Public record
Software health reportschema 0.27.0 · metrics 1.13.0 · 2026-07-30 03:35 UTC

stranxik / runward

After the spec: ship and run. A delivery framework for agentic systems — floor first, evolution on evidence, governance from day zero, handover with proof.

TypeScript · JavaScriptMIT★ 1 star⑂ 0 forkssince Jul 2026View on GitHub ↗

stranxik/runward holds a health index of 63 out of 100, placing it in the Moderate band. It scores highest on Engineering Quality (77/100) and lowest on Community & Adoption (47/100). It was last updated today. A single contributor accounts for most of its recent work.

63
overall / 100
Moderate

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

63
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

ThibaultPersonal account
6 followers15 public repossince Mar 2017

This repository is owned by a personal account. A single-owner project carries more continuity risk than an organization-backed one.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publishTags
npmrunward0.22.03,163278 days agoagenticai-agentsspec-drivendeliverygovernancellmarchitecture

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

70Good · 22% of overall
How it's scored
36/36Push recency — last push 0 days ago
2.8/36Commit cadence — 4/52 weeks with commits
18/18Commit volume — 240 commits in the last year
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Inputs used
commits_last_year240
human_commit_share1
days_since_last_push0
active_weeks_last_year4
How it's scored
27/27Ships releases — 26 releases published
36/36Release recency — latest release 8 days ago
27/27Release cadence — a release every ~0.6 days
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Inputs used
releases_count26
latest_release_tagv0.22.0
releases_from_tagsno
days_since_latest_release8
mean_days_between_releases0.6

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

47At risk · 18% of overall
How it's scored
0/60Stars — 1 stars
0/25Forks — 0 forks
0/15Watchers — 0 watchers
Inputs used
forks0
stars1
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

Community health

92Excellent
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (MIT)
18/18CONTRIBUTING guide
13.5/13.5Code of conduct
0/7.2Issue template
6.3/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingyes
has_issue_templateno
has_code_of_conductyes
has_pull_request_templateyes
How it's scored
46.7/80Monthly downloads — 3,163 downloads/month across npm
0/20Registry dependents — not reported by this ecosystem
Inputs used
packagesrunward
dependents
ecosystemsnpm
total_downloads
monthly_downloads3,163
Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

54Moderate · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
0/22.5Commit distribution — top contributor authored 100% of commits
1.4/13.5Contributor breadth — 1 contributors
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Inputs used
bus_factor1
contributors_sampled1
top_contributor_share1
How it's scored
46.8/46.8Issue resolution — 100% of issues closed
32.4/38.3PR acceptance — 33/39 decided PRs merged
0/15OpenSSF Scorecard: Code-Review — Found 0/13 approved changesets -- score normalized to 0
Inputs used
merged_prs33
open_issues0
closed_issues1
issue_closed_ratio1
closed_unmerged_prs6
How it's scored
10/30Ownership backing — personal (user) account
0/20Verified domain — not applicable to user accounts
6.1/25Owner reach — 6 followers of stranxik
20.8/25Track record — 15 public repos, account ~9 yr old
Inputs used
followers6
owner_typeUser
is_verified
owner_loginstranxik
public_repos15
account_age_days3,418
Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.
How it's scored
25/25Published & resolvable — 1 package(s) on npm
35/35Publish recency — latest publish 8 days ago
20/20Version history — 27 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packagesrunward
ecosystemsnpm
any_deprecatedno
min_days_since_publish8

Engineering Quality

Are baseline engineering and documentation practices in place?

77Good · 20% of overall
How it's scored
24/24CI workflows — 4 workflow(s)
24/24Tests present
0/16Linter config
0/9.6Pre-commit hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 8 out of 8 merged PRs checked by a CI test -- score normalized to 10
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configno
has_precommit_configno

Documentation

90Excellent
How it's scored
30/30README
25/25Documentation directory
15/15Documentation / homepage site — https://runward.dev
10/10Repository description
0/10Topics
10/10Wiki
Inputs used
topics
has_wikiyes
homepagehttps://runward.dev
has_readmeyes
has_docs_diryes
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

67Moderate · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — no data
2.5/2.5CI-Tests — 8 out of 8 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/13 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
5/5Packaging — packaging workflow detected
4.5/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 9
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
7.5/7.5Token-Permissions — GitHub workflow tokens follow principle of least privilege
6/7.5Vulnerabilities — 2 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate5.9
Excluded from scoring (no data or not applicable): branch_protection. Remaining weights renormalized.
How it's scored
35/35Direct dependencies free of known advisories — no direct dependency carries a known advisory
25/25Indirect dependencies free of known advisories — no indirect dependency carries a known advisory
0/40No advisories left outstanding — no advisory carries a publication date
Inputs used
sourceosv
advisories0
affected_packages0
assessed_packages27
unassessed_packages0
affected_by_severitynone
direct_affected_packages0
Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:runward@0.22.0 runtime dependency closure — what installing the published package pulls in — 27 packages. Reachability is not analyzed.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

72Good · 0% of overall
How it's scored
45/45Agent instructions — examples/request-triage/AGENTS.md, floor-ts/AGENTS.md, templates/targets/AGENTS.md
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 95 of 100 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share0.95
agent_instruction_filesexamples/request-triage/AGENTS.md, floor-ts/AGENTS.md, templates/targets/AGENTS.md
agent_instruction_max_bytes133,430
How it's scored
0/18One-command bootstrap
22/22Automated tests
0/11Lint / format config
11/11Static type checking — examples/request-triage/code/tsconfig.json, floor-ts/tsconfig.json, tsconfig.json
10/10Reproducible environment — lockfile
0/10Demonstrated agent practice — no agent-authored commits among the last 100
5/8Automated maintenance — dependency automation configured, none observed in the sampled commits
9/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 9
Inputs used
has_nixno
has_testsyes
lockfilespackage-lock.json
has_dockerfileno
typed_languageyes
bootstrap_files
has_devcontainerno
has_linter_configno
typecheck_configsexamples/request-triage/code/tsconfig.json, floor-ts/tsconfig.json, tsconfig.json
agent_commit_share0
toolchain_manifests
dependency_bot_commit_share0
How it's scored
45/45Type-checkable code — TypeScript (statically typed)
55/55Manageable file sizes — 0/90 source files over 60KB
Inputs used
primary_languageTypeScript
largest_source_bytes41,069
source_files_sampled90
oversized_source_files0
How it's scored
0/40API schema (OpenAPI/GraphQL/proto)
20/20MCP server
40/40Runnable examples — examples
Inputs used
example_dirsexamples
has_mcp_signalyes
api_schema_files

Key facts

1GitHub stars
1contributors
240commits, last 12 months
0days since last push
26releases
1bus factor
0open issues
npmpackage ecosystems

Data collection warnings

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

More detail

OpenSSF Scorecard 5.9 / 10
5.9aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-30 03:35 UTC

10Binary-Artifactsno binaries found in the repo
n/aBranch-Protectioninternal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
10CI-Tests8 out of 8 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/13 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
10Packagingpackaging workflow detected
9Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 9
0SASTSAST tool is not run on all commits -- score normalized to 0
10Security-Policysecurity policy file detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
10Token-PermissionsGitHub workflow tokens follow principle of least privilege
8Vulnerabilities2 existing vulnerabilities detected
Direct dependencies 4
RegistryPackageVersion constraintManifest
npmzod^4.4.3floor-ts/package.json
npm@inquirer/prompts^8.5.2package.json
npmchalk^5.6.0package.json
npmcommander^15.0.0package.json
All dependencies not collected

The resolved dependency set could not be collected for this report: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Dependency advisories 0

Installing npm:runward@0.22.0 pulls in 27 packages, direct and transitive: 0 carry known advisories, of which 0 are direct dependencies.

No known advisories affect the assessed dependencies.

An advisory means the version recorded in the dependency graph falls inside an advisory’s affected range. Reachability is not analysed, and the graph includes development and test pins — a finding may concern tooling rather than shipped software.

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 2181,
      "has_wiki": true,
      "homepage": "https://runward.dev",
      "languages": {
        "Shell": 633,
        "Python": 1783,
        "JavaScript": 142995,
        "TypeScript": 309690
      },
      "pushed_at": "2026-07-29T09:54:02Z",
      "created_at": "2026-07-05T21:40:41Z",
      "owner_type": "User",
      "updated_at": "2026-07-29T09:55:39Z",
      "description": "After the spec: ship and run. A delivery framework for agentic systems — floor first, evolution on evidence, governance from day zero, handover with proof.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript",
        "JavaScript"
      ]
    },
    "owner": {
      "blog": "https://runward.dev",
      "name": "Thibault",
      "type": "User",
      "login": "stranxik",
      "company": null,
      "location": "France",
      "followers": 6,
      "avatar_url": "https://avatars.githubusercontent.com/u/26541747?v=4",
      "created_at": "2017-03-20T10:42:16Z",
      "is_verified": null,
      "public_repos": 15,
      "account_age_days": 3418
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.22.0",
          "kind": "minor",
          "published_at": "2026-07-21T15:17:35Z"
        },
        {
          "tag": "v0.21.1",
          "kind": "patch",
          "published_at": "2026-07-21T13:15:11Z"
        },
        {
          "tag": "v0.21.0",
          "kind": "minor",
          "published_at": "2026-07-19T19:25:59Z"
        },
        {
          "tag": "v0.20.0",
          "kind": "minor",
          "published_at": "2026-07-19T13:02:17Z"
        },
        {
          "tag": "v0.19.0",
          "kind": "minor",
          "published_at": "2026-07-17T12:46:00Z"
        },
        {
          "tag": "v0.18.1",
          "kind": "patch",
          "published_at": "2026-07-16T10:30:19Z"
        },
        {
          "tag": "v0.18.0",
          "kind": "minor",
          "published_at": "2026-07-16T08:23:23Z"
        },
        {
          "tag": "v0.17.0",
          "kind": "minor",
          "published_at": "2026-07-16T02:51:13Z"
        },
        {
          "tag": "v0.16.0",
          "kind": "minor",
          "published_at": "2026-07-16T02:02:49Z"
        },
        {
          "tag": "v0.15.0",
          "kind": "minor",
          "published_at": "2026-07-16T00:59:50Z"
        },
        {
          "tag": "v0.14.2",
          "kind": "patch",
          "published_at": "2026-07-13T15:35:19Z"
        },
        {
          "tag": "v0.14.1",
          "kind": "patch",
          "published_at": "2026-07-13T10:57:52Z"
        },
        {
          "tag": "v0.14.0",
          "kind": "minor",
          "published_at": "2026-07-13T10:26:06Z"
        },
        {
          "tag": "v0.13.3",
          "kind": "patch",
          "published_at": "2026-07-12T20:40:53Z"
        },
        {
          "tag": "v0.13.2",
          "kind": "patch",
          "published_at": "2026-07-12T11:10:38Z"
        },
        {
          "tag": "v0.13.1",
          "kind": "patch",
          "published_at": "2026-07-12T10:38:32Z"
        },
        {
          "tag": "v0.13.0",
          "kind": "minor",
          "published_at": "2026-07-12T09:44:00Z"
        },
        {
          "tag": "v0.12.2",
          "kind": "patch",
          "published_at": "2026-07-11T18:45:46Z"
        },
        {
          "tag": "v0.12.1",
          "kind": "patch",
          "published_at": "2026-07-11T10:53:17Z"
        },
        {
          "tag": "v0.12.0",
          "kind": "minor",
          "published_at": "2026-07-11T08:58:40Z"
        },
        {
          "tag": "v0.11.0",
          "kind": "minor",
          "published_at": "2026-07-10T11:48:58Z"
        },
        {
          "tag": "v0.10.0",
          "kind": "minor",
          "published_at": "2026-07-10T07:50:45Z"
        },
        {
          "tag": "v0.9.1",
          "kind": "patch",
          "published_at": "2026-07-09T12:18:06Z"
        },
        {
          "tag": "v0.9.0",
          "kind": "minor",
          "published_at": "2026-07-09T12:08:57Z"
        },
        {
          "tag": "v0.8.0",
          "kind": "minor",
          "published_at": "2026-07-07T15:05:47Z"
        },
        {
          "tag": "v0.7.0",
          "kind": "minor",
          "published_at": "2026-07-07T12:06:36Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "9c30a25dd438f14658afbdd5b47b1ec40c06ad63",
          "body": "docs(adr): ratify the brownfield/characterize ADRs (0033–0038)",
          "is_bot": false,
          "headline": "Merge pull request #48 from stranxik/docs/ratify-brownfield-adrs",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-29T09:53:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "32a64d13dff1beee9defd4c5a3ca64c9a80df990",
          "body": "…en proof\n\nThe six ADRs from the 2026-07-20 resume-existing audit — ADR-0033 (status\nnames the iterate steady-state and the reopening watch) and ADR-0034..0038\n(characterize sees the whole tree, extracts pinned versions offline, reports\nchurn/bus-factor, detects infra & framework/DB signals, mines d\n[…]\ntion for\n  ADR-0035) — the two ADRs that had unit coverage only.\n- CHANGELOG: a dated Ratification entry naming the drift; no version bump.\n\nSelf-gate green: 109 unit tests, smoke OK, oscal-schema OK.",
          "is_bot": false,
          "headline": "docs(adr): ratify the brownfield/characterize ADRs (0033-0038) + hard…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-29T09:50:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d23c4b05bcc32ad34287ce4f576ab8e4c09e4cb7",
          "body": "chore(release): v0.22.0 — every gate names what it cannot verify",
          "is_bot": false,
          "headline": "Merge pull request #39 from stranxik/release/v0.22.0",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-21T15:17:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "84e5bb88ec2c9a5d84fed94859136eeaaf857326",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): v0.22.0 — every gate names what it cannot verify",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-21T15:16:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dc9dfb06d31ebc98809be196a015c9e083aaf2fb",
          "body": "feat(rules): ADR-0040 ratified — per-rule non-scope declaration",
          "is_bot": false,
          "headline": "Merge pull request #38 from stranxik/feat/adr-0040-nonscope",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-21T15:04:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6212cf2948a26f6ed01460434af5060c64ef6c81",
          "body": "…-wide default\n\nEvery gate names what it cannot verify. GATE_NON_SCOPE stated once\n(machine surface + explain + ISO readiness draft); per-rule nonScope\nwhere the blind zone is narrower (4 rules seeded). Gate path, manifest\nand ADR-0003 lint untouched — the rule-file carrier made the feared\nmigration unnecessary. 106 tests, self-gate green.",
          "is_bot": false,
          "headline": "feat(rules): ADR-0040 ratified — per-rule non-scope declaration, gate…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-21T15:03:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ab0f835a1d6b718f08766ad3e1358da05bad4811",
          "body": "docs: survey-grounded pass — third guardrail, change contract, ADR-0040 (proposed), distillation fence",
          "is_bot": false,
          "headline": "Merge pull request #37 from stranxik/docs/survey-actions",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-21T14:29:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "62dbf698840124eed3d207b0250e7b09a5e8fe9e",
          "body": "…ot a trigger",
          "is_bot": false,
          "headline": "docs(roadmap): AHE loop as the satellite's citable frame — a frame, n…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-21T14:27:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "612f428d5a61aab91b3a34da7e00e5a4437642e6",
          "body": "…v 2605.18747)",
          "is_bot": false,
          "headline": "merge survey/regulated-adoption (flotte worktrees, confrontation arXi…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-21T14:27:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b5d0a150ad3a9d465139f1ce67cf4c75a1793be3",
          "body": "… 2605.18747)",
          "is_bot": false,
          "headline": "merge survey/adr-0040-nonscope (flotte worktrees, confrontation arXiv…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-21T14:27:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d14703c8a2d9973816e0420629e97010af15c729",
          "body": "…v 2605.18747)",
          "is_bot": false,
          "headline": "merge survey/adr-0006-amendment (flotte worktrees, confrontation arXi…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-21T14:27:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3fef48ea40931fd643c6d9aa715092600939331a",
          "body": "…18747)",
          "is_bot": false,
          "headline": "merge survey/positioning (flotte worktrees, confrontation arXiv 2605.…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-21T14:27:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0a52b839deefe746ececf177a3389f830e9d7727",
          "body": "…Xiv 2605.18747)\n\n- Compliance guardrails: add the academic pendant to FedRAMP RFC-0024 and\n  Delve — the SWE-bench solved-correctly study (arXiv 2503.15223) cited by\n  the Code-as-Agent-Harness survey for its oracle-adequacy crisis, plus the\n  14-53% step-level failure-attribution range, and the su\n[…]\nsions at delivery, never runtime actions) and 'change contract' in\n  pillar 4 (dated reevaluation triggers + ADR-0006 tracked migrations).\n\nDrift gate: test/unit/positioning-drift.test.js green (5/5).",
          "is_bot": false,
          "headline": "docs(positioning): third guardrail talking point + survey lexicon (ar…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-21T14:27:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c9f3a843e32c1a6938cebdfc3083fee8988529b4",
          "body": "…alising ADR-0005 (status: proposed)",
          "is_bot": false,
          "headline": "docs(adr): ADR-0040 candidate — per-rule non-scope declaration, gener…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-21T14:26:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c59a4bd23e401e947953d790ddaa570348c3afa8",
          "body": "…y dated ADR, not promise (arXiv 2605.18747)",
          "is_bot": false,
          "headline": "docs(regulated): the distillation-surface fence — traces stay yours b…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-21T14:25:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ce5c1af7f89f32e4dcc1027a75ffdf04bae4b2ab",
          "body": "…(invariants, falsifier, rollback)",
          "is_bot": false,
          "headline": "docs(adr): amend ADR-0006 — the migration entry as a change contract …",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-21T14:25:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "776f7a671c5853f19412b05cab4eed7eb59ca2d1",
          "body": "chore(release-workflow): migrate deprecated actions/attest-sbom to actions/attest",
          "is_bot": false,
          "headline": "Merge pull request #36 from stranxik/chore/attest-migration",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-21T13:23:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2fd9935557547ade9f7becabacc1194237068c45",
          "body": "…w action name\n\nThe posture guard pinned the literal 'attest-sbom@<sha>'; the migration to\nactions/attest tripped it (as designed). The guard now asserts the successor\naction SHA-pinned AND the sbom-path binding, preserving the guarded property:\nSBOM SLSA-attested against the published tarball.",
          "is_bot": false,
          "headline": "test(posture): guard follows the attest migration — same property, ne…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-21T13:23:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0415e904aaa224a2215de002cb5953a39f05574d",
          "body": "…tions/attest\n\nSurfaced as a deprecation warning in the v0.21.1 publish log. actions/attest\nv4.2.0 accepts sbom-path directly (creates the same SBOM attestation); inputs\nunchanged, SHA-pinned. Real proof lands with the next release run.",
          "is_bot": false,
          "headline": "chore(release-workflow): migrate deprecated actions/attest-sbom to ac…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-21T13:20:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c4410048ebdf94fd8935578d418974bb507c91f7",
          "body": "chore(release): v0.21.1 — the three tiers, named",
          "is_bot": false,
          "headline": "Merge pull request #35 from stranxik/release/v0.21.1",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-21T13:14:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "07bb8684b9c5ee3df4cdaf223d049d3d624fb7a5",
          "body": "CHANGELOG block for the docs release (ADR-0039, two site pages, roadmap\ngroom), version stamped across the six distribution manifests, roadmap\nre-groomed at v0.21.1. No CLI change, no gate change.",
          "is_bot": false,
          "headline": "chore(release): v0.21.1 — the three tiers, named",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-21T13:13:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "59f859ab440e7eedd72e957a82d2244cb9a75c55",
          "body": "docs(adr): ADR-0039 — the operator layer stays outside the CLI",
          "is_bot": false,
          "headline": "Merge pull request #34 from stranxik/docs/operator-layer",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-21T13:08:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f93267556a5880ff4c08d87c53a587503dd3ce1a",
          "body": "… roadmap\n\nThree tiers named (docs to follow on the site), wiring guide planned,\ninert samples at most, operator tooling never in the MIT CLI, satellite\ndeferred behind the ADR-0028 channel-signal watch.",
          "is_bot": false,
          "headline": "docs(adr): ADR-0039 — the operator layer stays outside the CLI; groom…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-21T13:02:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "be6567000a99766a938789f91d0e889f559b2632",
          "body": "…tate\n\nfix(brownfield): close the resume-existing audit findings (ADR-0033–0038)",
          "is_bot": false,
          "headline": "Merge pull request #33 from stranxik/adr-0033-status-iterate-steady-s…",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-20T08:03:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1b48670efe8b83d599b15f6307e8cbd29fe4c726",
          "body": "A multi-agent audit of the resume-existing lot (adversarially verified,\n47/48 findings confirmed) surfaced three blockers and a set of important\ndefects, all in the code that promises deterministic *facts*. Fixed at\nthe root — no workarounds, no debt — with the ADRs amended to match.\n\nDeterminism (w\n[…]\nckfile fixture per\nclaimed family; scoped-extraction fixtures; the cross-locale determinism\nprobe. Also aligned runward's own ADR-0001 to the mandated trigger\nheading so its dogfooded status is clean.",
          "is_bot": false,
          "headline": "fix(brownfield): close the resume-existing audit findings (0033-0038)",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-20T07:55:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8bbef0c5e3f8b05460b9e8b6e03b37893652b0ed",
          "body": "ROADMAP.md had not been touched since v0.14.2: the floor-ts English\npass and the documentation site were both long shipped and still listed\nas ahead. Groomed, and — same fix pattern as the manifest stamps — a\npackaging test now fails the build if the 'Last groomed' stamp lags the\npackage version, so the roadmap can no longer rot silently.",
          "is_bot": false,
          "headline": "chore(roadmap): groom (7 releases late) + stale-roadmap guard",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-19T20:05:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "504c83823507864146e633f21ad1048bf466bd9b",
          "body": "README: the guiding principle now names its ancestry (information\nhiding, Parnas 1972; ports and adapters, Cockburn 2005) and states the\ndefault-not-requirement status inline, linking when-to-use. when-to-use:\nthe modularity paragraph gains the family map — onion, Clean,\nfunctional core, modular monolith all satisfy the hexa-* rules as\napplied (the rules check substance, never the label); vertical-slice or\ntransaction-script is the healthy deviated case.",
          "is_bot": false,
          "headline": "docs: place the hexagonal default in its fifty-year lineage",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-19T19:50:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9aaaf41e8a6014a69e9592db37c3ec79080eea04",
          "body": "The structure-neutrality argument existed without its words: the default\nshape is a modular core behind ports and adapters (hexagonal), a sober\ndefault with evolution triggers, never a requirement — the gate checks\nthe decision was confronted, and deviating with a traced ADR passes\ngreen (runward's own mission deviates). Extends the 'One language in\nthe core' neutrality from language to structure.",
          "is_bot": false,
          "headline": "docs(when-to-use): name modularity and the hexagonal default explicitly",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-19T19:43:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "67f924784b2e79915cfec87184ef28aa7b42c2a1",
          "body": "Extend 'runward gates itself' with the supply-chain parallel: publishing\nis a deliberate human gesture, everything downstream is deterministic\nmachinery (OIDC trusted publishing, SLSA provenance, attested SBOM).\nThe deterministic executes; the human decides the crossing.",
          "is_bot": false,
          "headline": "docs(readme): the release runs the same stance as the gate",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-19T19:28:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ed0ce84186282dcf9b8ba5b3ac58a52a2db81328",
          "body": "One command, the whole chain green: init --example now chains check --strict\non the freshly scaffolded reference mission (deterministic, zero-network,\nskipped under --dry-run), and its next-steps point at the guard demo\n(npm run demo — req-005, fabricated account, refused fail-closed).\n\nREADME accur\n[…]\nced comparison (Spec Kitty), FDE expanded on first use,\nWhy section leads with what runward does, compare + case-study linked from\nthe Documentation list. Example README counts all five demo requests.",
          "is_bot": false,
          "headline": "feat(init): --example ends by running the strict gate itself (v0.21.0)",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-19T19:10:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7860e9f8cab775e5d37ad8943a77d9db6903422a",
          "body": "docs(readme): surface 'try it' up front + lighten Why",
          "is_bot": false,
          "headline": "Merge pull request #32 from stranxik/docs/readme-try-it-early",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-19T13:47:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9117417b74edceb8325a362ad876519f2a9e6d48",
          "body": "Since the repo is the Show HN landing and the post's angle is 'go test it',\nmove the one-command trial up front (right after the entry, before the dense\nWhy section) instead of burying it ~50 lines down under Install. Show both:\n'npx runward init --example' (watch the chain go green + the guard catc\n[…]\nricated value) and 'npx runward init' (start your own project). Also\ncondense the densest Why paragraph (dropped the five-gestures enumeration;\nthe detail lives in the method/differentiator sections).",
          "is_bot": false,
          "headline": "docs(readme): surface 'try it' right after the entry + lighten Why",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-19T13:47:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c47997443e95d1d02ee35306b5a44125c8ce6ac7",
          "body": "fix(readme): self-host the npm badge (no shields/camo flap)",
          "is_bot": false,
          "headline": "Merge pull request #31 from stranxik/fix/npm-badge-self-hosted",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-19T13:14:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d7949cf90a9d122863d7c54573a2d2eb1a0d0032",
          "body": "The npm badge kept flapping (broken then delayed) — GitHub's camo proxy\nfetching img.shields.io at cold cache. It was the only dynamic badge; even\nmade static, it depends on the flaky camo<->shields path. Serve it from the\nrepo instead (raw.githubusercontent, GitHub's own domain, like the banner):\nrenders reliably, zero external dependency, no flap on launch day. Rendered\nat 2x, displayed at height 28 to match the shields for-the-badge row.",
          "is_bot": false,
          "headline": "fix(readme): self-host the npm badge (no more shields/camo flap)",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-19T13:13:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "87724fdf605f9462f214bc0ea6051d9b4896a667",
          "body": "fix(release): SBOM job must not attach to the release (contents:read)",
          "is_bot": false,
          "headline": "Merge pull request #30 from stranxik/fix/release-sbom-no-release-assets",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-19T13:01:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "094dc395dda2486581ccabf1c268eb3ad9648c46",
          "body": "The v0.20.0 release failed: anchore/sbom-action defaults to\nupload-release-assets:true, which needs contents:write — but the unprivileged\nSBOM job is contents:read (the whole point of the split). Set it false; the\nSBOM travels as a workflow artifact and the privileged publish job attaches it\nto the release (it has contents:write). Fail-closed worked: nothing published.",
          "is_bot": false,
          "headline": "fix(release): SBOM job must not attach to the release (contents:read)",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-19T13:00:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2e6328ac160d1865b64855faaa8505f2806031dc",
          "body": "chore(release): v0.20.0",
          "is_bot": false,
          "headline": "Merge pull request #29 from stranxik/release/v0.20.0",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-19T12:56:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0cf26286ff6676291262988cb37888552be83182",
          "body": "Bumps the version across package.json, the six distribution manifests (the\npackaging guard requires them in lockstep), CITATION.cff, the repo's own\nmission stamp and the distribution examples; adds the v0.20.0 CHANGELOG entry.\n\nShips: regulated-adoption evidence + SBOM/provenance (ADR-0031), OSCAL 1\n[…]\nven by a third-party tool (ADR-0032), the security-audit hardening, the\nTypeScript 7 forward-compat, and the docs/README work. Publish happens when\nthe GitHub Release is cut (OIDC trusted publishing).",
          "is_bot": false,
          "headline": "chore(release): v0.20.0",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-19T12:55:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f45dc122d5229dea4407179f9c1d2fc61fe3ec76",
          "body": "fix(readme): static npm badge (shields live endpoint failing)",
          "is_bot": false,
          "headline": "Merge pull request #28 from stranxik/fix/readme-npm-badge-static",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-19T12:52:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dbb84304fc28a6b3c57eabe004d9a1334bfa58c4",
          "body": "GitHub's camo returned 'Error Fetching Resource' fetching the dynamic\nimg.shields.io/npm/v/runward badge — shields' live npm-registry lookup was\ndown (the static shields badges rendered fine). Swap to a static npm badge\n(same for-the-badge style + npm logo) that never does a live lookup, so it\nrenders reliably. The version lives on the npm page, Releases and package.json.",
          "is_bot": false,
          "headline": "fix(readme): static npm badge (shields' live npm/v endpoint was failing)",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-19T12:51:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "823e468c94d7ce7b84ae985e1f4da0db911eb225",
          "body": "fix(readme): broken images (absolute banner URL + npm badge refresh)",
          "is_bot": false,
          "headline": "Merge pull request #27 from stranxik/fix/readme-broken-images",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-19T12:43:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f9032348d794df029225a08090c259ce4aa5d948",
          "body": "…images)\n\n- Banner used a relative path (assets/og-image-en.jpg) that npmjs.com can't\n  resolve (it isn't in the published tarball), so the header image was broken\n  on the npm package page. Point it at the raw GitHub URL — renders everywhere.\n- npm shields badge showed a broken-image icon on GitHub (camo cached a failed\n  shields fetch). Drop the redundant &label=npm (the npm/v badge already labels\n  itself 'npm'), which also changes the URL so GitHub re-fetches it.",
          "is_bot": false,
          "headline": "fix(readme): absolute banner URL + refresh the npm badge URL (broken …",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-19T12:42:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ec43c7088ce411b39632ab18e838a9f260accfd7",
          "body": "docs(readme): plainer HN-facing entry + version-less OG banner",
          "is_bot": false,
          "headline": "Merge pull request #26 from stranxik/docs/readme-entry-and-og",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-19T12:33:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fa42216dc9fc59491403f98d6d8cfe85392884d3",
          "body": "Since a Show HN links to the repo, the README is the landing. Rewrite the top\n(tagline + intro) in plain, direct language matching the launch post: lead with\n'AI writes the code — who verifies the engineering decisions behind it?', drop\nthe insider tagline ('the floor / run-grade engineering') and the dense\nthree-doors paragraph from the entry (that depth still lives in the sections\nbelow). Also swap in the evergreen, version-less OG banner.",
          "is_bot": false,
          "headline": "docs(readme): plainer HN-facing entry + version-less OG banner",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-19T12:32:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bfa702c73388f439a8d9610c874729c9667be398",
          "body": "chore(deps): ignore TypeScript major bumps in Dependabot",
          "is_bot": false,
          "headline": "Merge pull request #23 from stranxik/chore/dependabot-ignore-ts-major",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-18T19:45:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5f69dd26541c49750b78fcd2a9333ff5a121bf67",
          "body": "Adopting the TS 7 native-compiler preview on a published package is a\ndeliberate, hand-made call, not an automated bump — so Dependabot now\nignores typescript's major-version updates (minor/patch still flow). The\ntsconfig is already TS-7-ready (PR #22, types:[node]); this just stops the\nnoise until TS 7 is GA-stable. Documented in the dependabot.yml comment and\na CHANGELOG Unreleased entry.",
          "is_bot": false,
          "headline": "chore(deps): ignore TypeScript major bumps in Dependabot",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-18T19:44:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2b7f83f5f3efaa04dfc57108ffb0d99050386e54",
          "body": "chore(build): declare types:[node] in tsconfig (TypeScript 7 forward-compat)",
          "is_bot": false,
          "headline": "Merge pull request #22 from stranxik/chore/tsconfig-explicit-node-types",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-18T19:41:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "96822356398eff923f45c6d4a6c634b38638a825",
          "body": "…compat)\n\nThe tsconfig relied on TypeScript's implicit auto-inclusion of every\n@types/* package. TypeScript 7's native compiler drops that behaviour, so\nthe build failed with 102 errors (TS2591 'Cannot find name node:fs/…',\nplus cascading TS7006 implicit-any once @types/node no longer resolved).\nDec\n[…]\nexplicitly fixes it and is fully backward-compatible\n(TS 5.9.3 still builds with zero errors). Better hygiene regardless; makes\nthe eventual TypeScript 7 bump a clean pass. typescript stays at ^5.9.3.",
          "is_bot": false,
          "headline": "chore(build): declare types:[node] in tsconfig (TypeScript 7 forward-…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-18T19:40:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "19d87513ddbeedba2797ae1fbc834b5fce54e70c",
          "body": "chore(security): move SBOM generation out of the OIDC-privileged publish job",
          "is_bot": false,
          "headline": "Merge pull request #21 from stranxik/chore/release-sbom-least-privilege",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-18T11:13:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "90e8dc48170e75b7fca6a6993891f35e707383e4",
          "body": "…ish job\n\nAudit finding #1 (low): the third-party anchore/sbom-action ran inside the\nsingle publish job that holds id-token:write + contents:write. Split it into\na separate 'sbom' job with contents:read only; the privileged 'publish' job\nnow downloads that SBOM artifact and attests it. Workflow-leve\n[…]\n-closed: if SBOM\ngeneration or download fails, publish does not run.\n\nPins actions/download-artifact@d3f86a1 (v4). Needs validation on the next\nreal release (the OIDC publish path cannot run on a PR).",
          "is_bot": false,
          "headline": "chore(security): move SBOM generation out of the OIDC-privileged publ…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-18T11:12:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9a9608f450b065a8f09c8fc9060a872728a5c74e",
          "body": "chore(security): hardening from the security audit (CI, engines, ReDoS screen)",
          "is_bot": false,
          "headline": "Merge pull request #20 from stranxik/chore/security-hardening-audit",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-18T11:09:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1747efc1f694d7a8892b8b37107cd18c967c26ed",
          "body": "…S screen)\n\n- CI: set persist-credentials:false on every checkout in ci.yml and\n  watch-external-facts.yml, matching release.yml/scorecard.yml (OSSF\n  Scorecard consistency; no token left in the working tree).\n- engines: raise the Node floor to >=22.12.0 (was >=20). Node 20 is EOL\n  since 2026-04 an\n[…]\nscreen missed. Deterministic, zero-dep, in the spirit\n  of ADR-0020; a hostile rule signature can no longer hang check --strict.\n  Adds tests; existing safe signatures stay accepted (self-gate green).",
          "is_bot": false,
          "headline": "chore(security): hardening from the security audit (CI, engines, ReDo…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-18T11:03:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "231f18c2e14480eb356c7fde5c229e7e4c4466a9",
          "body": "docs(readme): use language-neutral /docs links",
          "is_bot": false,
          "headline": "Merge pull request #19 from stranxik/docs/readme-neutral-docs-links",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-18T10:27:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3aa8ce8ee3f6a64b99c6f91b1ccb3593f7d5b560",
          "body": "The docs site now auto-routes /docs to the visitor's language (French\nbrowser -> French, otherwise English), so the README no longer needs to\npin /docs/en. Neutral links serve each reader their own language.",
          "is_bot": false,
          "headline": "docs(readme): use language-neutral /docs links",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-18T10:27:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c8d2ef0750f0f9bd870ab3b94e266064f219893f",
          "body": "docs(readme): point doc-site links to the English docs (/docs/en)",
          "is_bot": false,
          "headline": "Merge pull request #18 from stranxik/docs/readme-en-links",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-18T09:57:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "96d6d646b55407ebab866f2862244063b9934886",
          "body": "The repo is English-only; the hosted /docs root is the French default and\n/docs/en is the English tree. Point the Docs badge and the Documentation\nsection links at /docs/en so they match the repo language. Visible label\nleft as runward.dev/docs.",
          "is_bot": false,
          "headline": "docs(readme): point doc-site links to the English docs (/docs/en)",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-18T09:57:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "34f6b520b4a5f493655ccf8417c8d47103bf79f1",
          "body": "docs(readme): surface the hosted documentation site",
          "is_bot": false,
          "headline": "Merge pull request #17 from stranxik/docs/readme-site-links",
          "author_name": "Thibault",
          "author_login": "stranxik",
          "committed_at": "2026-07-18T09:44:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "efec03eae34a791cce3e1258c5fe36b3f128dc57",
          "body": "The README only linked to in-repo markdown. Add a Docs badge and a\nDocumentation section pointing to runward.dev/docs with the key entry\npoints (quickstart, the deterministic gate, six phases, from-an-agent,\ncompliance evidence). In-repo doc links are kept as-is.",
          "is_bot": false,
          "headline": "docs(readme): surface the hosted documentation site",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-18T09:40:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e2bdc619645b302729e9a979698eef7a7c6011c1",
          "body": "A multi-agent documentation audit flagged small repo-to-world drifts:\n- src/lib/tools.ts: JSDoc said 'four phase skills' but PHASE_SKILLS has\n  five (architect, topology, floor, govern, handover).\n- runward/architecture.md: stamped v0.18.1 and cited 24 / 28 ADRs while\n  the journal holds 32; bumped to v0.19.0 (2026-07-17), counts -> 32.\n- runward/contracts/port-contract.md: the check signature omitted the\n  --json flag the CLI ships.\n\nSelf-gate strict green, 77/77 tests.",
          "is_bot": false,
          "headline": "docs: correct stale factual drifts surfaced by the docs audit",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-17T19:51:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4ea3b8b37f087f3ddadf842712edafd45277e700",
          "body": "The watch (issue #16) flagged runward two OSCAL generations behind NIST.\nA close-look investigation proved the bump trivial and risk-free:\n\n- our exact output validates against the NIST 1.2.2 component-definition\n  schema (runward's own ajv harness), version literal aside;\n- compliance-trestle 4.2.0\n[…]\nthe\n  self-hosting mission deliverables). CHANGELOG left historical.\n- ADR-0032 rewritten + renamed; watch OSCAL message reworded.\n- 77/77 tests green; trestle ingests the fresh 1.2.2 pack end-to-end.",
          "is_bot": false,
          "headline": "feat(oscal): track current OSCAL — bump 1.1.2 -> 1.2.2 (ADR-0032)",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-17T18:18:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0fdbc43b7133acfa2ef72f98b0c41d22e52a58b6",
          "body": "runward had silently fallen two OSCAL generations behind NIST (pinned\n1.1.2; NIST is at 1.2.2) with no test reddening — internal drift guards\ncompare repo-to-doc, never repo-to-world.\n\n- ADR-0032: staying on OSCAL 1.1.2 is a deliberate, recorded choice\n  (1.2.x is additive/backward-compatible; a bum\n[…]\n; others annual). It never\n  enters the OSCAL, so the golden is unchanged.\n- regulated-posture drift guard asserts the watch exists and tracks both\n  OSCAL and reviewBy, so silent deletion reddens CI.",
          "is_bot": false,
          "headline": "feat(governance): watch dated external facts out-of-band (ADR-0032)",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-17T18:00:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fc60a2ad72a4a042f54e8cb6aa9d9daa0edf0d73",
          "body": "The note describing the guard quoted the forbidden term \"audit-grade\"\nliterally, in a line the negation scanner does not count as negated.\nReword to \"a forbidden overclaim\" so the guard stops biting itself.",
          "is_bot": false,
          "headline": "fix(ci): positioning drift guard tripped on its own meta-note",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-17T17:53:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1999a78c8671078c1c8bf4e0837fd55948ad1f91",
          "body": "…ompliance-trestle)\n\nCloses the gap flagged as the most visible in regulated review: the OSCAL pack was validated\nonly against our vendored NIST JSON schema. Now every CI run also loads it in a real, independent\nOSCAL tool.\n\n- ci.yml job 'oscal-ingest': emit a pack from the reference mission, then i\n[…]\nRC SaaS ingestion stays the operator's step.\n- Drift guard extended: the oscal-ingest job + script are now enforced, so this proof can't be\n  silently dropped. Self-gate strict green; drift guard 6/6.",
          "is_bot": false,
          "headline": "feat(regulated): prove OSCAL ingestion by a third-party tool in CI (c…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-17T17:45:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "53b8c6f5178efa94640f8639744b2234892db926",
          "body": "…of truth cannot lie\n\nSame principle as the regulated-adoption guard: pin the verifiable claims of the marketing\nsource of truth so they cannot silently drift or overclaim.\n\ntest/unit/positioning-drift.test.js enforces:\n- the MANDATORY compliance guardrails are present and intact (audit-ready, NOT a\n[…]\nry cited ADR-NNNN exists.\nProven to bite: a stale date or a diluted guardrail fails it. Runs in npm test → in the self-gate.\nSubjective wording stays free. Self-gate strict green; 81 unit checks pass.",
          "is_bot": false,
          "headline": "feat(positioning): drift guard over positioning.md — the copy source …",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-17T17:37:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "db130e7410b5d0a8d3520bb98bd622ee55e4b1c7",
          "body": "…n sheet\n\nTwo things, both the runward principle turned on runward's own governance — the agent\nproduces, a deterministic gate guarantees, the operator decides.\n\n- SBOM on every push/PR (ci.yml, Syft SHA-pinned), not only at release: surfaces a\n  dependency drift between releases as an artifact.\n- t\n[…]\n stale. Proven to bite:\n  un-pinning an action fails the guard. Runs in npm test, so it's in the self-gate.\n- The sheet now states it is enforced by this guard. Self-gate strict green; npm test green.",
          "is_bot": false,
          "headline": "feat(regulated): SBOM in CI + a drift guard that enforces the adoptio…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-17T17:31:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bc2ed95920e42a3bcf07811b751baaa9cc521a43",
          "body": "…ne, factual corrections\n\nThree-agent adversarial audit of the regulated wedge; all confirmed findings fixed.\n\nSecurity (release workflow):\n- Publish the packed tarball itself (npm publish $TARBALL) so the SBOM attestation binds\n  to the exact artifact downloaded (attested == published) — the integr\n[…]\nis no secret scanner — the true claim is\n  no long-lived Actions secrets at all (OIDC trusted publishing).\n- SECURITY.md now links the regulated-adoption sheet. Self-gate strict green; npm test green.",
          "is_bot": false,
          "headline": "fix(regulated): audit follow-ups — SBOM integrity, supply-chain hygie…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-17T17:23:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "37bce033360fa15c5e66e357e89c8c89e5c21600",
          "body": "…icence framing (ADR-0031)\n\nA four-agent investigation confirmed runward is usable in regulated environments as a\nwedge (sovereign engineering evidence that feeds a compliance programme), not a validator,\nand that its local/no-data-flow nature makes most vendor due-diligence moot. This closes\nthe *r\n[…]\n, and the honest limits\n  (no runtime logs for art.12, point-in-time, single-maintainer/no-SLA, forkability).\n- Linked from the compliance index and the README. Self-gate strict green; npm test green.",
          "is_bot": false,
          "headline": "feat(regulated): narrow the wedge — SBOM, regulated-adoption sheet, l…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-17T17:11:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "228f1f18b1e01a285fbcd8adc385e1009de34a42",
          "body": null,
          "is_bot": false,
          "headline": "docs(changelog): date v0.19.0 to its release day (2026-07-17)",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-17T12:45:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4941980f5359b2f75452c359637a4d129da30129",
          "body": "Version bump across package.json, CITATION.cff, and the six distribution manifests\n(packaging.test guard green), plus the CHANGELOG entry and the distribution.md pin\nexamples. ADR-0030 ships: neutral init default, runward wire (read-only harness\ndetection), check --json, hardened non-interactivity.",
          "is_bot": false,
          "headline": "chore(release): bump to 0.19.0 — agent-operable baseline + runward wire",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T14:39:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ab4472b3892c930064dc86c5b58bdea25c39a343",
          "body": "…e null-channel path, ADR + doc coherence\n\n- check --json --hooks no longer corrupts the JSON contract: a hook's stdout is\n  routed to stderr (fd 2) under --json, since log() cannot suppress a subprocess\n  (audit finding, machine-contract blocker).\n- wire: when a config-detected harness ships no cha\n[…]\ndsurf → recommendedChannel null, bare-mission → undetermined, and check --json\n  --strict exposes conformance / --json alone omits it. Unit 65, smoke green.\n- README: add the runward wire command row.",
          "is_bot": false,
          "headline": "fix(check,wire): audit follow-ups — no JSON pollution from hooks, wir…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T14:16:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f71b0fb3d97b17c077feee968c56153bd8170140",
          "body": "…ead-only (ADR-0030)\n\n- runward wire: detects the AI harness running the command via verified runtime\n  signals (CLAUDECODE for Claude Code + Cowork, GEMINI_CLI, CURSOR_AGENT), falling\n  back to config-file markers (weaker), then 'undetermined'. Recommends the matching\n  auto-trigger channel and poi\n[…]\n(runtime signal > config file > undetermined).\n- Tests: 6 unit cases (signal precedence, Cursor marker, undetermined, config override,\n  wires:false invariant) + a smoke contract check on wire --json.",
          "is_bot": false,
          "headline": "feat(wire): best-effort harness detection → channel recommendation, r…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T14:09:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "88ac7018eacd5cbfdce3f9a443656abd8c95e442",
          "body": "…on, hardened non-interactivity (ADR-0030)\n\n- init with no explicit --tools now writes only the vendor-neutral baseline\n  (AGENTS.md + .agents/skills); --yes no longer defaults to the claude profile\n  and the wizard pre-checks nothing. Closes a standing vendor-neutrality breach.\n- check --json: a st\n[…]\ne operating model: neutral baseline, best-effort harness\n  detection (never a prerequisite, never self-wiring), machine-readable surface.\n- Tests: neutral-default and check --json assertions in smoke.",
          "is_bot": false,
          "headline": "feat(cli): agent-operable baseline — neutral init default, check --js…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T13:58:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "06d9ed68da09f86ca36f9831a2acd4e21813bdcb",
          "body": "…-telemetry (verified)",
          "is_bot": false,
          "headline": "docs(positioning): quote RFC-0024 verbatim on GenAI-not-deterministic…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T12:55:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "191d80c3498fc316872710652cda86b4374d6030",
          "body": "…oundary)\n\nDistribution-comms pass, from a 3-agent investigation.\n- README: the distribution story was told 3× (lines 56/63/88, with a double\n  enumeration of the same siblings). Consolidated into one tier-structured\n  block in Install (hard-CI / hard-turn-end / soft-per-tool / discovery-only),\n  di\n[…]\nunded (MCP tools are model-controlled; the registry needs a\n  runnable package). packaging/mcp/README and distribution.md cite it.\nNo badge added (a Claude-specific one would break vendor-neutrality).",
          "is_bot": false,
          "headline": "docs(dist): consolidate the README install story, add ADR-0029 (MCP b…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T12:52:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "324a08b5e1a6140e6ba835090a58f2124ef27e7e",
          "body": "- Copilot: drop-in install path documented (.github/hooks/ or ~/.copilot/hooks/), no submission.\n- Cursor: consumable via the hooks.json drop-in (advisory stop, soft per-tool).\n- Kiro: published from a thin dedicated repo (stranxik/runward-kiro) because Kiro requires\n  POWER.md at the repo root, wit\n[…]\n: not published, by design — the registry needs a real MCP server package, and an MCP\n  tool is model-controlled (discovery, never a gate). The descriptor documents that stance;\n  no MCP server ships.",
          "is_bot": false,
          "headline": "docs(dist): finalize the last four channels (Copilot, Cursor, Kiro, MCP)",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T12:07:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3027840709fabe5d542fa5aa5d21bee1e245f934",
          "body": "Codex: document the git-backed --sparse install (packaging/codex reads\ndirectly, no copy) and note the marketplace.json now matches the documented\nschema; the curated Codex directory is partners-only, the --sparse add is open.\nGemini: gemini extensions install requires the manifest at the repo root,\n[…]\n\nthe extension is published from a thin dedicated repo (stranxik/runward-gemini);\npackaging/gemini/ is the mirrored source, with gemini extensions link for local\ndev. distribution.md updated for both.",
          "is_bot": false,
          "headline": "docs(dist): Codex --sparse install + Gemini dedicated-repo pointer",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T11:56:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f889102d30e0bd1efcb80af08e12bea374425810",
          "body": "…in) to the Install section",
          "is_bot": false,
          "headline": "docs(readme): add wire-the-gate install (CI Action + Claude Code plug…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T11:13:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "46ff53108e3c417dfc14df10a4496e3c7c9a3870",
          "body": null,
          "is_bot": false,
          "headline": "docs(readme): add GitHub Marketplace badge for the runward gate Action",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T11:09:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f07b59c7189e64cfdb78fa9827ac85d9aff39033",
          "body": null,
          "is_bot": false,
          "headline": "docs(dist): align the CI pin example to 0.18.1",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T10:29:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "af3fd86c1bfbfad91987e6ee7032d83a0ce48bb9",
          "body": "…elog, bumps, stamps",
          "is_bot": false,
          "headline": "chore(release): v0.18.1 — security + pre-marketplace hardening; chang…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T10:29:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bcb2c331e94b2c52685d5343e375eb16d61783dd",
          "body": "A 5-agent adversarial audit (security, compliance, code coherence, packagings,\narchitecture) before public marketplace submission. Two real security holes,\nplus polish. Fixed:\n\n- SECURITY — seal traversal (evidence.ts verifyEvidenceLock): the seal writer\n  confined paths (v0.17) but the verifier did\n[…]\nount harmonized to 28 (was 24/26 in four places).\n- Guards: unit tests for the seal-traversal rejection, the ReDoS screen, and a\n  packaging version/hook check that would have caught the 0.17.0 drift.",
          "is_bot": false,
          "headline": "fix(security+dist): close the pre-marketplace audit findings",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T10:26:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3d6aaf3ef88736ed6067d861a4f1dd74c34d6267",
          "body": null,
          "is_bot": false,
          "headline": "docs: refresh README OG banner to v0.18.0",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T08:25:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cca5f0e6a5680a7542692bd1d4830044715bfc44",
          "body": "… stamps",
          "is_bot": false,
          "headline": "chore(release): v0.18.0 — distributable packagings; changelog, bumps,…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T08:22:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9231a86969a45db778fedfd0b4344cf091e39830",
          "body": "…nization, link the honest map)\n\nMerged the packaging/ family (Gemini, Codex, Copilot, Cursor, Kiro, MCP)\nbuilt per ADR-0028, and reconciled it with the core done in parallel:\n- every hook command is npx --yes runward check --strict (robust after a\n  bare plugin install, matching plugins/runward-gat\n[…]\n\nsoft per-tool (Cursor/Kiro), discovery-only for MCP (model-controlled,\nnever a gate). Format-uncertainty flags kept in each channel's README\n(Codex/Cursor/Copilot manifests to confirm at submission).",
          "is_bot": false,
          "headline": "feat(dist): reconcile per-harness packagings with the core (npx harmo…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T08:20:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "be3479cfdd8c16e7a15a62e7715832b31b26252b",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'worktree-agent-aa229ab9b6d1d6a1d'",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T08:19:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c8e51b3f8f854023783963abbd0a2a47675d35a7",
          "body": "…Kiro, MCP descriptor (ADR-0028)",
          "is_bot": false,
          "headline": "feat(dist): per-harness packagings — Gemini, Codex, Copilot, Cursor, …",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T08:18:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "17b85217b4fd94d8b4dbf429bee9e68c10851409",
          "body": null,
          "is_bot": false,
          "headline": "docs(dist): the honest channel map (docs/distribution.md) + README link",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T08:12:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "32ce06d350fcf7b359186067bee5295d8e67cfaf",
          "body": "…gin+marketplace)",
          "is_bot": false,
          "headline": "wip(dist): ADR-0028 + core packagings (GitHub Action, Claude Code plu…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T08:11:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dd0d8fee80461dcceffc7567e6df55a67d0185db",
          "body": "…ver is gated; OSCAL as a citable spec\n\nThe distribution/message pass: lead the differentiators with the unique\ncombination a code-level benchmark confirmed nobody else pairs (rule-level\ngate with sealed evidence, gated hand-over, published OSCAL mapping); fix\nthe stale '58 craft rules' (now 64); reframe hand-over as a gated\ndeliverable, not a folder; present the OSCAL mapping as the reference,\ncitable mini-spec; add the FedRAMP RFC-0024 / Delve backing for the\nzero-LLM stance.",
          "is_bot": false,
          "headline": "docs(readme): frame the four grounds; fix rule count (58->64); hand-o…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T06:47:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8794f0f69aa2387198f5bf71d3bf2d20b8384858",
          "body": null,
          "is_bot": false,
          "headline": "docs: refresh README OG banner to v0.17.0",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T02:53:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d12483ca8d17f0077fd88b7ad7feeb0b734c2076",
          "body": "…t date\n\nCHANGELOG for the second-audit hardening (traversal, ReDoS, OSCAL/spec\nreconciliation, seal scope, RUNWARD_NOW, doc regressions), the EU AI Act\ndate correction, and the BMAD review-layer adapter; version 0.17.0; mission\nstamps and CITATION.cff bumped.",
          "is_bot": false,
          "headline": "chore(release): v0.17.0 — audit remediation + BMAD adapter + EU AI Ac…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T02:50:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d6593e79d3086ab85173883e6db4810c3a7a18fd",
          "body": "…AD calls (ADR-0027)\n\nA fresh code-level competitive benchmark found a distribution seam: BMAD's\nbmad-code-review exposes a review-layers extension point whose instruction\nmay 'run anything (e.g. an external reviewer via bash)'. templates/adapters/\nbmad-review-layer.toml adds runward's deterministic\n[…]\nileged over the\nother orchestrators (ADR-0027). EXPECTED_ADAPTERS 5 -> 6; README documents\nthe seam; smoke covers the path. Also fixed the compliance unit test that\nhad frozen the pre-Omnibus EU date.",
          "is_bot": false,
          "headline": "feat(adapters): BMAD review-layer adapter — the gate as a reviewer BM…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T02:49:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d36f4b040622fb4915916c1ed1674dc21f408309",
          "body": "…igital Omnibus)\n\nThe Digital Omnibus on AI (Council final green light 29 June 2026) postponed\nthe Annex III/IV high-risk obligations from 2 August 2026 to 2 December 2027\n— our regime data and docs still carried the stale deadline, which the OSCAL\nreadiness draft printed. Corrected in place (a fact\n[…]\nedRAMP RFC-0024 forbidding GenAI-produced evidence\n(a federal validation of the zero-LLM gate) and the Delve affair (AI-prefilled\nSOC 2 audits) — both arguing that AI-produced evidence is not trusted.",
          "is_bot": false,
          "headline": "fix(compliance): EU AI Act high-risk date 2026-08-02 -> 2027-12-02 (D…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T02:46:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "669a06d0a1f28e56eb996638e27d5e1a02f9bfd0",
          "body": "…r adapter count, README Kiro/topology)\n\n- first-mission.md: the wizard poses five prompts, not four (the 'What are\n  you building?' seed was undocumented); refreshed the stale output counts\n  (84 -> 119 files, 11 -> 13 deliverables) and the current gate message.\n- doctor + EXPECTED_ADAPTERS: count \n[…]\nng the README; now 5 real adapters).\n- README: execution-topology.md added to the mission tree (a gated\n  deliverable was missing), Kiro added to the tool-profiles list and the\n  adapter-seam comment.",
          "is_bot": false,
          "headline": "docs/fix: doc regressions from the audit (first-mission counts, docto…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T02:45:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8577b2a2dd73a066d499f3a0bebcdd6d8867b324",
          "body": "…SCAL/spec drift, seal scope\n\nA second adversarial audit (our own method on ourselves) broke four things\nshipped in v0.15/v0.16. Closed, still deterministic, zero-LLM:\n\n- Path traversal (CASSE): file:/etc/hosts and file:../../etc/hosts passed\n  the gate green, contradicting ADR-0019's 'resolves unde\n[…]\ntity across filesystems.\n\nGolden regenerated (href now regime-derived). Unit + smoke cover traversal,\nReDoS, order-independent OSCAL aggregation, the regime-derived link, and the\nRUNWARD_NOW fallback.",
          "is_bot": false,
          "headline": "fix(gate): close the audit's four gate fissures — traversal, ReDoS, O…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T02:42:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c3075231b999376c086272aa3c9d82be155826c9",
          "body": null,
          "is_bot": false,
          "headline": "docs: refresh README OG banner to v0.16.0",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T02:05:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "634783c96dbb8a36fbb28c714c4e36d6e3e9587d",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): v0.16.0 — changelog, version bump, mission stamps",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T02:01:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7eff24e904a909b87eb155dd33c56db149d4a640",
          "body": "The audit's whitespace finding, executed with ADR-0017's own move: the\npromise 'the hand-over is proven by a real task redone without you' was\nDefinition-of-Done prose no gate verified — the differentiator was the\nleast backed claim in the chain. Now:\n\n- runward/handover.md joins the mission layout \n[…]\nt on both missions.\n- The handover workflow's Outputs/DoD name the gated note; the golden\n  OSCAL is regenerated (the new rules extend ASI08/09/10 coverage);\n  smoke covers the fifth phase end to end.",
          "is_bot": false,
          "headline": "feat(gate): hand-over becomes a gated conformance phase (ADR-0026)",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T02:00:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9a6745cef5d8194f83fa64206afb980e0477c6b1",
          "body": "…ec (ADR-0025)\n\ndocs/spec/runward-oscal-mapping.md v1.0 — implementation-independent: the\ndecision -> ADR -> manifest -> OSCAL chain, the component-definition shape,\nthe implementation-status derivation rules (with the paper-coverage\nasymmetry stated), the deterministic UUID seed grammar, the regime\n[…]\nations. The golden fixture\nis promoted to normative example (the conformance suite wins over the\nprose). CITATION.cff at the root makes citing mechanical; README and the\ncompliance docs link the spec.",
          "is_bot": false,
          "headline": "docs(spec): publish the OSCAL mapping as a versioned, citable mini-sp…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T01:53:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0afd80c6c2ceb1207a24323f9abf12e8d996f38c",
          "body": "… gate sample (ADR-0018 amended)\n\n--tools kiro mirrors the phase skills as .kiro/steering/runward-<phase>.md\n(inclusion: auto + name + description — Kiro's relevance idiom, same\nsemantics as the SKILL.md trigger); AGENTS.md is read natively by Kiro so\nthe charter needs no extra file. templates/adapt\n[…]\nne port as the Claude Code hook. EXPECTED_ADAPTERS 5 -> 6;\nadapters README documents both seams; smoke covers profile emission,\nrelevance frontmatter, subordination to the gate, and the adapter count.",
          "is_bot": false,
          "headline": "feat(adapters): Kiro — steering mirror of the phase skills, Stop-hook…",
          "author_name": "Thibault Souris",
          "author_login": "stranxik",
          "committed_at": "2026-07-16T01:50:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        }
      ],
      "releases_count": 26,
      "commits_last_year": 240,
      "latest_release_at": "2026-07-21T15:17:35Z",
      "latest_release_tag": "v0.22.0",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 4,
      "days_since_latest_release": 8,
      "mean_days_between_releases": 0.6
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 100,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "runward",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "agentic",
            "ai-agents",
            "spec-driven",
            "delivery",
            "governance",
            "llm",
            "architecture"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/runward",
          "is_deprecated": false,
          "latest_version": "0.22.0",
          "repository_url": "https://github.com/stranxik/runward",
          "versions_count": 27,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 3163,
          "first_published_at": "2026-07-06T12:51:50.241000Z",
          "latest_published_at": "2026-07-21T15:18:25.901000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 8
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 1,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": null,
      "open_issues_and_prs": 8
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": true,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "examples/request-triage/code/tsconfig.json",
        "floor-ts/tsconfig.json",
        "tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 41069,
      "source_files_sampled": 90,
      "oversized_source_files": 0,
      "agent_instruction_files": [
        "examples/request-triage/AGENTS.md",
        "floor-ts/AGENTS.md",
        "templates/targets/AGENTS.md"
      ],
      "agent_instruction_max_bytes": 133430
    },
    "dependencies": {
      "manifests": [
        "floor-ts/package.json",
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 27,
        "malicious_count": 0,
        "assessed_package": "npm:runward@0.22.0",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "zod",
          "manifest": "floor-ts/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.4.3"
        },
        {
          "name": "@inquirer/prompts",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^8.5.2"
        },
        {
          "name": "chalk",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.6.0"
        },
        {
          "name": "commander",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^15.0.0"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 8,
        "merged_prs": 33,
        "open_issues": 0,
        "closed_ratio": 1,
        "closed_issues": 1,
        "closed_unmerged_prs": 6
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "stranxik",
          "commits": 200,
          "avatar_url": "https://avatars.githubusercontent.com/u/26541747?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "release.yml",
        "scorecard.yml",
        "watch-external-facts.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": null,
            "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "8 out of 8 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/13 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 9,
            "reason": "dependency not pinned by hash detected -- score normalized to 9",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 10,
            "reason": "GitHub workflow tokens follow principle of least privilege",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 8,
            "reason": "2 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "9c30a25dd438f14658afbdd5b47b1ec40c06ad63",
        "ran_at": "2026-07-30T03:35:05Z",
        "aggregate_score": 5.9,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-29T09:54:31Z",
      "oldest_open_prs": [
        {
          "number": 24,
          "created_at": "2026-07-18T19:46:16Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 40,
          "created_at": "2026-07-22T03:24:24Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 41,
          "created_at": "2026-07-22T03:24:27Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 43,
          "created_at": "2026-07-29T03:23:49Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 44,
          "created_at": "2026-07-29T03:23:59Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 45,
          "created_at": "2026-07-29T03:24:05Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 46,
          "created_at": "2026-07-29T03:24:11Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 47,
          "created_at": "2026-07-29T03:24:15Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-29T09:53:59Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/stranxik/runward",
    "host": "github.com",
    "name": "runward",
    "owner": "stranxik"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 63,
      "inputs": {
        "security": 67,
        "vitality": 70,
        "community": 47,
        "governance": 54,
        "engineering": 77
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 70,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 57,
            "inputs": {
              "commits_last_year": 240,
              "human_commit_share": 1,
              "days_since_last_push": 0,
              "active_weeks_last_year": 4
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "4/52 weeks with commits",
                "points": 2.8,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 4
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "240 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 240
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 26,
              "latest_release_tag": "v0.22.0",
              "releases_from_tags": false,
              "days_since_latest_release": 8,
              "mean_days_between_releases": 0.6
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "26 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 26
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 8 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 8
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~0.6 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 0.6
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 47,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 1,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "1 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 58,
            "inputs": {
              "packages": [
                "runward"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 3163
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "3,163 downloads/month across npm",
                "points": 46.7,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 3163,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 54,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 79,
            "inputs": {
              "merged_prs": 33,
              "open_issues": 0,
              "closed_issues": 1,
              "issue_closed_ratio": 1,
              "closed_unmerged_prs": 6
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "100% of issues closed",
                "points": 46.8,
                "status": "met",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "33/39 decided PRs merged",
                "points": 32.4,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 33,
                      "decided": 39
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/13 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 46,
            "inputs": {
              "followers": 6,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "stranxik",
              "public_repos": 15,
              "account_age_days": 3418
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "6 followers of stranxik",
                "points": 6.1,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 6,
                      "login": "stranxik"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "15 public repos, account ~9 yr old",
                "points": 20.8,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 15
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 9
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "runward"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 8
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 8 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 8
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "27 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 27
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 77,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "4 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "8 out of 8 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": "https://runward.dev",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://runward.dev",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 67,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Branch-Protection. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "branch_protection"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 59,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 5.9
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "8 out of 8 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/13 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 9",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "GitHub workflow tokens follow principle of least privilege",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "2 existing vulnerabilities detected",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:runward@0.22.0 runtime dependency closure — what installing the published package pulls in — 27 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:runward@0.22.0",
                  "assessed": 27
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 0,
              "affected_packages": 0,
              "assessed_packages": 27,
              "unassessed_packages": 0,
              "affected_by_severity": "none",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "no indirect dependency carries a known advisory",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "no_indirect_advisories",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 27,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 72,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.95,
              "agent_instruction_files": [
                "examples/request-triage/AGENTS.md",
                "floor-ts/AGENTS.md",
                "templates/targets/AGENTS.md"
              ],
              "agent_instruction_max_bytes": 133430
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "examples/request-triage/AGENTS.md, floor-ts/AGENTS.md, templates/targets/AGENTS.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples/request-triage/AGENTS.md, floor-ts/AGENTS.md, templates/targets/AGENTS.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "95 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 95,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 57,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "package-lock.json"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "examples/request-triage/code/tsconfig.json",
                "floor-ts/tsconfig.json",
                "tsconfig.json"
              ],
              "agent_commit_share": 0,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "examples/request-triage/code/tsconfig.json, floor-ts/tsconfig.json, tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples/request-triage/code/tsconfig.json, floor-ts/tsconfig.json, tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "dependency automation configured, none observed in the sampled commits",
                "points": 5,
                "status": "partial",
                "details": [
                  {
                    "code": "dependency_bot_config_only",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 9",
                "points": 9,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 41069,
              "source_files_sampled": 90,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/90 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 90,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "moderate",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": true,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-30T03:35:19.084065Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/s/stranxik/runward.svg",
  "full_name": "stranxik/runward",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsnpm.