosystem": "npm"
},
{
"name": "why-is-node-running",
"direct": false,
"version": "2.3.0",
"ecosystem": "npm"
},
{
"name": "wrap-ansi",
"direct": false,
"version": "6.2.0",
"ecosystem": "npm"
},
{
"name": "wrap-ansi",
"direct": false,
"version": "7.0.0",
"ecosystem": "npm"
},
{
"name": "y18n",
"direct": false,
"version": "5.0.8",
"ecosystem": "npm"
},
{
"name": "yargs",
"direct": false,
"version": "17.7.2",
"ecosystem": "npm"
},
{
"name": "yargs-parser",
"direct": false,
"version": "21.1.1",
"ecosystem": "npm"
},
{
"name": "yoctocolors-cjs",
"direct": false,
"version": "2.1.3",
"ecosystem": "npm"
},
{
"name": "myclabs/deep-copy",
"direct": false,
"version": "1.13.4",
"ecosystem": "packagist"
},
{
"name": "nikic/php-parser",
"direct": false,
"version": "5.7.0",
"ecosystem": "packagist"
},
{
"name": "phar-io/manifest",
"direct": false,
"version": "2.0.4",
"ecosystem": "packagist"
},
{
"name": "phar-io/version",
"direct": false,
"version": "3.2.1",
"ecosystem": "packagist"
},
{
"name": "phpunit/php-code-coverage",
"direct": false,
"version": "11.0.12",
"ecosystem": "packagist"
},
{
"name": "phpunit/php-file-iterator",
"direct": false,
"version": "5.1.1",
"ecosystem": "packagist"
},
{
"name": "phpunit/php-invoker",
"direct": false,
"version": "5.0.1",
"ecosystem": "packagist"
},
{
"name": "phpunit/php-text-template",
"direct": false,
"version": "4.0.1",
"ecosystem": "packagist"
},
{
"name": "phpunit/php-timer",
"direct": false,
"version": "7.0.1",
"ecosystem": "packagist"
},
{
"name": "phpunit/phpunit",
"direct": false,
"version": "11.5.55",
"ecosystem": "packagist"
},
{
"name": "sebastian/cli-parser",
"direct": false,
"version": "3.0.2",
"ecosystem": "packagist"
},
{
"name": "sebastian/code-unit",
"direct": false,
"version": "3.0.3",
"ecosystem": "packagist"
},
{
"name": "sebastian/code-unit-reverse-lookup",
"direct": false,
"version": "4.0.1",
"ecosystem": "packagist"
},
{
"name": "sebastian/comparator",
"direct": false,
"version": "6.3.3",
"ecosystem": "packagist"
},
{
"name": "sebastian/complexity",
"direct": false,
"version": "4.0.1",
"ecosystem": "packagist"
},
{
"name": "sebastian/diff",
"direct": false,
"version": "6.0.2",
"ecosystem": "packagist"
},
{
"name": "sebastian/environment",
"direct": false,
"version": "7.2.1",
"ecosystem": "packagist"
},
{
"name": "sebastian/exporter",
"direct": false,
"version": "6.3.2",
"ecosystem": "packagist"
},
{
"name": "sebastian/global-state",
"direct": false,
"version": "7.0.2",
"ecosystem": "packagist"
},
{
"name": "sebastian/lines-of-code",
"direct": false,
"version": "3.0.1",
"ecosystem": "packagist"
},
{
"name": "sebastian/object-enumerator",
"direct": false,
"version": "6.0.1",
"ecosystem": "packagist"
},
{
"name": "sebastian/object-reflector",
"direct": false,
"version": "4.0.1",
"ecosystem": "packagist"
},
{
"name": "sebastian/recursion-context",
"direct": false,
"version": "6.0.3",
"ecosystem": "packagist"
},
{
"name": "sebastian/type",
"direct": false,
"version": "5.1.3",
"ecosystem": "packagist"
},
{
"name": "sebastian/version",
"direct": false,
"version": "5.0.2",
"ecosystem": "packagist"
},
{
"name": "staabm/side-effects-detector",
"direct": false,
"version": "1.0.5",
"ecosystem": "packagist"
},
{
"name": "theseer/tokenizer",
"direct": false,
"version": "1.3.1",
"ecosystem": "packagist"
},
{
"name": "flit-core",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "httpx",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "langchain",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "langchain-anthropic",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "langchain-core",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "muninn-python",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "pytest",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "pytest-asyncio",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "python-dotenv",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "respx",
"direct": false,
"version": null,
"ecosystem": "pypi"
}
],
"collected": true,
"truncated": false,
"total_count": 339,
"direct_count": 22,
"indirect_count": 317
}
},
"maintainership": {
"issues": {
"open_prs": 14,
"merged_prs": 442,
"open_issues": 64,
"closed_ratio": 0.768,
"closed_issues": 212,
"closed_unmerged_prs": 25
},
"bus_factor": 1,
"bot_contributors": 1,
"top_contributors": [
{
"type": "User",
"login": "scrypster",
"commits": 344,
"avatar_url": "https://avatars.githubusercontent.com/u/59214607?v=4"
},
{
"type": "User",
"login": "johanneshauer",
"commits": 22,
"avatar_url": "https://avatars.githubusercontent.com/u/93012957?v=4"
},
{
"type": "User",
"login": "Invincibear",
"commits": 20,
"avatar_url": "https://avatars.githubusercontent.com/u/6895337?v=4"
},
{
"type": "User",
"login": "isaac-ranger",
"commits": 15,
"avatar_url": "https://avatars.githubusercontent.com/u/259727350?v=4"
},
{
"type": "User",
"login": "To3Knee",
"commits": 11,
"avatar_url": "https://avatars.githubusercontent.com/u/178674259?v=4"
},
{
"type": "User",
"login": "maybebyte",
"commits": 11,
"avatar_url": "https://avatars.githubusercontent.com/u/99762926?v=4"
},
{
"type": "User",
"login": "Aperrix",
"commits": 9,
"avatar_url": "https://avatars.githubusercontent.com/u/26674548?v=4"
},
{
"type": "User",
"login": "ad-astra-bot",
"commits": 7,
"avatar_url": "https://avatars.githubusercontent.com/u/263242209?v=4"
},
{
"type": "User",
"login": "ojamin",
"commits": 6,
"avatar_url": "https://avatars.githubusercontent.com/u/201050?v=4"
},
{
"type": "User",
"login": "madeinoz67",
"commits": 5,
"avatar_url": "https://avatars.githubusercontent.com/u/4160293?v=4"
}
],
"contributors_sampled": 22,
"top_contributor_share": 0.726
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"ci.yml",
"docker-publish.yml",
"publish-sdk.yml",
"release.yml"
],
"has_docs_dir": true,
"linter_configs": [],
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"composer.lock",
"go.sum",
"package-lock.json"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 8,
"reason": "binaries present in source code",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 5,
"reason": "branch protection is not maximal on development and all release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 10,
"reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 1,
"reason": "Found 3/30 approved changesets -- score normalized to 1",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 3,
"reason": "project has 1 contributing companies or organizations -- score normalized to 3",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 10,
"reason": "project is fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 9,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 18 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": 10,
"reason": "packaging workflow detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 3,
"reason": "dependency not pinned by hash detected -- score normalized to 3",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 0,
"reason": "SAST tool is not run on all commits -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 10,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": 0,
"reason": "Project has not signed or included provenance with any releases.",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 7,
"reason": "3 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "e24b5dcfd3c4a756f3cfbe51f0e36f4351fd14cb",
"ran_at": "2026-08-01T02:14:47Z",
"aggregate_score": 6,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": true,
"has_dependabot_config": false
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-31T21:41:51Z",
"oldest_open_prs": [
{
"number": 367,
"created_at": "2026-04-04T11:27:55Z",
"last_comment_at": "2026-07-01T15:53:34Z",
"last_comment_author": "scrypster"
},
{
"number": 431,
"created_at": "2026-05-06T02:47:59Z",
"last_comment_at": "2026-07-08T00:59:30Z",
"last_comment_author": "gitssie"
},
{
"number": 644,
"created_at": "2026-07-21T01:40:22Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 645,
"created_at": "2026-07-21T02:12:56Z",
"last_comment_at": "2026-07-28T00:09:55Z",
"last_comment_author": "dpearson2699"
},
{
"number": 659,
"created_at": "2026-07-27T08:09:28Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 687,
"created_at": "2026-07-28T16:27:57Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 730,
"created_at": "2026-07-30T03:26:17Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 732,
"created_at": "2026-07-30T05:12:09Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 736,
"created_at": "2026-07-30T13:26:51Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 737,
"created_at": "2026-07-30T14:45:20Z",
"last_comment_at": "2026-07-30T15:35:15Z",
"last_comment_author": "likesjx"
},
{
"number": 748,
"created_at": "2026-07-31T13:03:07Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 749,
"created_at": "2026-07-31T13:03:19Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 750,
"created_at": "2026-07-31T13:03:29Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 752,
"created_at": "2026-07-31T14:13:01Z",
"last_comment_at": null,
"last_comment_author": null
}
],
"last_merged_pr_at": "2026-07-31T21:34:21Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": [
{
"number": 321,
"created_at": "2026-03-31T09:40:15Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 322,
"created_at": "2026-03-31T09:40:29Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 323,
"created_at": "2026-03-31T09:40:45Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 324,
"created_at": "2026-03-31T09:40:59Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 325,
"created_at": "2026-03-31T09:41:12Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 326,
"created_at": "2026-03-31T09:41:27Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 375,
"created_at": "2026-04-08T20:33:54Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 376,
"created_at": "2026-04-08T20:34:32Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 378,
"created_at": "2026-04-10T00:40:34Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 384,
"created_at": "2026-04-10T01:25:58Z",
"last_comment_at": "2026-04-10T01:32:13Z",
"last_comment_author": "ByartMyars"
},
{
"number": 386,
"created_at": "2026-04-10T01:26:31Z",
"last_comment_at": "2026-04-28T02:45:31Z",
"last_comment_author": "scrypster"
},
{
"number": 388,
"created_at": "2026-04-10T01:26:55Z",
"last_comment_at": "2026-04-28T02:45:37Z",
"last_comment_author": "scrypster"
},
{
"number": 546,
"created_at": "2026-06-17T12:18:25Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 556,
"created_at": "2026-06-29T19:51:17Z",
"last_comment_at": "2026-07-19T07:19:26Z",
"last_comment_author": "madeinoz67"
},
{
"number": 561,
"created_at": "2026-07-01T15:53:58Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 588,
"created_at": "2026-07-07T07:03:08Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 595,
"created_at": "2026-07-10T10:49:07Z",
"last_comment_at": "2026-07-12T16:01:28Z",
"last_comment_author": "johanneshauer"
},
{
"number": 596,
"created_at": "2026-07-10T11:57:26Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 598,
"created_at": "2026-07-11T22:41:39Z",
"last_comment_at": "2026-07-30T14:53:11Z",
"last_comment_author": "ad-astra-bot"
},
{
"number": 600,
"created_at": "2026-07-12T11:03:01Z",
"last_comment_at": "2026-07-21T14:58:32Z",
"last_comment_author": "johanneshauer"
}
]
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/scrypster/muninndb",
"host": "github.com",
"name": "muninndb",
"owner": "scrypster"
},
"metrics": {
"overall": {
"key": "overall",
"band": "moderate",
"name": "Overall health",
"note": null,
"notes": [],
"value": 69,
"inputs": {
"security": 65,
"vitality": 83,
"community": 66,
"governance": 61,
"engineering": 71
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 83,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "good",
"name": "Development activity",
"note": null,
"notes": [],
"value": 78,
"inputs": {
"commits_last_year": 1035,
"human_commit_share": 0.94,
"days_since_last_push": 0,
"active_weeks_last_year": 21
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "21/52 weeks with commits",
"points": 14.5,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 21
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "1035 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 1035
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 18 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"releases_count": 47,
"latest_release_tag": "v0.9.0",
"releases_from_tags": false,
"days_since_latest_release": 11,
"mean_days_between_releases": 11.7
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "47 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 47
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 11 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 11
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~11.7 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 11.7
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "repository_too_young",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "moderate",
"name": "Community & Adoption",
"value": 66,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "moderate",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 62,
"inputs": {
"forks": 75,
"stars": 318,
"watchers": 12,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "318 stars",
"points": 40.6,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 318
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "75 forks",
"points": 15.6,
"status": "partial",
"details": [
{
"code": "forks",
"params": {
"count": 75
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "12 watchers",
"points": 5.8,
"status": "partial",
"details": [
{
"code": "watchers",
"params": {
"count": 12
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "good",
"name": "Community health",
"note": null,
"notes": [],
"value": 71,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": true,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "license file present, not a recognized license",
"points": 16.9,
"status": "partial",
"details": [
{
"code": "license_custom",
"params": {}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 18,
"status": "met",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 6.3,
"status": "met",
"details": [],
"max_points": 6.3
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "moderate",
"name": "Sustainability & Governance",
"value": 61,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "at_risk",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 32,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 22,
"top_contributor_share": 0.726
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 73% of commits",
"points": 6.2,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 73
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "22 contributors",
"points": 13.5,
"status": "met",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 22
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 1 contributing companies or organizations -- score normalized to 3",
"points": 3,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "good",
"name": "Issue & PR responsiveness",
"note": null,
"notes": [],
"value": 74,
"inputs": {
"merged_prs": 442,
"open_issues": 64,
"closed_issues": 212,
"issue_closed_ratio": 0.768,
"closed_unmerged_prs": 25
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "77% of issues closed",
"points": 35.9,
"status": "partial",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 77
}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "442/467 decided PRs merged",
"points": 36.2,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 442,
"decided": 467
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 3/30 approved changesets -- score normalized to 1",
"points": 1.5,
"status": "partial",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "moderate",
"name": "Ownership & stewardship",
"note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"verified_domain"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 50,
"inputs": {
"followers": 38,
"owner_type": "User",
"is_verified": null,
"owner_login": "scrypster",
"public_repos": 7,
"account_age_days": 2410
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "personal (user) account",
"points": 10,
"status": "partial",
"details": [
{
"code": "owner_personal",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": "not applicable to user accounts",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_applicable_to_user_accounts",
"params": {}
}
],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "38 followers of scrypster",
"points": 11.4,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 38,
"login": "scrypster"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "7 public repos, account ~6 yr old",
"points": 18.6,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 7
}
},
{
"code": "account_age_years",
"params": {
"years": 6
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"github.com/scrypster/muninndb"
],
"ecosystems": "go",
"any_deprecated": false,
"min_days_since_publish": 11
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on go",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "go"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 11 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 11
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "47 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 47
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "good",
"name": "Engineering Quality",
"value": 71,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "moderate",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 68,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "4 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 4
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
"points": 20,
"status": "met",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "good",
"name": "Documentation",
"note": null,
"notes": [],
"value": 75,
"inputs": {
"topics": [],
"has_wiki": true,
"homepage": null,
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "moderate",
"name": "Security",
"value": 65,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "moderate",
"name": "Security posture",
"note": null,
"notes": [],
"value": 60,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 18,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 0,
"scorecard_aggregate": 6
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "binaries present in source code",
"points": 6,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection is not maximal on development and all release branches",
"points": 3.8,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 3/30 approved changesets -- score normalized to 1",
"points": 0.8,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 1 contributing companies or organizations -- score normalized to 3",
"points": 0.8,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is fuzzed",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.2,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 18 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 3",
"points": 1.5,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is not run on all commits -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "3 existing vulnerabilities detected",
"points": 5.2,
"status": "partial",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "excellent",
"name": "Dependency advisories",
"note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories. Remaining weights renormalized. Matched 329 resolved dependencies against OSV; 10 could not be assessed (no resolved version, an unsupported ecosystem, or beyond the reported package list). This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"indirect_dependencies_free_of_known_advisories"
]
}
},
{
"code": "weights_renormalized",
"params": {}
},
{
"code": "advisories_scope_repository",
"params": {
"assessed": 329
}
},
{
"code": "advisories_unassessed",
"params": {
"count": 10
}
},
{
"code": "advisories_repo_graph_caveat",
"params": {}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 86,
"inputs": {
"source": "osv",
"advisories": 3,
"affected_packages": 3,
"assessed_packages": 329,
"unassessed_packages": 10,
"affected_by_severity": "unknown 3",
"direct_affected_packages": 2
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "2 affected: github.com/klauspost/compress v1.16.0 (unknown), golang.org/x/crypto v0.52.0 (unknown)",
"points": 24.7,
"status": "partial",
"details": [
{
"code": "advisories_affected",
"params": {
"count": 2,
"packages": "github.com/klauspost/compress v1.16.0 (unknown), golang.org/x/crypto v0.52.0 (unknown)"
}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "transitive set not separable from development and test dependencies in this scope",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_scope_not_separable",
"params": {}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "no advisory has been public longer than 90 days",
"points": 40,
"status": "met",
"details": [
{
"code": "advisories_none_stale",
"params": {
"days": 90
}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "excellent",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 329,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 5
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "excellent",
"name": "AI Readiness",
"value": 85,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "excellent",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 85,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 0.989,
"agent_instruction_files": [
"CLAUDE.md"
],
"agent_instruction_max_bytes": 10233
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "CLAUDE.md",
"points": 45,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "CLAUDE.md"
}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "93 of 94 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 93,
"sampled": 94
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "good",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 82,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"composer.lock",
"go.sum",
"package-lock.json"
],
"has_dockerfile": true,
"typed_language": true,
"bootstrap_files": [
"Makefile"
],
"has_devcontainer": false,
"has_linter_config": false,
"typecheck_configs": [
"sdk/node/tsconfig.json"
],
"agent_commit_share": 0.1,
"toolchain_manifests": [
"go.mod",
"sdk/go/muninn/go.mod",
"sdk/kotlin/build.gradle.kts"
],
"dependency_bot_commit_share": 0.06
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "Makefile",
"points": 18,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Makefile"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "sdk/node/tsconfig.json",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "sdk/node/tsconfig.json"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "Dockerfile, lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Dockerfile, lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "10 of the last 100 commits agent-authored or agent-credited",
"points": 10,
"status": "met",
"details": [
{
"code": "agent_authored_commits",
"params": {
"count": 10,
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "6 of the last 100 commits are automated dependency updates",
"points": 8,
"status": "met",
"details": [
{
"code": "dependency_bot_commits",
"params": {
"count": 6,
"sampled": 100
}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 3",
"points": 3,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 99,
"inputs": {
"primary_language": "Go",
"largest_source_bytes": 178827,
"source_files_sampled": 894,
"oversized_source_files": 13
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Go (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "13/894 source files over 60KB",
"points": 54.2,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 894,
"oversized": 13
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "good",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 80,
"inputs": {
"example_dirs": [
"examples"
],
"has_mcp_signal": false,
"api_schema_files": [
"internal/transport/rest/openapi.yaml",
"proto/muninn/v1/service.proto"
]
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": "internal/transport/rest/openapi.yaml, proto/muninn/v1/service.proto",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "internal/transport/rest/openapi.yaml, proto/muninn/v1/service.proto"
}
}
],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": "examples",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "examples"
}
}
],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
],
"report_type": "repository",
"generated_at": "2026-08-01T02:15:14.787576Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/s/scrypster/muninndb.svg",
"full_name": "scrypster/muninndb",
"license_state": "custom",
"license_spdx": null
}