Raw JSON report machine-readable
{
"data": {
"repo": {
"topics": [
"api",
"cli",
"mcp",
"server"
],
"is_fork": false,
"size_kb": 27814,
"has_wiki": true,
"homepage": "https://www.silkweave.dev",
"languages": {
"CSS": 4352,
"Astro": 276961,
"JavaScript": 65766,
"TypeScript": 644201
},
"pushed_at": "2026-07-20T23:52:36Z",
"created_at": "2026-04-08T01:29:35Z",
"owner_type": "Organization",
"updated_at": "2026-07-20T23:52:27Z",
"description": "Silkweave Monorepo",
"is_archived": false,
"is_disabled": false,
"license_spdx": "MIT",
"default_branch": "master",
"license_spdx_raw": "MIT",
"primary_language": "TypeScript",
"significant_languages": [
"TypeScript",
"Astro"
]
},
"owner": {
"blog": null,
"name": "Silkweave",
"type": "Organization",
"login": "silkweave",
"company": null,
"location": null,
"followers": 0,
"avatar_url": "https://avatars.githubusercontent.com/u/274353181?v=4",
"created_at": "2026-04-07T23:35:49Z",
"is_verified": null,
"public_repos": 3,
"account_age_days": 110
},
"license": {
"state": "standard",
"spdx_id": "MIT",
"raw_spdx": "MIT",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v5.0.0",
"kind": "major",
"published_at": "2026-07-20T23:52:57Z"
},
{
"tag": "v4.4.0",
"kind": "minor",
"published_at": "2026-07-20T06:56:20Z"
},
{
"tag": "v4.3.0",
"kind": "minor",
"published_at": "2026-07-20T04:09:03Z"
},
{
"tag": "v4.2.0",
"kind": "minor",
"published_at": "2026-07-17T04:57:47Z"
},
{
"tag": "v4.1.0",
"kind": "minor",
"published_at": "2026-07-16T02:59:27Z"
},
{
"tag": "v4.0.1",
"kind": "patch",
"published_at": "2026-07-14T07:33:48Z"
},
{
"tag": "v4.0.0",
"kind": "major",
"published_at": "2026-07-13T08:56:56Z"
},
{
"tag": "v3.2.1",
"kind": "patch",
"published_at": "2026-07-13T08:56:58Z"
},
{
"tag": "v3.2.0",
"kind": "minor",
"published_at": "2026-07-13T03:27:47Z"
},
{
"tag": "v3.1.0",
"kind": "minor",
"published_at": "2026-07-08T00:21:46Z"
},
{
"tag": "v3.0.0",
"kind": "major",
"published_at": "2026-06-21T00:32:07Z"
},
{
"tag": "v2.6.1",
"kind": "patch",
"published_at": "2026-06-18T12:58:17Z"
},
{
"tag": "v2.6.0",
"kind": "minor",
"published_at": "2026-06-18T03:03:19Z"
},
{
"tag": "v2.5.0",
"kind": "minor",
"published_at": "2026-06-18T00:56:53Z"
},
{
"tag": "v2.4.0",
"kind": "minor",
"published_at": "2026-06-16T13:59:05Z"
},
{
"tag": "v2.3.0",
"kind": "minor",
"published_at": "2026-06-16T12:34:24Z"
},
{
"tag": "v2.2.0",
"kind": "minor",
"published_at": "2026-06-16T12:34:27Z"
},
{
"tag": "v2.1.0",
"kind": "minor",
"published_at": "2026-06-16T12:34:30Z"
},
{
"tag": "v2.0.0",
"kind": "major",
"published_at": "2026-06-16T12:34:33Z"
},
{
"tag": "v1.12.0",
"kind": "minor",
"published_at": "2026-06-16T12:34:35Z"
},
{
"tag": "v1.6.0",
"kind": "minor",
"published_at": "2026-06-16T12:34:38Z"
},
{
"tag": "v1.5.0",
"kind": "minor",
"published_at": "2026-06-16T12:34:40Z"
},
{
"tag": "v1.4.0",
"kind": "minor",
"published_at": "2026-06-16T12:34:43Z"
}
],
"recent_commits": [
{
"oid": "b755bcc0b1be87b911ebe930f7f0870eb2892a5d",
"body": "Changelog entry flipped to released (2026-07-21) + multi-skill plugin\nhighlight added.\n\nClaude-Session: https://claude.ai/code/session_01LZJpmZ7owT3zTTXUprvkB4",
"is_bot": false,
"headline": "chore: bump version to 5.0.0",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-07-20T23:52:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3758eb4203737569061c0f8c6bb6605cba47263b",
"body": "- silkweave skills pack now accepts multiple skill dirs, bundling them into\n ONE Claude Code plugin (--package required; plugin name = package basename\n via pluginNameForPackage(); all skills must agree on a version; new\n -d/--description override).\n- marketplaceJson() groups skills sharing an np\n[…]\ne-plugin@1.0.0, so\n /plugin marketplace add + /plugin install work end-to-end.\n- root .gitignore: dist/ (default pack output).\n\nClaude-Session: https://claude.ai/code/session_01LZJpmZ7owT3zTTXUprvkB4",
"is_bot": false,
"headline": "feat(skills): multi-skill plugin packs + grouped marketplace entries",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-07-20T23:42:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f8ab18c7c80f1e1dc15cf5553dfc0600fe27455a",
"body": "The v*.*.* trigger also matches prerelease tags (v5.0.0-rc.1); without a\ndist-tag the RC would become npm's latest. Tags whose version contains a\nhyphen now publish with --tag next.\n\nClaude-Session: https://claude.ai/code/session_01LZJpmZ7owT3zTTXUprvkB4",
"is_bot": false,
"headline": "ci: publish prerelease tags under the next dist-tag",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-07-20T12:59:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3f4f12564b256889a3a63dbd67c1bb4931735166",
"body": "Claude-Session: https://claude.ai/code/session_01LZJpmZ7owT3zTTXUprvkB4",
"is_bot": false,
"headline": "chore: bump version to 5.0.0-rc.1",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-07-20T12:59:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "74a60d48f601a658a5de06bd3c24ae2caba0aabd",
"body": "…eased)\n\nStaged as unreleased while 5.0.0 is in RC testing; flip the flag when the\nv5.0.0 tag ships so the sync script creates the GitHub release.\n\nClaude-Session: https://claude.ai/code/session_01LZJpmZ7owT3zTTXUprvkB4",
"is_bot": false,
"headline": "docs(changelog): 5.0.0 entry - skills over MCP + CLI repurpose (unrel…",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-07-20T12:58:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9d071a2d748fa6909b918990df29f57e5d6e37c1",
"body": "- Root README: new 'Agent Skills over MCP' section (serving + CLI + plugin\n bridge), silkweave CLI row notes the 5.0 umbrella->CLI breaking change,\n rewrite the stale session-based 'MCP Streamable HTTP' section (stateless\n since 3.1), current StartMcpHttpOptions table, skills example in dev list.\n[…]\n.1).\n- Website /features: 'Skills, served from your server' section (serve /\n sync-with-lockfile / Claude Code plugin bridge).\n\nClaude-Session: https://claude.ai/code/session_01LZJpmZ7owT3zTTXUprvkB4",
"is_bot": false,
"headline": "docs: 5.0 refresh - skills coverage + stale reference sweep",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-07-20T12:57:58Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ecc1fc9f9b66c09e222fdef40d297f87d66d8cb0",
"body": "Public skills get the native /plugin experience without exposing a repo or\nrunning a registry:\n\n- silkweave skills pack <dir>: wrap one skill into a skills-only Claude Code\n plugin package ready for publishing to npm (package.json + .claude-plugin/\n plugin.json + skills/<name>/). Version from fron\n[…]\npers (cognitive complexity 51 -> 34; was\n already over the 40 cap at HEAD) + fix unhandled _ready rejection on boot\n failure.\n\nClaude-Session: https://claude.ai/code/session_01LZJpmZ7owT3zTTXUprvkB4",
"is_bot": false,
"headline": "feat(skills): npm / Claude Code marketplace bridge (Phase 3)",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-07-20T12:57:50Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f93c8fef1d0f3465d50c0d43fde8b717d8e37797",
"body": "…re CLI\n\nPhase 2 of skills-over-MCP, opt-in while the SEP-2640 draft churns:\n\n- @silkweave/skills: SKILLS_EXTENSION_ID + SkillEntryWire entry shape\n ({uri, frontmatter, resources: [{uri, digest}]}) and aggregateDigest()\n (canonical SKILL.md-first ordering, shared by server and client so\n lockfile\n[…]\nping tests;\n live-verified sync through the extension path against examples/skills\n (now serving with skillsExtension: true).\n\nClaude-Session: https://claude.ai/code/session_01LZJpmZ7owT3zTTXUprvkB4",
"is_bot": false,
"headline": "feat(skills): experimental SEP-2640 extension serving + extension-awa…",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-07-20T11:38:47Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e71d427402be83cc35d237483ade25039d00fef0",
"body": "…e CLI\n\nPhase 1 of skills-over-MCP (design: plans/skills-over-mcp-exploration.md,\ntracks the MCP Skills WG's SEP-2640 resources baseline):\n\n- @silkweave/skills (new): resolveSkills() loader/validator for SKILL.md\n dirs or inline files (edge-safe, lazy node:fs), per-file + aggregate\n sha256 digests\n[…]\n umbrella.ts removed with the umbrella entry points.\n- docs: CLAUDE.md skills section, package READMEs, website docs + sidebar.\n\nClaude-Session: https://claude.ai/code/session_01LZJpmZ7owT3zTTXUprvkB4",
"is_bot": false,
"headline": "feat(skills): serve Agent Skills over MCP + repurpose silkweave as th…",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-07-20T11:29:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a046b20f2324fd00efaad94580f387371aee23b7",
"body": "Claude-Session: https://claude.ai/code/session_01TePv882rKF29J2ZRWmNHX5",
"is_bot": false,
"headline": "chore: bump version to 4.4.0",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-07-20T06:55:57Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d3d75e870b65426f2d2fb94a287d9ebd203b519b",
"body": "Actions can now return a binary or text artifact (screenshot, PDF, JSON/\nmarkdown artifact, audio) instead of a JSON object, declared with the new\ncore binary() output schema and returned as resource(), a Web-Standard\nFile/Blob, or bare Uint8Array/ArrayBuffer bytes.\n\n- core: ActionResource + resourc\n[…]\nion winning\n- examples: render-badge binary action in mcp/fastify/cli examples\n\nEmbed-only by design: no hosted resource links.\n\nClaude-Session: https://claude.ai/code/session_01TePv882rKF29J2ZRWmNHX5",
"is_bot": false,
"headline": "feat(core): binary/text resource results across all adapters",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-07-20T06:55:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ba4dca53157b157408380f4c65d239c76bbedd6e",
"body": "Claude-Session: https://claude.ai/code/session_01KFkrhmA6CzGKeDBPChP6g1",
"is_bot": false,
"headline": "chore: bump version to 4.3.0",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-07-20T04:08:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "432eee36c2c23c40f8d372f0ff97abbffa53ba15",
"body": "buildRouter's inline streaming/buffered branches nested five levels deep\nand tripped the cognitive-complexity fitness gate (55 > 40). Extract\nsubscriptionProcedure/bufferedProcedure helpers - behavior unchanged.\n\nClaude-Session: https://claude.ai/code/session_01KFkrhmA6CzGKeDBPChP6g1",
"is_bot": false,
"headline": "refactor(trpc): extract procedure builders from buildRouter",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-07-20T04:07:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "dbaf296c7a98c36ff90b7f8ddaa49f0a5fd8d140",
"body": "cliProxy can now talk to auth-gated MCP servers without monkey-patching\nglobalThis.fetch: new options headers (record or lazy thunk, resolved once\nper invocation before connecting), requestInit, fetch, and authProvider are\nforwarded to StreamableHTTPClientTransport. A failed connect prints a\nlegible\n[…]\nroxy test suite, README url-string fix, docs across all\nthree layers (READMEs, CLAUDE.md, website incl. new CLI Proxy section).\n\nClaude-Session: https://claude.ai/code/session_01KFkrhmA6CzGKeDBPChP6g1",
"is_bot": false,
"headline": "feat(mcp): cliProxy auth passthrough + positional arguments",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-07-20T04:07:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cf8cbe2aa9e24e181e0047de5074c69f2123d674",
"body": null,
"is_bot": false,
"headline": "chore: bump version to 4.2.0",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-07-17T04:56:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3e4a88a7bdfbdcf9700f2abb4769bb1db0e68b5a",
"body": "…dation failures\n\nToolCallEvent gains an optional args field carrying the call's input on\nevery transport: the parsed (post-zod) input on success and handler-error\nevents (MCP registrar + nestjs tRPC wrapper, per-procedure even inside a\ntRPC httpBatch), and the raw offered input on the new validatio\n[…]\nThe nestjs trpc() adapter emits the same\nevents from tRPC's onError seam (buildValidationErrorEmitter, internal),\ndiscriminated by cause ZodError since tRPC parses input before the\nresolver ever runs.",
"is_bot": false,
"headline": "feat(telemetry): per-call args on ToolCallEvent + events for arg-vali…",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-07-17T04:56:20Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4994437a913402e1df27bc36a3ee03f5648730da",
"body": "Minor release headlined by @silkweave/typegen dropping its `typescript` peer\ndependency (direct .d.ts string emission). Includes a small breaking change to\nthe low-level zodToTs() export (now returns a string). Changelog entry added.\n\nClaude-Session: https://claude.ai/code/session_01Wd61J8MZwTSXNUpRzNaEC5",
"is_bot": false,
"headline": "chore: bump version to 4.1.0",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-07-16T02:58:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6bf4b6ac52e1af6fe18d22961f69470a909c301b",
"body": "…ency\n\n@silkweave/typegen only ever produced .d.ts *text* - it never type-checked -\nso the TypeScript compiler-API AST factory + printer were pure overhead that\nforced a `typescript` peer dependency onto every consumer at server boot. This\nreplaces them with direct string emission, so typegen carrie\n[…]\nevDependency for this package's own build/typecheck.\n- Docs updated across CLAUDE.md, the package README, and the website docs.\n\nClaude-Session: https://claude.ai/code/session_01Wd61J8MZwTSXNUpRzNaEC5",
"is_bot": false,
"headline": "feat(typegen): emit .d.ts as strings, drop the typescript peer depend…",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-07-16T02:58:13Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "13e36fcade43b97714ac7d7b10aaf17e155a549d",
"body": "- rehype-external-links adds target=_blank rel=noopener,noreferrer to external\n markdown links at build time (own-site absolute links excluded)\n- docs.astro hand-authored external anchors get target=_blank rel=noopener,\n matching the existing Footer/Hero/privacy/terms convention",
"is_bot": false,
"headline": "feat(website): external links open in a new tab site-wide",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-07-15T00:08:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "09b874a11b8d4e953aa86d31fe2fd74bfd35b117",
"body": "…ic endpoint\n\nThe key was already committed and served from website/static/<key>.txt (the\ndefault IndexNow key location), so the dynamic [key].txt.ts route and the\nwebsite/.env copy were redundant. The submit script now auto-discovers the\nkey from the static file, with $INDEXNOW_KEY as override.",
"is_bot": false,
"headline": "refactor(seo): use the committed static IndexNow key file, drop dynam…",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-07-14T23:59:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "96aa651625a8e530f20a52991999dfe9b356589d",
"body": "- pnpm indexnow <paths> posts changed URLs to api.indexnow.org\n- website serves the key at /<key>.txt from INDEXNOW_KEY env (no committed key file)\n- key stored gitignored in website/.env; CLAUDE.md documents when to re-submit",
"is_bot": false,
"headline": "feat(seo): IndexNow submission script + dynamic key endpoint",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-07-14T23:21:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "62aa85326dfea3c240c49e3937ed8ddeac9b1943",
"body": null,
"is_bot": false,
"headline": "content(blog): publish \"Automate around the ceremony\"",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-07-14T23:21:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c16a04f3f04f6d6447977abc48cb554eeec211e4",
"body": "Claude-Session: https://claude.ai/code/session_01ByvUdTGYFqkSeW9rCrMsTR",
"is_bot": false,
"headline": "chore: bump version to 4.0.1",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-07-14T07:33:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6174d5a2c0109db5557bf59f41c32b8d3da1ed97",
"body": "…o snake_case schema keys\n\nSame bug as the cliProxy fix: options register as kebab-case flags and\ncommander stores them camelized, so snake_case input keys never received\ntheir values. Adds vitest to @silkweave/cli with regression coverage.\n\nClaude-Session: https://claude.ai/code/session_01ByvUdTGYFqkSeW9rCrMsTR",
"is_bot": false,
"headline": "fix(cli): read commander opts via camelCase so kebab-case flags map t…",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-07-14T07:32:16Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0db2adf4f8dd0e56994442085643c0f63de037f0",
"body": "…o snake_case schema keys\n\nOptions register as kebab-case flags (--action-id) and Commander stores parsed\nvalues camelized (actionId), but the action read them back with the raw schema\nkey (action_id) — so every multi-word parameter was silently dropped and tools\nlike run-now failed with 'action_id \n[…]\n\n'run-now --action-id warehouse-derive' now passes the argument through.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01SpfNKoTpsgVqzN1NFK49SQ",
"is_bot": false,
"headline": "fix(mcp): read cli-proxy args via camelCase so kebab-case flags map t…",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-07-14T06:34:37Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "9035d2b5c0d9e1a30d8be1f65f2daf218396196a",
"body": "Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VRoG28Kx1Y3sREXVVD3jmu",
"is_bot": false,
"headline": "chore: bump version to 4.0.0",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-07-13T08:42:53Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "d82c22da515e42f17ed80b03c2e0ddeb4ffa8916",
"body": "… it uses\n\nBREAKING CHANGES from the post-3.2 deep audit. Migration is mostly import-path\nand install changes; runtime behavior is unchanged.\n\n- @silkweave/mcp: the Express http() server + its mountable handlers\n (mcpTransport, oauthRoutes, protectedResourceMetadata, sideloadResource,\n mcpCors, au\n[…]\nt, no\nALS); core has no dependencies. pnpm check green, 226 tests pass.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VRoG28Kx1Y3sREXVVD3jmu",
"is_bot": false,
"headline": "feat!: dependency-boundary cleanup - every package installs only what…",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-07-13T08:42:00Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "5a0130fddc5f91da01bd7b87e0c616fabc28f68d",
"body": "- Force-patch transitively-pulled vulnerable dev/website deps via pnpm\n overrides (shell-quote 1.10.0, ws 8.21.0, qs 6.15.2, hono 4.12.29,\n js-yaml 4.3.0) and bump website astro to 6.4.8. Closes the Dependabot\n critical (shell-quote) + the astro/ws/hono/js-yaml alerts. Per the audit\n triage none\n[…]\npe does not\n strip fields before a guard/handler reads them over MCP).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VRoG28Kx1Y3sREXVVD3jmu",
"is_bot": false,
"headline": "chore: dependency remediation + edge portability (post-audit follow-up)",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-07-13T08:18:07Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "847f6cd831242aeee57826326562de5e80f3fec0",
"body": "Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VRoG28Kx1Y3sREXVVD3jmu",
"is_bot": false,
"headline": "chore: bump version to 3.2.1",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-07-13T08:09:08Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "ce002701fb0e40c8efdb6fae5479e3b0a7544484",
"body": "A multi-agent audit (per-dimension finders + adversarial verification)\nsurfaced 40 confirmed findings. This lands the reachable security fixes\nand the self-contained correctness items; dependency-boundary refactors\nare deferred to a follow-up. No public API breaks.\n\nSecurity (reachable, verified):\n-\n[…]\nion, and the structured toolResult guard. pnpm check + 226 tests green.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VRoG28Kx1Y3sREXVVD3jmu",
"is_bot": false,
"headline": "fix: security + correctness patch batch from the post-3.2 deep audit",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-07-13T08:08:12Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "56e365f5987d26f2fff3dc50cb0e075b4ee9c624",
"body": "Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VRoG28Kx1Y3sREXVVD3jmu",
"is_bot": false,
"headline": "chore: bump version to 3.2.0",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-07-13T03:19:57Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "1afac565f2430bf1e41663f9ce6ea54e78dced8d",
"body": "Website docs gain Tool Results (json default, smart, structured),\nPer-Request Tool Filtering, and Telemetry sections (+ sidebar entries);\nthe Action interface reference covers annotations/tags/disposition.\nRoot README adds an MCP Tool Quality section. Changelog entry for\n3.2.0 with the json-default flip flagged as breaking.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VRoG28Kx1Y3sREXVVD3jmu",
"is_bot": false,
"headline": "docs: website + root README + changelog for the 3.2 MCP quality batch",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-07-13T03:19:43Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "3a7f6fef1342562c03de37be85c34446eb635127",
"body": "Core defines ToolCallEvent/OnToolCall/emitToolCall() - one event per\ntool/procedure invocation, fire-and-forget (never awaited on the call\npath; hook errors logged and swallowed). The MCP registrar emits after\nresult formatting, so MCP events carry resultBytes and sideloaded;\nok:false covers thrown \n[…]\nnt as failed calls; async *\nsubscriptions span full stream consumption).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VRoG28Kx1Y3sREXVVD3jmu",
"is_bot": false,
"headline": "feat: onToolCall telemetry hook (MCP adapters + nestjs DI wiring)",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-07-13T03:12:33Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "1c9e5d7f983351fd6068b525dc1669dbd6330ae8",
"body": "…tion.tags\n\nfilterActions?: (actions, request) => Action[] | Promise<Action[]> on\nhttp()/mcpTransport()/edge()/nestjs mcp() runs before registerTools()\non every POST - the stateless transport recomputes the tool list per\nrequest, so per-API-key scoping is a single callback and permission\nchanges app\n[…]\ng to its ESM build under require). @silkweave/edge\ngains a vitest setup.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VRoG28Kx1Y3sREXVVD3jmu",
"is_bot": false,
"headline": "feat(mcp): per-request filterActions on the stateless transports + Ac…",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-07-13T03:01:58Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "a9edf71395d84dd2b515ab7de7323608d678b346",
"body": "…lips to json\n\nBREAKING: the fallback MCP result disposition is now 'json' (compact\nJSON text) instead of 'smart'. Set disposition: 'smart' per action, or\ndefaultResult: 'smart' in @silkweave/nestjs, to restore payload\nsideloading.\n\ndisposition: 'structured' declares the action's output schema as th\n[…]\n\n@ApiOkResponse boot-errors; @Trpc({ output }) is reused when explicit).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VRoG28Kx1Y3sREXVVD3jmu",
"is_bot": false,
"headline": "feat(mcp)!: structured output via disposition 'structured'; default f…",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-07-13T02:41:24Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "bd3cb4f745c2831153e4551a972753e6f478744c",
"body": "Action gains an annotations field (ToolAnnotations, defined in core so\nnon-MCP packages need no SDK type dependency). registerTools() forwards\nit to registerTool() over a kind-derived base (query => readOnlyHint).\n@silkweave/nestjs derives defaults from the HTTP verb (@Get => read-only\n+ idempotent,\n[…]\nmpotent)\nand exposes an @Mcp({ annotations }) override merged over them.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01VRoG28Kx1Y3sREXVVD3jmu",
"is_bot": false,
"headline": "feat(mcp): tool annotations with derived read-only/destructive hints",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-07-13T02:32:32Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "3f4421db2b197958fb6e51fbfbe12e3748256c09",
"body": null,
"is_bot": false,
"headline": "add indexnow key",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-07-09T22:19:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e8827ca5ff6b13e7d88eec7071f7e01e5338d75c",
"body": "…AI workbench\"\n\nCanonical post for the shared-mac-mini-ai-workbench initiative: hero image\nfrom the teaser render, 29s teaser video embedded after the intro\n(static/videos/), LinkedIn share link wired; reddit link to follow once the\nr/ClaudeCode post is live.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "content(blog): publish \"Give your agents a home: our shared Mac mini …",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-07-08T03:30:06Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "569a01b5d37688d30ea2c53437c99d0366f7179e",
"body": "Aligned minor bump across all packages. Prepends the 3.1.0 changelog entry:\n@silkweave/logger folded into @silkweave/core, @clack/prompts dropped repo-wide,\ndead zod@3 dependency removed.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01UXiPbPDb2fRir1CeVvVAX1",
"is_bot": false,
"headline": "chore: bump version to 3.1.0",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-07-08T00:20:55Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "efa818d54cce931e953671b4fade6bf8765c9a8e",
"body": "…d clack\n\nThe structured logger is the shape of the `context.get('logger')` key every\naction receives, so it belongs in core - and it is zero-dependency. Move the\n`Logger`/`LogLevel` types, `createLogger()`, and `buildLogLevels()` from the\nstandalone `@silkweave/logger` package into `packages/core/s\n[…]\noverage.\n\nDocs updated across CLAUDE.md, root/umbrella/cli/mcp READMEs.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01UXiPbPDb2fRir1CeVvVAX1",
"is_bot": false,
"headline": "refactor: fold logger into @silkweave/core, drop @silkweave/logger an…",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-07-08T00:20:02Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "2f95133c459e6e5d5ff9a1cd8e8c55dbe9de7014",
"body": "A depth-vs-breadth teardown of the Claude Max tier choice: the 5x/20x\nmultipliers price per-session usage, not the weekly cap, so for most\nsolo builders the upgrade is the wrong purchase. Canonical long-form;\nthe Reddit adaptation is already live and cross-linked.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "content(blog): publish \"Claude Max: two 5x accounts vs. one 20x\"",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-26T15:39:08Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "4efbb985a4cbe35d8d57e62c5460569af33f5e69",
"body": "Add /privacy and /terms legal pages ahead of Google and GitHub\nsingle-sign-on launch, and link both from the footer.\n\nThe privacy policy is written to satisfy Google's API Services User\nData Policy: it discloses how account data (name, email, avatar,\nprovider account ID) is accessed, used, stored, a\n[…]\n international\nusers; terms are governed by Singapore law.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01UXiPbPDb2fRir1CeVvVAX1",
"is_bot": false,
"headline": "docs(website): add privacy policy and terms of service pages",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-26T08:44:42Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "2ab65a20c1b063f947dee910b6637f63c6190d1c",
"body": "Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_014eZqj8nbJrmyJoRo8csUkX",
"is_bot": false,
"headline": "chore: mark 3.0.0 changelog entry as released",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-21T00:31:14Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "8436d319c45a71155f008d52ceba4f62b2f8cabf",
"body": "Aligned major bump across all packages for the 3.0 release (breaking: stateless\nMCP transport, @silkweave/auth split, express-optional peers, @silkweave/vercel\nrenamed to @silkweave/edge).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore: bump version to 3.0.0",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-21T00:17:08Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "8e7e97050b47af01c20f9ffc71014f79c1e8ea29",
"body": "…inter; add 3.0.0 changelog\n\nBack-fill docs for the 3.0 features that shipped without user-facing docs, and\nprepare the release notes:\n\n- changelog: prepend the 3.0.0 entry (marked unreleased until the v3.0.0 tag is\n pushed) covering the stateless transport, auth split, express-optional path,\n OAu\n[…]\nE: correct the package-table rows for @silkweave/auth (lead with the\n resource-server core) and @silkweave/logger (pino was dropped in 2.6.1).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: document 3.0 auth split, express-optional MCP, and the action l…",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-21T00:17:08Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "44f5257b8e4dcc79195927603e4d2ae0e2f24d30",
"body": "…are example; stateless 405 guard\n\nBREAKING CHANGE: @silkweave/vercel is renamed to @silkweave/edge, and its\nadapter `vercel()` to `edge()` (types VercelAdapter/VercelAdapterOptions ->\nEdgeAdapter/EdgeAdapterOptions; umbrella subpath silkweave/vercel ->\nsilkweave/edge). The adapter is platform-agnos\n[…]\nbsite\n for the rename + new example. Genuine Vercel-platform and Vercel AI SDK\n references preserved (only the adapter/package name changed).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "refactor(edge)!: rename @silkweave/vercel to @silkweave/edge; Cloudfl…",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-20T23:48:37Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "ad52cc9dd63f552c2c2441d5b1a449b5a8bff2fd",
"body": "M6 - ecosystem guardrails (help implementers avoid costly agent-facing mistakes):\n- New `lintActions()` / `reportActionLint()` in @silkweave/core: static checks\n for agent-hostile action defs - missing or throwaway `description` (the model\n reads it to decide when to call a tool) and undescribed i\n[…]\ne\ncache metadata (SEP-2549), structured outputSchema, Tasks (SEP-2663).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01AyuJCEknqUHmvNGF3Eb8Hb",
"is_bot": false,
"headline": "feat(core): action linter guardrail for agent-friendly tool definitions",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-20T07:57:34Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "4c0d13ddb0cefb52c9eb4864dfc6e0bd015fe4df",
"body": "M5 - harden the resource-server core (delegated-IdP path):\n- Audience binding (RFC 8707 / SEP-2352): reject a verified token whose `aud`\n does not include this resource - the confused-deputy defence. Configurable\n via `AuthConfig.audience` (defaults to `resourceUrl`; `false` to skip).\n A token wi\n[…]\nuth README.\n\nbuild 16/16, lint+check+test 68/68 (new auth suite green).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01AyuJCEknqUHmvNGF3Eb8Hb",
"is_bot": false,
"headline": "feat(auth): resource-server hardening for the 2026 OAuth SEPs",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-20T07:52:19Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "832100f114f4b3d0f379511840b6ba7a3def861b",
"body": "…ptional peers\n\nM4 - dependency trim + integration primitives:\n- New express-free `@silkweave/mcp/tools` subpath re-exporting the\n transport-agnostic shared code (registerTools + result helpers).\n- `@silkweave/vercel` imports from `@silkweave/mcp/tools`, so the\n web-standard / serverless path (ver\n[…]\n\nof `@silkweave/mcp`. Web-standard consumers no longer install Express.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01AyuJCEknqUHmvNGF3Eb8Hb",
"is_bot": false,
"headline": "refactor(mcp,vercel)!: express-free web-standard path; express/cors o…",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-20T07:46:45Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "5c82214803f7d3b324bb56f3b9d3492f6b023195",
"body": "…ce-server core / opt-in OAuth\n\nSilkweave 3.0 groundwork (M1 + M3-lite of the plan), landed on the\n1.29.0 SDK so it ships independently of the unpublished MCP v2 SDK.\n\nM1 - auth split (@silkweave/auth):\n- Root barrel is now the spec-required resource-server surface only:\n bearer validation + RFC 97\n[…]\ntp() adapter\nis stateless: GET/DELETE /mcp and Mcp-Session-Id are gone.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01AyuJCEknqUHmvNGF3Eb8Hb",
"is_bot": false,
"headline": "refactor(mcp,auth)!: stateless MCP transport + split auth into resour…",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-20T07:34:19Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "1c3f52a6aa5a720b68c4bc9343d04b7ff3b0db11",
"body": "Adds a `turbo test` step to ci.yml (every push to master + PRs) after\nlint/typecheck, and to publish.yml before `pnpm publish` so a release cannot\nship with a failing suite. Tests run on TS source via the @silkweave/source\ncondition, so they need no build of their own. Updates the CLAUDE.md CI/CD notes\nand the wrapup test entry (no longer \"skip\") with how to add Vitest to a package.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "ci: run the Vitest suite in CI and gate publishing on it",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-19T13:32:47Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "44685e300f53b190b04d80d83591984cafd3a145",
"body": "Specs route reflection via real @Controller + verb decorators (runtime metadata,\nindependent of design:type): controller+method path composition with :param\nextraction and the OpenAPI {param} form, controller-path fallback for path-less\nmethods, every HTTP verb mapping, leading/trailing slash normalization, a\nprefixless controller, and the GET / empty-path default when no metadata exists.\n\n6 tests; full gate green (67 tasks).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "test(nestjs): cover reflect/route composition",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-19T13:32:04Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "0dce70b49f925793365c6b01ca36a9bcd4d8edfa",
"body": "Wires Vitest into @silkweave/trpc and specs the error mapper that gives guard\ndenials the right wire code:\n\n- TRPCError passes through untouched\n- ZodError -> BAD_REQUEST (message carried)\n- SilkweaveError statusCode -> tRPC code (400/401/403/404/429), message + cause\n preserved; unmapped status ->\n[…]\n3 from an @UseGuards denial as a FORBIDDEN TRPCError\n(data.httpStatus) over the tRPC adapter. 7 tests; full gate green (67 tasks).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "test(trpc): cover mapError status/code mapping",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-19T13:29:22Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "b44c36ca375867152e97dc1cdfa81dbb9ed2898b",
"body": "Specs the pure FieldDesc -> Zod conversion and per-source mappers directly (no\ndecorators, so independent of design:type emission):\n\n- mergeField precedence (defined-over-wins, no undefined clobber)\n- fieldToZod: constrained string/integer(float-reject)/number, array-of-items,\n object-record, strin\n[…]\ntem-array / itemless-array, keeps\n enum/object/typed (the nested-DTO degradation detector)\n\n21 tests; full gate green (66 tasks).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "test(nestjs): cover the reflect/schema converter hub",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-19T13:26:16Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "21051abde3f66e05c4c4df46734c376a9e4f9e4b",
"body": "- isStreamingAction: true only for an async-generator run; false for async/sync\n functions and a missing run.\n- runStreamingAction: throws on a non-streaming action, buffers chunks in order,\n invokes onChunk per chunk with a zero-based index, awaits onChunk before\n pulling the next value (the bac\n[…]\nuarantee, asserted via yield/consume\n interleaving), and returns [] for an empty generator.\n\n8 tests; full gate green (66 tasks).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "test(core): cover the streaming runner and isStreamingAction",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-19T12:50:08Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "c870d0b333eb7336d714fdcba779a362a8bdf48f",
"body": "Specs the zero-dependency structured logger (the de-pino'd default forked into\nthe MCP action context):\n\n- createLogger: structured JSON line per call (object data merged, scalars under\n msg), severity-threshold gating, stream:false discarding output while onLog\n still fires, onLog firing alongsid\n[…]\nwhich skips the stream).\n- buildLogLevels: a function per level routed through one callback.\n\n8 tests; full gate green (66 tasks).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "test(logger): cover createLogger and buildLogLevels",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-19T12:48:43Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "33b2d22d1f3764674be2b48c9a59c3364c91fe9b",
"body": "… test\n\nDrives a real @Controller with @Post + @Body + @UseGuards(ApiKeySessionGuard) +\n@Mcp through ControllerDiscovery (real MetadataScanner/Reflector, faked\nDiscoveryService/ModuleRef) and exercises the synthesized MCP action's run():\n\n- discovery yields one action named Messages.send with the @B\n[…]\nody (reconstructed from the validated input), deciding\nidentically to how it would over REST. 7 tests; full gate green (65 tasks).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "test(nestjs): end-to-end ControllerDiscovery auth-scoping integration…",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-19T12:46:26Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "79c4fd1330829eb35bb5f795ac149cad04ca311b",
"body": "Wires Vitest into @silkweave/mcp and specs the result helpers every MCP adapter\n(and the OpenWA port) leans on:\n\n- smartToolResult: small string/object payloads as a single text block; payloads\n over 4096 chars split into a summary + base64 embedded resource (.txt/text-plain\n vs .json/application-\n[…]\ning leaks to the wire.\n- parseResourceMessage: base64 blob vs inline text.\n\n13 tests; full turbo lint+check+test green (65 tasks).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "test(mcp): cover tool-result formatting and error handling",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-19T12:41:21Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "bf8c8912746e8145d4d5e8243073135d7b9fd42f",
"body": "Wires Vitest into @silkweave/core and adds specs for the pure utilities the\nFastify REST adapter and CLI depend on:\n\n- http.ts: actionMethod (explicit verb vs kind default), methodHasBody,\n pathParamNames, validateActionRouting (throws SilkweaveError on a :param or\n queryParams entry missing from \n[…]\natic + function\n defaults) and nested combinations down to the base type.\n\n21 tests; full turbo lint+check+test green (64 tasks).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "test(core): cover HTTP routing helpers and the zod unwrap utility",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-19T12:39:18Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "5d2fd061e95fadd8ec16c01d287cb2be51830a85",
"body": "…guards\n\nAdds specs for the three modules the auth-over-MCP path runs through:\n\n- executionContext: switchToHttp/Rpc/Ws hosts, getType (http vs rpc), class/\n handler/args exposure - what a guard reflects against.\n- rebind (invokeRebound/resolveArg + specialBinding): value/object/params field\n reco\n[…]\nt type faithfully\n (the ApiKeyGuard shape the OpenWA bar needs).\n\n42 tests across 4 files, all green under turbo lint+check+test.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "test(nestjs): cover the guard/auth path - execution context, rebind, …",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-19T12:35:52Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "4c7c56038df64fc99a1178d563e96a34b78c5dd6",
"body": "…construction\n\nIntroduce Vitest as the test runner (simpler + ESM-native vs jest). A shared\nvitest.shared.ts sets resolve.conditions to the custom @silkweave/source\ncondition so specs import cross-package TS source with no build step, mirroring\nthe example Vite/Astro configs. Each package re-exports\n[…]\ns/query/body routing and\npopulation, including the OpenWA scenario: a @Body-sourced scope id is now\nreadable at req.body over MCP.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "test(nestjs): add Vitest, extract request-slot helpers, cover slot re…",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-19T12:26:27Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "4d33fff635449a2ee4eaaf00c028cba48e2c41b2",
"body": "…ansport-transparent guards\n\nGuards over MCP previously only saw faithful headers + path params; query was\nempty and body was never mirrored onto the request stand-in. A scope-enforcing\nguard reading req.query[...] or req.body[...] therefore decided differently over\nMCP than over REST.\n\nrequestSlotF\n[…]\nth (e.g. per-key session\nscoping) runs transport-transparently. Docs updated across CLAUDE.md, the nestjs\nREADME, and the website.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(nestjs): reconstruct request params/query/body from input for tr…",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-19T12:16:53Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "3bf38bcad0659cfe7bad4feaf55f0c74b2211ff5",
"body": "Link the pino-drop / CLI-proxy de-leak highlights to release commit 6528d3b.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01N9drwEfiN8xdBbqztg7iHC",
"is_bot": false,
"headline": "docs(changelog): add 2.6.1 release entry",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-18T12:56:49Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "6528d3bee3802ccae3525ef1af78e6a61ad1dab6",
"body": "…er path\n\nSlims the dependency tree, especially for MCP + NestJS adopters.\n\n- @silkweave/logger: createLogger() is now a zero-dependency structured\n logger (JSON lines to a stream, level threshold, onLog/onProgress); pino\n dropped entirely. Only hard dep is now zod.\n- @silkweave/core: drop the unu\n[…]\nero-dep utility\n(change-case). Bump all packages to 2.6.1.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01N9drwEfiN8xdBbqztg7iHC",
"is_bot": false,
"headline": "refactor(logger,mcp,core): drop pino, de-leak CLI proxy from MCP serv…",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-18T12:56:31Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "393a3fd4486d2c97637f9fa675cbda5690d22281",
"body": "NestJS reflection diagnostics (unreflectable-param + degraded-output\nwarnings), nullable reflection, ZodObject/zod-v4 input overrides, and\n@Res() over the tRPC transport. Prepend the 2.6.0 changelog entry.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore: bump version to 2.6.0",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-18T03:02:57Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "4f448e57d41b53ab36af32689f5b9be692ad9992",
"body": "…ect input, @Res over tRPC\n\nImprovements surfaced migrating a real app against the NestJS reflection layer:\n\n- Warn at boot when a whole-DTO @Body()/@Query() reflects to zero fields\n (intersection/union types erase to Object under design:type, silently\n dropping every DTO field). A ({ input }) ove\n[…]\n work) and undefined over MCP.\n\nDocs updated across CLAUDE.md, the package README (incl. zod v3/v4 interop),\nand the website docs.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(nestjs): warn on unreflectable params/outputs, nullable + ZodObj…",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-18T03:01:18Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "9536f75f57370e14150ad0ef4fae819e3ec74f10",
"body": "- astro: trailingSlash 'never' + build format 'file' so /path/ 308s to /path\n (kills trailing-slash duplicates); sitemap drops the slash to match canonical\n- exclude /test from sitemap (live tRPC demo, no inbound links) and noindex it\n- Layout: add noindex prop emitting <meta name=\"robots\" content=\n[…]\nthe\n unwarranted Software App rich-result requirements; tighten meta descriptions\n- turbo: add .vercel/output/** to build outputs\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "seo: fix trailing-slash canonicals, sitemap, noindex, alt text, JSON-LD",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-18T02:37:09Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "f7dc392ddb220fae0a8c22765733d309d3d3c099",
"body": "Add a CI/CD section covering ci.yml (lint/typecheck) and publish.yml\n(OIDC trusted publishing on vX.Y.Z tags), update the Wrapup Config publish\nline away from manual pnpm publish:all, and note the tag-must-contain-workflow\nand pnpm>=11.1.0 OIDC constraints.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: document GitHub Actions CI + npm trusted-publishing flow",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-18T01:36:59Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "c4b7bbdaaa5ce2c07e20dab4997bc25c1eb5962d",
"body": "CI verified green; activate publish.yml so vX.Y.Z tag pushes publish all\npackages to npm via OIDC trusted publishing (pnpm publish -r).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "ci: enable npm trusted-publishing workflow",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-18T01:26:39Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "7d7f0112b719319560b614898943dc3a79ba9d74",
"body": "…blish disabled for now)\n\nCI runs build + turbo lint/check on push to master and PRs.\nPublish workflow (OIDC trusted publishing via pnpm publish -r on vX.Y.Z tags)\nis staged as publish.yml.disabled until CI is verified green.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "ci: add lint/typecheck workflow + npm trusted-publishing workflow (pu…",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-18T01:21:20Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "ae2f550d44fa929e22a76426e297194efecf0163",
"body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01GVH5fwyJS8BUmR7EVwjNzw",
"is_bot": false,
"headline": "chore: bump version to 2.5.0",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-18T00:56:20Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "6b01553621e90fb1a203d3f4f2fba4020019095a",
"body": "…th exports\n\nAdd the tRPC sibling of @Mcp to the controller-reflection model so a single\nNestJS controller method can serve REST, MCP, and end-to-end-typed tRPC at once.\n\n- @Trpc() reflects input like @Mcp, plus output types (from @ApiOkResponse or\n @Trpc({ output })), verb-inferred kind, and async\n[…]\nLAUDE.md, README, website) and the nestjs example updated.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_01GVH5fwyJS8BUmR7EVwjNzw",
"is_bot": false,
"headline": "feat(nestjs): @Trpc decorator + trpc()/typegen() adapters, with subpa…",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-18T00:55:32Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "ec6871b3edf27bccf337be0b5c757906a1f8eb1f",
"body": "… 4-card set\n\n- /adapters listed only 6 cards but the heading/site say seven; add the missing\n Typegen build-time adapter so the page matches 'Seven adapters'.\n- /integrations: replace the uneven prose intro with a 'Four ways to integrate'\n card grid (NestJS, Next.js, Standalone, Vercel AI SDK) - \n[…]\nk each - so the four read as one consistent peer set. Invert the\n Vercel currentColor mark to white so it shows on the dark card.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(website): add 7th adapter (Typegen) + redesign integrations as a…",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-17T02:24:03Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "342db38ed2c6bbdc7fcc0782afe69a52295fb53c",
"body": "…abels\n\n- Fix cramped deep-dive cards: the .dd-cards > li padding reset was overriding\n .dd-card padding on cards that are the <li> itself (features, how-it-works),\n zeroing it. Scope the reset to wrapper <li>s (:not(.dd-card)) so every card\n keeps its 1.5rem padding; bump grid gap to 1.25rem to \n[…]\nn the nav logo and\n 'Silkweave on GitHub' on the footer brand link (both previously resolved to a\n bare, ambiguous 'Silkweave').\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(website): card padding, footer heading order & descriptive link l…",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-17T02:01:01Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "4c9e017a4b46989dd360cdbc991e019d34228376",
"body": "- Homepage 'Read the full documentation' now uses the shared .section-deeper\n outline button (matches the 'Dive deeper' CTAs)\n- Deep-dive pages use the same .container width (--max-width) as the homepage\n so content aligns with the top-nav logo\n- Fix broken adapter cards: linked .dd-card anchors r\n[…]\nls flex so cards (li or inner <a>) fill the cell as equal-height boxes,\n with the package tag / card link pinned along the bottom\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(website): docs CTA button, deep-dive container width & card layout",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-17T01:41:20Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "363c751f169622873386ee789bb9b7bb1f860d97",
"body": "…hlighting\n\n- Top nav now links to the deep-dive pages (/how-it-works, /adapters,\n /integrations, /features) instead of homepage scroll anchors; drop the\n redundant Quick start item (hero CTA still covers it)\n- 'Dive deeper' links restyled as centered outline buttons (like the header\n Read the Do\n[…]\ne: accent header glow,\n gradient headings, pill eyebrows, card grids (.dd-cards), numbered/linked\n cards, and callout/info boxes\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(website): polish deep-dive pages + wire nav, buttons, syntax hig…",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-17T01:32:54Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "bdda293ebde9b77b4b2eff9014e22a755a964058",
"body": "Keep the homepage one-pager, but add four prerendered deep-dive pages -\n/how-it-works, /adapters, /integrations, /features - each with unique,\nexpanded prose (its own h1, intro, sections) targeting long-tail queries and\ncross-linking into /docs#anchors. /docs stays the single API reference, so\nthere\n[…]\n.section-deeper)\n- Pages auto-join the sitemap; fixed two stale /docs#anchor targets\n (#adapter-mcp-stdio/http, #adapter-typegen)\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(website): add section deep-dive pages for SEO depth",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-17T01:16:04Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "0fc879d08a1803abb8881f09bc57c82a317f9fe5",
"body": "…itle\n\n- JSON-LD structured data: SoftwareApplication (home), BlogPosting +\n BreadcrumbList (blog), TechArticle + BreadcrumbList (docs)\n- Default 1200x630 og.png social card so every page renders a share image\n (blog posts keep their own); add og:site_name, og:image dims, and\n twitter:site/creato\n[…]\ned homepage <title>/description ('TypeScript toolkit for MCP\n servers, REST APIs & CLI tools') and a keyword-bearing hero eyebrow\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(website): SEO foundations - JSON-LD, social card, RSS, keyword t…",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-17T01:06:36Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "c34fd3c68d1d539a2cc423accfbd88a663d2db07",
"body": "DocsLayout rendered <Layout title> without a slug, so Layout's canonical\nfell back to the site root - the docs page advertised the homepage as its\ncanonical URL (flagged by PageSpeed Insights). Forward slug='docs' (⇒\nhttps://www.silkweave.dev/docs) and a docs-specific meta description.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(website): set canonical URL + description on docs page",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-17T00:50:52Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "89fc589daf7bc85bdcb987a0e85257928c19528f",
"body": "…:global()\n\nThe previous attempt set .integration-card code, but that rule is Astro\ncomponent-scoped (gets a data-astro-cid attribute), while the card's inline\n<code> is injected through set:html and carries no scoping attribute - so the\nrule never matched and the code kept inheriting --text-dim (4.\n[…]\nCAG AA). Target it with .integration-card :global(code)\nand use --text, rendering the inline code at ~12.7:1. Verified in-browser.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(website): actually fix integration-card inline code contrast via …",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-17T00:37:21Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "b0931997f4d5022348e0ffaed6af944a1d5f9177",
"body": "The nav/footer/integration-card logos sit beside visible name text\n(\"Silkweave\" wordmark, or the card's <h3> label), so a descriptive alt\nduplicates that text and screen readers announce it twice (flagged by\nLighthouse). Mark the logos decorative with alt=\"\" - matching the existing\ndocs.astro heading logos - and drop the now-unused logoAlt data fields.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(website): use empty alt on logo images adjacent to wordmark text",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-17T00:29:03Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "10b96b5863c922be1ffcc7205f6943af230f774a",
"body": "Inline <code> in the integration cards inherited --text-dim (#7e7e94) on\nthe --accent-bg (#1e1b4b) card background, yielding only 4.03:1 contrast -\nbelow the 4.5:1 WCAG AA threshold (flagged by Lighthouse, 11 nodes). Set an\nexplicit #9a9ab0 on .integration-card code for ~5.8:1 while staying tonal\nwith the dim palette. Scoped to the cards so docs inline code (bright\n--text) is unaffected.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(website): meet WCAG AA contrast for integration-card inline code",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-17T00:21:14Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "4a2e95e6c8e90fbbf8e7c629b53341cb04ad16df",
"body": null,
"is_bot": false,
"headline": "Fix vercel image serving",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-17T00:12:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8bd352f0331aedb1303b1b077b4149100b94ba76",
"body": null,
"is_bot": false,
"headline": "Add support request message",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-16T14:13:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e06dae433f9f0e5b650ea09f0a5b096abfe64282",
"body": "…lease tooling (v2.4.0)\n\nPackages:\n- @silkweave/nextjs — Next.js App Router adapter. defineSilkweave({ actions })\n projects one action set onto route handlers: app.mcp() (MCP tools) + app.trpc()\n (typed tRPC). Wraps vercel() + trpcFetch(); App Router only, no next/react dep.\n- NestJS: SilkweaveMod\n[…]\nicense/homepage/bugs metadata on every package\n- .gitignore .next/; turbo build outputs include .next\n- Bump all packages to 2.4.0\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat: @silkweave/nextjs adapter, NestJS defaultResult, changelog & re…",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-16T13:58:30Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "9a447bc8fe8b10f3116b44c091c275b629aed138",
"body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore: bump version to 2.3.0",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-16T12:25:05Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "1eeab3ee1dd438125abea8d8a10f31f46e58a6a4",
"body": "Add an action-level `disposition: 'json' | 'smart'` default that selects\njsonToolResult vs smartToolResult for MCP tool results. The MCP transport\nnow falls back to this default when the client omits `_meta.disposition`,\nso a client's per-call disposition still wins (client → action → 'smart').\n\nNes\n[…]\non's `disposition`. Docs updated across CLAUDE.md, package READMEs, and\nthe website; nestjs example demonstrates `result: 'json'`.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(nestjs): configurable MCP result format via @Mcp({ result })",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-16T12:24:36Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "75f2529b74c9a6ccc90c665e7e1ec8dcf3b4f956",
"body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore: bump version to 2.2.0",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-16T02:23:15Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "c98f7734e5f07192e002a1f9a21a507aa2895def",
"body": "…s (MCP)\n\nPath params reached the handler (via the reflected input -> @Param rebind)\nbut never request.params, so any req.params-reading guard was blind to them\nover MCP. Concretely, a session-scoped guard (OpenWA's ApiKeyGuard checking\nallowedSessions via request.params['id']) failed open over MCP \n[…]\n=allowed and\ndenies id=denied over the MCP run path (ForbiddenException), where before the\nfix params was {} and both were denied.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(nestjs): populate request.params from path bindings before guard…",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-16T02:22:59Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "37e70e79e4ce2b96a47027bda135702e2f533273",
"body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore: bump version to 2.1.0",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-16T02:11:27Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "34501fe3187054e7402593f1eb3a8c4dc747ffce",
"body": "handleToolError() put error.stack on the wire for any non-SilkweaveError\n(and the raw thrown value in the unknown branch), exposing server internals\nto the MCP client. Nest's UnauthorizedException is a plain Error, so every\nauth failure shipped a full stack trace to callers.\n\nReturn only { success, \n[…]\n to the client via notifications/message, which would re-leak.\n\nThe vercel adapter reuses handleToolError, so it inherits the fix.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(mcp): stop leaking stack traces in tool error results",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-16T01:42:31Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "29c458197ac132b30d19966fe50fd33f2f04ea76",
"body": "…or in-repo dev\n\nExternal consumers (npm/pnpm install, pnpm link) previously resolved to raw\nTS source because main pointed at src/index.ts and the build entry lived only\nin publishConfig (which link/install ignore). Adopt a dual-resolution setup so\nexternal consumers always get build/ while in-repo\n[…]\nndex.d.mts (typechecks clean); in-repo tsc/tsx/node + Vite resolve to\nsrc; pnpm build + check green; tarball contains build/ only.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(build): resolve published packages to build output, keep source f…",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-16T01:42:24Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "aff769d896f01bbb9996d8d97e752358b036cfe4",
"body": "App-global guards (registered via app.useGlobalGuards() or\n{ provide: APP_GUARD, useClass }) previously never ran on MCP tool calls -\nonly method/class @UseGuards did. Add an opt-in allow-list so e.g. an\nApiKeyGuard can authenticate tool calls.\n\n- collectGlobalGuards() reads ApplicationConfig.getGlo\n[…]\nd guards (e.g. ThrottlerGuard, which needs a writable response\nMCP can't provide). Documented the headers-only MCP request caveat.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(nestjs): honor opt-in app-global guards on MCP tool calls",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-16T01:41:59Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "430b3d839bc4ae3cfee233f0d123f6fbc6b63ef1",
"body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore: bump version to 2.0.0",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-15T04:28:45Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "c66ff63d1d89ef717b8944a147d14230e7975922",
"body": "Replace the @Action/@Actions provider-decorator model with an additive\n@Mcp() decorator on existing NestJS controller routes. The tool name,\ndescription, and input schema are reflected from the route, the\n@Param/@Query/@Body decorators, and any @nestjs/swagger / class-validator\nmetadata the method a\n[…]\nand their now-unused deps)\n- Example reworked to real @Controller + @Mcp; docs updated across\n README, CLAUDE.md, and the website\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(nestjs)!: expose existing controllers as MCP tools via @Mcp",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-15T04:28:08Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "7b0db1ec705deb21cd9657ade36cc702f2f1aa1b",
"body": "Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore: bump version to 1.12.0",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-14T23:36:33Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "b6db6bcb34dfa6aa1707da2a9d31281745d7e64b",
"body": "pnpm 11 no longer reads the `pnpm` field in package.json (onlyBuiltDependencies,\noverrides, peerDependencyRules), which caused every `pnpm install` to rewrite\npackage.json. Remove the dead field and approve the @scarf/scarf build script\n(pulled in by @nestjs/swagger) in pnpm-workspace.yaml's allowBu\n[…]\nle\nzod/esbuild/vite overrides are dropped (they were never applied under pnpm 11\nand forcing them breaks the Astro website build).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore: migrate deprecated pnpm field to pnpm-workspace.yaml",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-14T23:36:00Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "4a935e3b84d76634069e7a6a8f7884f74fb8b022",
"body": "Add three optional Action fields honored by the REST-style adapters\n(@silkweave/fastify and @silkweave/nestjs `rest`):\n\n- `method` ('GET'|'POST'|'PUT'|'DELETE'; defaults to POST, or GET for\n `kind: 'query'`)\n- `path` route template with `:param` placeholders resolved from the URL\n- `queryParams` in\n[…]\nistered routes).\n@nestjs/swagger is an optional peer dependency.\n\nDocs updated across CLAUDE.md, package READMEs, and the website.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat: REST routing (method/path/queryParams) + NestJS Swagger",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-14T23:36:00Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "2d6d0e0ec81c3c9041d38d87b04f0bfe6506dc63",
"body": null,
"is_bot": false,
"headline": "allow request in context for mcp/nestjs",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-14T09:24:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bb20176ee33eb129965392eba6c0631991bbcbd3",
"body": "…tions\n\nDiscover @Action methods declared as `async function*` and build a streaming\ncore Action (chunk schema + async-generator run) so the trpc/typegen adapters\nexpose them as tRPC subscriptions (SSE), matching standalone createAction.\nGuards run inside the generator before the first yield; an asy\n[…]\nd*\n- example-nestjs: add streaming `countdown` action\n- docs: CLAUDE.md, nestjs README, website docs\n- bump all packages to 1.10.0\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(nestjs): stream async-generator @Action methods as tRPC subscrip…",
"author_name": "Tobias Strebitzer",
"author_login": "tobiasstrebitzer",
"committed_at": "2026-06-02T02:45:26Z",
"body_truncated": true,
"is_coding_agent": true
}
],
"releases_count": 23,
"commits_last_year": 140,
"latest_release_at": "2026-07-20T23:52:57Z",
"latest_release_tag": "v5.0.0",
"releases_from_tags": false,
"days_since_last_push": 6,
"active_weeks_last_year": 13,
"days_since_latest_release": 6,
"mean_days_between_releases": 1.4
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": false,
"health_percentage": 50,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "@silkweave/ai",
"exists": true,
"license": "MIT",
"keywords": [],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/@silkweave/ai",
"is_deprecated": false,
"latest_version": "5.0.0",
"repository_url": "https://github.com/silkweave/silkweave",
"versions_count": 22,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 1593,
"first_published_at": "2026-05-28T10:20:11.011000Z",
"latest_published_at": "2026-07-20T23:56:49.294000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 6
},
{
"name": "@silkweave/cli",
"exists": true,
"license": "MIT",
"keywords": [],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/@silkweave/cli",
"is_deprecated": false,
"latest_version": "5.0.0",
"repository_url": "https://github.com/silkweave/silkweave",
"versions_count": 33,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 1797,
"first_published_at": "2026-04-08T01:39:51.609000Z",
"latest_published_at": "2026-07-20T23:56:59.916000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 6
},
{
"name": "@silkweave/mcp",
"exists": true,
"license": "MIT",
"keywords": [],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/@silkweave/mcp",
"is_deprecated": false,
"latest_version": "5.0.0",
"repository_url": "https://github.com/silkweave/silkweave",
"versions_count": 34,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 2385,
"first_published_at": "2026-04-08T01:39:58.827000Z",
"latest_published_at": "2026-07-21T00:07:33.179000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 6
},
{
"name": "@silkweave/auth",
"exists": true,
"license": "MIT",
"keywords": [],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/@silkweave/auth",
"is_deprecated": false,
"latest_version": "5.0.0",
"repository_url": "https://github.com/silkweave/silkweave",
"versions_count": 34,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 2692,
"first_published_at": "2026-04-08T01:39:41.322000Z",
"latest_published_at": "2026-07-20T23:56:54.844000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 6
},
{
"name": "@silkweave/core",
"exists": true,
"license": "MIT",
"keywords": [],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/@silkweave/core",
"is_deprecated": false,
"latest_version": "5.0.0",
"repository_url": "https://github.com/silkweave/silkweave",
"versions_count": 34,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 3210,
"first_published_at": "2026-04-08T01:39:48.197000Z",
"latest_published_at": "2026-07-20T23:56:42.962000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 6
},
{
"name": "@silkweave/edge",
"exists": true,
"license": "MIT",
"keywords": [],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/@silkweave/edge",
"is_deprecated": false,
"latest_version": "5.0.0",
"repository_url": "https://github.com/silkweave/silkweave",
"versions_count": 12,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 1658,
"first_published_at": "2026-06-21T00:26:57.782000Z",
"latest_published_at": "2026-07-21T00:07:43.709000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 6
},
{
"name": "@silkweave/trpc",
"exists": true,
"license": "MIT",
"keywords": [],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/@silkweave/trpc",
"is_deprecated": false,
"latest_version": "5.0.0",
"repository_url": "https://github.com/silkweave/silkweave",
"versions_count": 26,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 1667,
"first_published_at": "2026-04-21T03:34:25.418000Z",
"latest_published_at": "2026-07-21T00:07:38.339000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 6
},
{
"name": "@silkweave/nestjs",
"exists": true,
"license": "MIT",
"keywords": [],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/@silkweave/nestjs",
"is_deprecated": false,
"latest_version": "5.0.0",
"repository_url": "https://github.com/silkweave/silkweave",
"versions_count": 23,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 1608,
"first_published_at": "2026-05-13T06:48:00.983000Z",
"latest_published_at": "2026-07-21T00:07:49.404000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 6
}
]
},
"popularity": {
"forks": 1,
"stars": 18,
"watchers": 0,
"fork_history": {
"days": [
{
"date": "2026-06-09",
"count": 1
}
],
"complete": true,
"collected": 1,
"total_forks": 1
},
"star_history": null,
"open_issues_and_prs": 0
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [
"examples"
],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": true,
"bootstrap_files": [],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [
"examples/ai/tsconfig.json",
"examples/cli/tsconfig.json",
"examples/cloudflare/tsconfig.json",
"examples/core/tsconfig.json",
"examples/edge/tsconfig.json",
"examples/fastify/tsconfig.json",
"examples/mcp/tsconfig.json",
"examples/nestjs/tsconfig.json",
"examples/nextjs/tsconfig.json",
"examples/skills/tsconfig.json",
"examples/trpc/tsconfig.json",
"examples/typegen/tsconfig.json",
"packages/ai/tsconfig.json",
"packages/auth/tsconfig.json",
"packages/cli/tsconfig.json",
"packages/core/tsconfig.json",
"packages/edge/tsconfig.json",
"packages/fastify/tsconfig.json",
"packages/mcp/tsconfig.json",
"packages/nestjs/tsconfig.json",
"packages/nextjs/tsconfig.json",
"packages/silkweave/tsconfig.json",
"packages/skills/tsconfig.json",
"packages/trpc/tsconfig.json",
"packages/typegen/tsconfig.json",
"tsconfig.json",
"website/tsconfig.json"
],
"toolchain_manifests": [],
"largest_source_bytes": 35847,
"source_files_sampled": 262,
"oversized_source_files": 0,
"agent_instruction_files": [
"CLAUDE.md"
],
"agent_instruction_max_bytes": 74590
},
"dependencies": {
"manifests": [
"package.json",
"website/package.json"
],
"advisories": {
"error": null,
"scope": "published_package",
"source": "osv",
"findings": [],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 2,
"malicious_count": 0,
"assessed_package": "npm:@silkweave/ai@5.0.0",
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"npm"
],
"dependencies": [
{
"name": "@astrojs/rss",
"manifest": "website/package.json",
"ecosystem": "npm",
"version_constraint": "^4.0.18"
},
{
"name": "@astrojs/vercel",
"manifest": "website/package.json",
"ecosystem": "npm",
"version_constraint": "^10.0.4"
},
{
"name": "@silkweave/auth",
"manifest": "website/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@silkweave/core",
"manifest": "website/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@silkweave/edge",
"manifest": "website/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@silkweave/trpc",
"manifest": "website/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@trpc/client",
"manifest": "website/package.json",
"ecosystem": "npm",
"version_constraint": "^11.16.0"
},
{
"name": "@trpc/server",
"manifest": "website/package.json",
"ecosystem": "npm",
"version_constraint": "^11.16.0"
},
{
"name": "@upstash/redis",
"manifest": "website/package.json",
"ecosystem": "npm",
"version_constraint": "^1.37.0"
},
{
"name": "@vercel/analytics",
"manifest": "website/package.json",
"ecosystem": "npm",
"version_constraint": "^2.0.1"
},
{
"name": "@vercel/speed-insights",
"manifest": "website/package.json",
"ecosystem": "npm",
"version_constraint": "^2.0.0"
},
{
"name": "rehype-external-links",
"manifest": "website/package.json",
"ecosystem": "npm",
"version_constraint": "^3.0.0"
},
{
"name": "zod",
"manifest": "website/package.json",
"ecosystem": "npm",
"version_constraint": "^3.25.0"
},
{
"name": "@silkweave/core",
"manifest": "packages/ai/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "zod",
"manifest": "packages/ai/package.json",
"ecosystem": "npm",
"version_constraint": "^3.25.0"
},
{
"name": "@silkweave/core",
"manifest": "packages/auth/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "jose",
"manifest": "packages/auth/package.json",
"ecosystem": "npm",
"version_constraint": "^6.0.0"
},
{
"name": "@silkweave/core",
"manifest": "packages/cli/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "change-case",
"manifest": "packages/cli/package.json",
"ecosystem": "npm",
"version_constraint": "^5.4.4"
},
{
"name": "commander",
"manifest": "packages/cli/package.json",
"ecosystem": "npm",
"version_constraint": "^13.1.0"
},
{
"name": "zod",
"manifest": "packages/cli/package.json",
"ecosystem": "npm",
"version_constraint": "^3.25.0"
},
{
"name": "@modelcontextprotocol/sdk",
"manifest": "packages/edge/package.json",
"ecosystem": "npm",
"version_constraint": "^1.29.0"
},
{
"name": "@silkweave/auth",
"manifest": "packages/edge/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@silkweave/core",
"manifest": "packages/edge/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@silkweave/mcp",
"manifest": "packages/edge/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "zod",
"manifest": "packages/edge/package.json",
"ecosystem": "npm",
"version_constraint": "^3.25.0"
},
{
"name": "@fastify/cors",
"manifest": "packages/fastify/package.json",
"ecosystem": "npm",
"version_constraint": "^11.2.0"
},
{
"name": "@fastify/swagger",
"manifest": "packages/fastify/package.json",
"ecosystem": "npm",
"version_constraint": "^9.7.0"
},
{
"name": "@silkweave/auth",
"manifest": "packages/fastify/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@silkweave/core",
"manifest": "packages/fastify/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "fastify",
"manifest": "packages/fastify/package.json",
"ecosystem": "npm",
"version_constraint": "^5.8.2"
},
{
"name": "zod",
"manifest": "packages/fastify/package.json",
"ecosystem": "npm",
"version_constraint": "^3.25.0"
},
{
"name": "@modelcontextprotocol/sdk",
"manifest": "packages/mcp/package.json",
"ecosystem": "npm",
"version_constraint": "^1.29.0"
},
{
"name": "@silkweave/auth",
"manifest": "packages/mcp/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@silkweave/core",
"manifest": "packages/mcp/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "change-case",
"manifest": "packages/mcp/package.json",
"ecosystem": "npm",
"version_constraint": "^5.4.4"
},
{
"name": "zod",
"manifest": "packages/mcp/package.json",
"ecosystem": "npm",
"version_constraint": "^3.25.0"
},
{
"name": "@silkweave/core",
"manifest": "packages/nestjs/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "change-case",
"manifest": "packages/nestjs/package.json",
"ecosystem": "npm",
"version_constraint": "^5.4.4"
},
{
"name": "cors",
"manifest": "packages/nestjs/package.json",
"ecosystem": "npm",
"version_constraint": "^2.8.6"
},
{
"name": "express",
"manifest": "packages/nestjs/package.json",
"ecosystem": "npm",
"version_constraint": "^5.2.1"
},
{
"name": "zod",
"manifest": "packages/nestjs/package.json",
"ecosystem": "npm",
"version_constraint": "^3.25.0"
},
{
"name": "@silkweave/auth",
"manifest": "packages/nextjs/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@silkweave/core",
"manifest": "packages/nextjs/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@silkweave/edge",
"manifest": "packages/nextjs/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "zod",
"manifest": "packages/nextjs/package.json",
"ecosystem": "npm",
"version_constraint": "^3.25.0"
},
{
"name": "@modelcontextprotocol/sdk",
"manifest": "packages/silkweave/package.json",
"ecosystem": "npm",
"version_constraint": "^1.29.0"
},
{
"name": "@silkweave/core",
"manifest": "packages/silkweave/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@silkweave/mcp",
"manifest": "packages/silkweave/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@silkweave/skills",
"manifest": "packages/silkweave/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "commander",
"manifest": "packages/silkweave/package.json",
"ecosystem": "npm",
"version_constraint": "^13.1.0"
},
{
"name": "zod",
"manifest": "packages/silkweave/package.json",
"ecosystem": "npm",
"version_constraint": "^3.25.0"
},
{
"name": "@silkweave/core",
"manifest": "packages/skills/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "yaml",
"manifest": "packages/skills/package.json",
"ecosystem": "npm",
"version_constraint": "^2.8.0"
},
{
"name": "zod",
"manifest": "packages/skills/package.json",
"ecosystem": "npm",
"version_constraint": "^3.25.0"
},
{
"name": "@silkweave/auth",
"manifest": "packages/trpc/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@silkweave/core",
"manifest": "packages/trpc/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "@trpc/server",
"manifest": "packages/trpc/package.json",
"ecosystem": "npm",
"version_constraint": "^11.7.1"
},
{
"name": "change-case",
"manifest": "packages/trpc/package.json",
"ecosystem": "npm",
"version_constraint": "^5.4.4"
},
{
"name": "cors",
"manifest": "packages/trpc/package.json",
"ecosystem": "npm",
"version_constraint": "^2.8.5"
},
{
"name": "zod",
"manifest": "packages/trpc/package.json",
"ecosystem": "npm",
"version_constraint": "^3.25.0"
},
{
"name": "@silkweave/core",
"manifest": "packages/typegen/package.json",
"ecosystem": "npm",
"version_constraint": "workspace:*"
},
{
"name": "change-case",
"manifest": "packages/typegen/package.json",
"ecosystem": "npm",
"version_constraint": "^5.4.4"
},
{
"name": "zod",
"manifest": "packages/typegen/package.json",
"ecosystem": "npm",
"version_constraint": "^3.25.0"
}
],
"all_dependencies": {
"error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
"source": null,
"packages": [],
"collected": false,
"truncated": false,
"total_count": null,
"direct_count": null,
"indirect_count": null
}
},
"maintainership": {
"issues": {
"open_prs": 0,
"merged_prs": 1,
"open_issues": 0,
"closed_ratio": null,
"closed_issues": 0,
"closed_unmerged_prs": 1
},
"bus_factor": 1,
"bot_contributors": 0,
"top_contributors": [
{
"type": "User",
"login": "tobiasstrebitzer",
"commits": 140,
"avatar_url": "https://avatars.githubusercontent.com/u/222509?v=4"
}
],
"contributors_sampled": 1,
"top_contributor_share": 1
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"ci.yml",
"publish.yml"
],
"has_docs_dir": false,
"linter_configs": [
"eslint.config.mjs"
],
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"pnpm-lock.yaml"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 0,
"reason": "branch protection not enabled on development/release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": null,
"reason": "no pull request found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/30 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 6,
"reason": "project has 2 contributing companies or organizations -- score normalized to 6",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 0,
"reason": "no update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": 10,
"reason": "packaging workflow detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 0,
"reason": "dependency not pinned by hash detected -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 0,
"reason": "no SAST tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 0,
"reason": "security policy file not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 0,
"reason": "37 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "b755bcc0b1be87b911ebe930f7f0870eb2892a5d",
"ran_at": "2026-07-27T18:36:01Z",
"aggregate_score": 3.6,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": false,
"has_dependabot_config": false
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-21T00:08:02Z",
"oldest_open_prs": [],
"last_merged_pr_at": "2026-06-16T13:49:11Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": []
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/silkweave/silkweave",
"host": "github.com",
"name": "silkweave",
"owner": "silkweave"
},
"metrics": {
"overall": {
"key": "overall",
"band": "good",
"name": "Overall health",
"note": "The weighted overall 60 is calibrated to 65 on the published index scale (record calibration 2026-08-02).",
"notes": [
{
"code": "overall_calibration",
"params": {
"raw": 60,
"calibrated": 65,
"calibration": "2026-08-02"
}
}
],
"value": 65,
"inputs": {
"security": 49,
"vitality": 84,
"community": 43,
"governance": 42,
"calibration": "2026-08-02",
"engineering": 78,
"ai_readiness": 75,
"weighted_overall_raw": 60
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "excellent",
"name": "Vitality",
"value": 84,
"weight": 0.21,
"metrics": [
{
"key": "development_activity",
"band": "good",
"name": "Development activity",
"note": null,
"notes": [],
"value": 73,
"inputs": {
"commits_last_year": 140,
"human_commit_share": 1,
"days_since_last_push": 6,
"active_weeks_last_year": 13
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 6 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 6
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "13/52 weeks with commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 13
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "140 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 140
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "exceptional",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 100,
"inputs": {
"releases_count": 23,
"latest_release_tag": "v5.0.0",
"releases_from_tags": false,
"days_since_latest_release": 6,
"mean_days_between_releases": 1.4
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "23 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 23
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 6 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 6
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~1.4 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 1.4
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "exceptional",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "repository_too_young",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "weak",
"name": "Community & Adoption",
"value": 43,
"weight": 0.17,
"metrics": [
{
"key": "popularity",
"band": "at_risk",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 20,
"inputs": {
"forks": 1,
"stars": 18,
"watchers": 0,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "18 stars",
"points": 20,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 18
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "1 forks",
"points": 0,
"status": "missed",
"details": [
{
"code": "forks",
"params": {
"count": 1
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "0 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 0
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "moderate",
"name": "Community health",
"note": null,
"notes": [],
"value": 50,
"inputs": {
"has_readme": true,
"has_license": true,
"readme_badges": null,
"has_contributing": false,
"has_issue_template": false,
"has_code_of_conduct": false,
"readme_badge_services": [],
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (MIT)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "MIT"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
},
{
"key": "ecosystem_adoption",
"band": "good",
"name": "Ecosystem adoption (downloads)",
"note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"registry_dependents"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 70,
"inputs": {
"packages": [
"@silkweave/ai",
"@silkweave/cli",
"@silkweave/mcp",
"@silkweave/auth",
"@silkweave/core",
"@silkweave/edge",
"@silkweave/trpc",
"@silkweave/nestjs"
],
"dependents": null,
"ecosystems": "npm",
"total_downloads": null,
"monthly_downloads": 16610
},
"components": [
{
"key": "monthly_downloads",
"name": "Monthly downloads",
"detail": "16,610 downloads/month across npm",
"points": 56.3,
"status": "partial",
"details": [
{
"code": "downloads_monthly",
"params": {
"count": 16610,
"ecosystems": "npm"
}
}
],
"max_points": 80
},
{
"key": "registry_dependents",
"name": "Registry dependents",
"detail": "not reported by this ecosystem",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_reported_by_this_ecosystem",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "weak",
"name": "Sustainability & Governance",
"value": 42,
"weight": 0.23,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 16,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 1,
"top_contributor_share": 1
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 100% of commits",
"points": 0,
"status": "missed",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 100
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "1 contributors",
"points": 1.4,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 1
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 2 contributing companies or organizations -- score normalized to 6",
"points": 6,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "at_risk",
"name": "Issue & PR responsiveness",
"note": "Excluded from scoring (no data or not applicable): Issue resolution, Newcomer PR acceptance. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"issue_resolution",
"newcomer_pr_acceptance"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 33,
"inputs": {
"merged_prs": 1,
"open_issues": 0,
"closed_issues": 0,
"prs_merged_7d": null,
"prs_decided_7d": null,
"prs_merged_30d": null,
"prs_decided_30d": null,
"issue_closed_ratio": null,
"closed_unmerged_prs": 1,
"first_time_authors_30d": null,
"first_time_prs_merged_30d": null,
"first_time_prs_decided_30d": null
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "no issues or no data",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_issues_or_data",
"params": {}
}
],
"max_points": 42
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "1/2 decided PRs merged",
"points": 15,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 1,
"decided": 2
}
}
],
"max_points": 30
},
{
"key": "newcomer_pr_acceptance",
"name": "Newcomer PR acceptance",
"detail": "no first-time contributor's PR decided in 30d",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_newcomer_prs",
"params": {
"days": 30
}
}
],
"max_points": 13
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "weak",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 35,
"inputs": {
"followers": 0,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "silkweave",
"public_repos": 3,
"account_age_days": 110
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "0 followers of silkweave",
"points": 0,
"status": "missed",
"details": [
{
"code": "owner_followers",
"params": {
"count": 0,
"login": "silkweave"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "3 public repos, account ~0 yr old",
"points": 5,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 3
}
},
{
"code": "account_age_years",
"params": {
"years": 0
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "exceptional",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"@silkweave/ai",
"@silkweave/cli",
"@silkweave/mcp",
"@silkweave/auth",
"@silkweave/core",
"@silkweave/edge",
"@silkweave/trpc",
"@silkweave/nestjs"
],
"ecosystems": "npm",
"any_deprecated": false,
"min_days_since_publish": 6
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "8 package(s) on npm",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 8,
"ecosystems": "npm"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 6 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 6
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "34 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 34
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "good",
"name": "Engineering Quality",
"value": 78,
"weight": 0.19,
"metrics": [
{
"key": "engineering_practices",
"band": "excellent",
"name": "Engineering practices",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_ci_tests"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 80,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "2 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 2
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": "eslint.config.mjs",
"points": 16,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "eslint.config.mjs"
}
}
],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "no pull request found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "good",
"name": "Documentation",
"note": null,
"notes": [],
"value": 75,
"inputs": {
"topics": [
"api",
"cli",
"mcp",
"server"
],
"has_wiki": true,
"homepage": "https://www.silkweave.dev",
"has_readme": true,
"has_docs_dir": false,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": "https://www.silkweave.dev",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": "4 topics",
"points": 10,
"status": "met",
"details": [
{
"code": "topics_count",
"params": {
"count": 4
}
}
],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "weak",
"name": "Security",
"value": 49,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "weak",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): CI-Tests, Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"ci_tests",
"signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 36,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 16,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 2,
"scorecard_aggregate": 3.6
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection not enabled on development/release branches",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "no pull request found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 2 contributing companies or organizations -- score normalized to 6",
"points": 1.5,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "no update tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "no SAST tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file not detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "37 existing vulnerabilities detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "exceptional",
"name": "Dependency advisories",
"note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:@silkweave/ai@5.0.0 runtime dependency closure — what installing the published package pulls in — 2 packages. Reachability is not analyzed.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"no_advisories_left_outstanding"
]
}
},
{
"code": "weights_renormalized",
"params": {}
},
{
"code": "advisories_scope_published",
"params": {
"package": "npm:@silkweave/ai@5.0.0",
"assessed": 2
}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 100,
"inputs": {
"source": "osv",
"advisories": 0,
"affected_packages": 0,
"assessed_packages": 2,
"unassessed_packages": 0,
"affected_by_severity": "none",
"direct_affected_packages": 0
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "no direct dependency carries a known advisory",
"points": 35,
"status": "met",
"details": [
{
"code": "no_direct_advisories",
"params": {}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "no indirect dependency carries a known advisory",
"points": 25,
"status": "met",
"details": [
{
"code": "no_indirect_advisories",
"params": {}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "no advisory carries a publication date",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_no_publication_date",
"params": {}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "exceptional",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 2,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "exceptional",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"commit_weight_rule": {
"min_commits": 50,
"min_commit_share": 0.1
},
"review_only_matches": 0,
"below_threshold_exposures": [],
"assessed_self_published_locations": 2
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "good",
"name": "AI Readiness",
"value": 75,
"weight": 0.04,
"metrics": [
{
"key": "ai_agent_context",
"band": "excellent",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 85,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 0.96,
"agent_instruction_files": [
"CLAUDE.md"
],
"agent_instruction_max_bytes": 74590
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "CLAUDE.md",
"points": 45,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "CLAUDE.md"
}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "96 of 100 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 96,
"sampled": 100
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "moderate",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 64,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"pnpm-lock.yaml"
],
"has_dockerfile": false,
"typed_language": true,
"bootstrap_files": [],
"has_devcontainer": false,
"has_linter_config": true,
"typecheck_configs": [
"examples/ai/tsconfig.json",
"examples/cli/tsconfig.json",
"examples/cloudflare/tsconfig.json",
"examples/core/tsconfig.json",
"examples/edge/tsconfig.json",
"examples/fastify/tsconfig.json",
"examples/mcp/tsconfig.json",
"examples/nestjs/tsconfig.json",
"examples/nextjs/tsconfig.json",
"examples/skills/tsconfig.json",
"examples/trpc/tsconfig.json",
"examples/typegen/tsconfig.json",
"packages/ai/tsconfig.json",
"packages/auth/tsconfig.json",
"packages/cli/tsconfig.json",
"packages/core/tsconfig.json",
"packages/edge/tsconfig.json",
"packages/fastify/tsconfig.json",
"packages/mcp/tsconfig.json",
"packages/nestjs/tsconfig.json",
"packages/nextjs/tsconfig.json",
"packages/silkweave/tsconfig.json",
"packages/skills/tsconfig.json",
"packages/trpc/tsconfig.json",
"packages/typegen/tsconfig.json",
"tsconfig.json",
"website/tsconfig.json"
],
"agent_commit_share": 0.72,
"toolchain_manifests": [],
"dependency_bot_commit_share": 0
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": "eslint.config.mjs",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "eslint.config.mjs"
}
}
],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "examples/ai/tsconfig.json, examples/cli/tsconfig.json, examples/cloudflare/tsconfig.json, examples/core/tsconfig.json, examples/edge/tsconfig.json, examples/fastify/tsconfig.json, examples/mcp/tsconfig.json, examples/nestjs/tsconfig.json, examples/nextjs/tsconfig.json, examples/skills/tsconfig.json, examples/trpc/tsconfig.json, examples/typegen/tsconfig.json, packages/ai/tsconfig.json, packages/auth/tsconfig.json, packages/cli/tsconfig.json, packages/core/tsconfig.json, packages/edge/tsconfig.json, packages/fastify/tsconfig.json, packages/mcp/tsconfig.json, packages/nestjs/tsconfig.json, packages/nextjs/tsconfig.json, packages/silkweave/tsconfig.json, packages/skills/tsconfig.json, packages/trpc/tsconfig.json, packages/typegen/tsconfig.json, tsconfig.json, website/tsconfig.json",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "examples/ai/tsconfig.json, examples/cli/tsconfig.json, examples/cloudflare/tsconfig.json, examples/core/tsconfig.json, examples/edge/tsconfig.json, examples/fastify/tsconfig.json, examples/mcp/tsconfig.json, examples/nestjs/tsconfig.json, examples/nextjs/tsconfig.json, examples/skills/tsconfig.json, examples/trpc/tsconfig.json, examples/typegen/tsconfig.json, packages/ai/tsconfig.json, packages/auth/tsconfig.json, packages/cli/tsconfig.json, packages/core/tsconfig.json, packages/edge/tsconfig.json, packages/fastify/tsconfig.json, packages/mcp/tsconfig.json, packages/nestjs/tsconfig.json, packages/nextjs/tsconfig.json, packages/silkweave/tsconfig.json, packages/skills/tsconfig.json, packages/trpc/tsconfig.json, packages/typegen/tsconfig.json, tsconfig.json, website/tsconfig.json"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "72 of the last 100 commits agent-authored or agent-credited",
"points": 10,
"status": "met",
"details": [
{
"code": "agent_authored_commits",
"params": {
"count": 72,
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "no automated dependency updates observed",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_dependency_automation",
"params": {}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "exceptional",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"primary_language": "TypeScript",
"largest_source_bytes": 35847,
"source_files_sampled": 262,
"oversized_source_files": 0
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "TypeScript (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "TypeScript"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "0/262 source files over 60KB",
"points": 55,
"status": "met",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 262,
"oversized": 0
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "moderate",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 60,
"inputs": {
"example_dirs": [
"examples"
],
"has_mcp_signal": true,
"api_schema_files": []
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 20,
"status": "met",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": "examples",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "examples"
}
}
],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? Carries a deliberately small weight: agent tooling is a real maintenance signal, but its absence must never gate the top of the scale (calibration saturates at raw 91, so 100/100 remains reachable with AI Readiness at zero)."
}
],
"classification": {
"labels": [
"network-service",
"mcp-server",
"cli",
"library"
],
"scores": {
"cli": 6,
"library": 6,
"mcp-server": 7,
"network-service": 8
},
"primary": "network-service",
"evidence": [
{
"tier": "distribution",
"label": "library",
"source": "registry:npm",
"weight": 6
},
{
"tier": "dependencies",
"label": "cli",
"source": "dep:commander",
"weight": 4
},
{
"tier": "dependencies",
"label": "mcp-server",
"source": "dep:@modelcontextprotocol/sdk",
"weight": 4
},
{
"tier": "dependencies",
"label": "network-service",
"source": "dep:express",
"weight": 4
},
{
"tier": "dependencies",
"label": "network-service",
"source": "dep:fastify",
"weight": 4
},
{
"tier": "structure",
"label": "mcp-server",
"source": "mcp_signal",
"weight": 3
},
{
"tier": "tags",
"label": "cli",
"source": "tag:cli",
"weight": 2
}
],
"artifacts": [],
"confidence": "medium",
"host_extension": false,
"runs_as_process": true,
"consumed_by_code": true
},
"metrics_version": "2.3.1"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
"GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
],
"report_type": "repository",
"generated_at": "2026-07-27T18:36:10.260340Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/s/silkweave/silkweave.svg",
"full_name": "silkweave/silkweave",
"license_state": "standard",
"license_spdx": "MIT"
}