Public record
Software health reportschema 0.25.0 · metrics 1.13.0 · 2026-07-21 23:06 UTC

toshtag / code-pact

Vendor-neutral control plane for AI coding agents. Deterministic CLI surface for context fetch, verify, and progress. Stable in v1.0 for claude-code / codex / generic; cursor / gemini-cli experimental.

TypeScriptMIT★ 1 star⑂ 1 forksince May 2026View on GitHub ↗

toshtag/code-pact holds a health index of 60 out of 100, placing it in the Moderate band. It scores highest on Engineering Quality (77/100) and lowest on Community & Adoption (41/100). It was last updated today. A single contributor accounts for most of its recent work.

60
overall / 100
Moderate

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

60
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

PocketPersonal account
3 followers6 public repossince Dec 2022

This repository is owned by a personal account. A single-owner project carries more continuity risk than an organization-backed one.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publishTags
npmcode-pact2.7.02,102624 days agoaiagentcliclaudecodexdesignspec-driven

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

72Good · 22% of overall
How it's scored
36/36Push recency — last push 0 days ago
6.2/36Commit cadence — 9/52 weeks with commits
18/18Commit volume — 532 commits in the last year
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Inputs used
commits_last_year532
human_commit_share0.99
days_since_last_push0
active_weeks_last_year9
How it's scored
27/27Ships releases — 62 releases published
36/36Release recency — latest release 0 days ago
27/27Release cadence — a release every ~3.6 days
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Inputs used
releases_count62
latest_release_tagP80-T2-evidence
releases_from_tagsno
days_since_latest_release0
mean_days_between_releases3.6

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

41At risk · 18% of overall
How it's scored
0/60Stars — 1 stars
0/25Forks — 1 forks
0/15Watchers — 0 watchers
Inputs used
forks1
stars1
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonbelow_threshold
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (MIT)
18/18CONTRIBUTING guide
0/13.5Code of conduct
0/7.2Issue template
6.3/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingyes
has_issue_templateno
has_code_of_conductno
has_pull_request_templateyes
How it's scored
44.3/80Monthly downloads — 2,102 downloads/month across npm
0/20Registry dependents — not reported by this ecosystem
Inputs used
packagescode-pact
dependents
ecosystemsnpm
total_downloads
monthly_downloads2,102
Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

51Moderate · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
0/22.5Commit distribution — top contributor authored 100% of commits
1.4/13.5Contributor breadth — 1 contributors
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Inputs used
bus_factor1
contributors_sampled1
top_contributor_share1
How it's scored
38.9/46.8Issue resolution — 83% of issues closed
38.1/38.3PR acceptance — 537/539 decided PRs merged
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Inputs used
merged_prs537
open_issues1
closed_issues5
issue_closed_ratio0.833
closed_unmerged_prs2
How it's scored
10/30Ownership backing — personal (user) account
0/20Verified domain — not applicable to user accounts
4.3/25Owner reach — 3 followers of toshtag
13.4/25Track record — 6 public repos, account ~3 yr old
Inputs used
followers3
owner_typeUser
is_verified
owner_logintoshtag
public_repos6
account_age_days1,328
Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.
How it's scored
25/25Published & resolvable — 1 package(s) on npm
35/35Publish recency — latest publish 4 days ago
20/20Version history — 62 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packagescode-pact
ecosystemsnpm
any_deprecatedno
min_days_since_publish4

Engineering Quality

Are baseline engineering and documentation practices in place?

77Good · 20% of overall
How it's scored
24/24CI workflows — 3 workflow(s)
24/24Tests present
0/16Linter config
0/9.6Pre-commit hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 27 out of 27 merged PRs checked by a CI test -- score normalized to 10
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configno
has_precommit_configno

Documentation

90Excellent
How it's scored
30/30README
25/25Documentation directory
15/15Documentation / homepage site — https://www.npmjs.com/package/code-pact
10/10Repository description
10/10Topics — 12 topics
0/10Wiki
Inputs used
topicsagent, ai, claude, cli, codex, design, spec-driven, ai-agents, claude-code, cursor, developer-tools, gemini-cli
has_wikino
homepagehttps://www.npmjs.com/package/code-pact
has_readmeyes
has_docs_diryes
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

59Moderate · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — no data
2.5/2.5CI-Tests — 27 out of 27 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
0/5Packaging — no data
5/5Pinned-Dependencies — all dependencies are pinned
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
7.5/7.5Token-Permissions — GitHub workflow tokens follow principle of least privilege
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate5.9
Excluded from scoring (no data or not applicable): branch_protection, packaging. Remaining weights renormalized.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

60Moderate · 0% of overall
How it's scored
0/45Agent instructions — no CLAUDE.md / AGENTS.md / editor rules
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 98 of 99 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share0.99
agent_instruction_files
agent_instruction_max_bytes
How it's scored
0/18One-command bootstrap
22/22Automated tests
0/11Lint / format config
11/11Static type checking — tsconfig.json
10/10Reproducible environment — lockfile
0/10Demonstrated agent practice — no agent-authored commits among the last 100
8/8Automated maintenance — 1 of the last 100 commits are automated dependency updates
10/10OpenSSF Scorecard: Pinned-Dependencies — all dependencies are pinned
Inputs used
has_nixno
has_testsyes
lockfilespnpm-lock.yaml
has_dockerfileno
typed_languageyes
bootstrap_files
has_devcontainerno
has_linter_configno
typecheck_configstsconfig.json
agent_commit_share0
toolchain_manifests
dependency_bot_commit_share0.01
How it's scored
45/45Type-checkable code — TypeScript (statically typed)
54.2/55Manageable file sizes — 9/617 source files over 60KB
Inputs used
primary_languageTypeScript
largest_source_bytes80,712
source_files_sampled617
oversized_source_files9

Key facts

1GitHub stars
1contributors
532commits, last 12 months
0days since last push
62releases
1bus factor
1open issues
npmpackage ecosystems

Data collection warnings

  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository
  • deps.dev does not index npm:code-pact@2.7.0; advisories assessed against the repository dependency graph instead

More detail

Star and fork history 1 ★ / 1 ⇿
1Stars
1Forks
33Releases

When each star and fork was added, collected from GitHub and bucketed by day. Cumulative growth sits directly above the daily additions it is made of, so the two read against each other: steady organic accretion looks nothing like an abrupt, short-lived burst. Where that difference is measurable, it is reported as growth authenticity.

0001111112026-052026-052026-06
Major 0Minor 26Patch 7
OpenSSF Scorecard 5.9 / 10
5.9aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-21 23:06 UTC

10Binary-Artifactsno binaries found in the repo
n/aBranch-Protectioninternal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
10CI-Tests27 out of 27 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
n/aPackagingpackaging workflow not detected
10Pinned-Dependenciesall dependencies are pinned
0SASTSAST tool is not run on all commits -- score normalized to 0
10Security-Policysecurity policy file detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
10Token-PermissionsGitHub workflow tokens follow principle of least privilege
10Vulnerabilities0 existing vulnerabilities detected
Direct dependencies 2
RegistryPackageVersion constraintManifest
npmyaml^2.9.0package.json
npmzod^4.4.3package.json
All dependencies not collected

The resolved dependency set could not be collected for this report: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [
        "agent",
        "ai",
        "claude",
        "cli",
        "codex",
        "design",
        "spec-driven",
        "ai-agents",
        "claude-code",
        "cursor",
        "developer-tools",
        "gemini-cli"
      ],
      "is_fork": false,
      "size_kb": 5800,
      "has_wiki": false,
      "homepage": "https://www.npmjs.com/package/code-pact",
      "languages": {
        "Shell": 37,
        "JavaScript": 349539,
        "TypeScript": 6080944
      },
      "pushed_at": "2026-07-21T14:28:09Z",
      "created_at": "2026-05-15T09:40:01Z",
      "owner_type": "User",
      "updated_at": "2026-07-21T14:31:52Z",
      "description": "Vendor-neutral control plane for AI coding agents. Deterministic CLI surface for context fetch, verify, and progress. Stable in v1.0 for claude-code / codex / generic; cursor / gemini-cli experimental.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": null,
      "name": "Pocket",
      "type": "User",
      "login": "toshtag",
      "company": null,
      "location": "Japan",
      "followers": 3,
      "avatar_url": "https://avatars.githubusercontent.com/u/119549809?v=4",
      "created_at": "2022-12-01T01:31:46Z",
      "is_verified": null,
      "public_repos": 6,
      "account_age_days": 1328
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "P80-T2-evidence",
          "kind": "other",
          "published_at": "2026-07-21T08:35:37Z"
        },
        {
          "tag": "v2.7.0",
          "kind": "minor",
          "published_at": "2026-07-17T05:26:56Z"
        },
        {
          "tag": "v2.6.0",
          "kind": "minor",
          "published_at": "2026-07-14T10:13:25Z"
        },
        {
          "tag": "v2.5.0",
          "kind": "minor",
          "published_at": "2026-07-14T07:56:09Z"
        },
        {
          "tag": "v2.4.0",
          "kind": "minor",
          "published_at": "2026-07-14T02:43:23Z"
        },
        {
          "tag": "v2.3.0",
          "kind": "minor",
          "published_at": "2026-07-13T14:14:50Z"
        },
        {
          "tag": "v2.2.0",
          "kind": "minor",
          "published_at": "2026-07-13T08:55:55Z"
        },
        {
          "tag": "v2.1.0",
          "kind": "minor",
          "published_at": "2026-07-11T13:27:10Z"
        },
        {
          "tag": "v2.0.1",
          "kind": "patch",
          "published_at": "2026-07-10T10:38:10Z"
        },
        {
          "tag": "v2.0.0",
          "kind": "major",
          "published_at": "2026-06-18T14:00:15Z"
        },
        {
          "tag": "v1.32.0",
          "kind": "minor",
          "published_at": "2026-06-05T12:51:25Z"
        },
        {
          "tag": "v1.31.0",
          "kind": "minor",
          "published_at": "2026-06-04T08:11:57Z"
        },
        {
          "tag": "v1.30.1",
          "kind": "patch",
          "published_at": "2026-06-03T09:04:09Z"
        },
        {
          "tag": "v1.30.0",
          "kind": "minor",
          "published_at": "2026-06-03T08:00:38Z"
        },
        {
          "tag": "v1.29.2",
          "kind": "patch",
          "published_at": "2026-06-02T13:54:35Z"
        },
        {
          "tag": "v1.29.1",
          "kind": "patch",
          "published_at": "2026-06-02T12:24:05Z"
        },
        {
          "tag": "v1.29.0",
          "kind": "minor",
          "published_at": "2026-06-02T05:50:46Z"
        },
        {
          "tag": "v1.28.0",
          "kind": "minor",
          "published_at": "2026-06-02T01:26:47Z"
        },
        {
          "tag": "v1.26.0",
          "kind": "minor",
          "published_at": "2026-05-30T06:59:21Z"
        },
        {
          "tag": "v1.25.0",
          "kind": "minor",
          "published_at": "2026-05-28T07:27:05Z"
        },
        {
          "tag": "v1.24.0",
          "kind": "minor",
          "published_at": "2026-05-28T05:06:55Z"
        },
        {
          "tag": "v1.23.0",
          "kind": "minor",
          "published_at": "2026-05-28T04:16:33Z"
        },
        {
          "tag": "v1.22.0",
          "kind": "minor",
          "published_at": "2026-05-28T02:39:55Z"
        },
        {
          "tag": "v1.21.0",
          "kind": "minor",
          "published_at": "2026-05-28T01:44:12Z"
        },
        {
          "tag": "v1.20.0",
          "kind": "minor",
          "published_at": "2026-05-27T14:15:36Z"
        },
        {
          "tag": "v1.19.0",
          "kind": "minor",
          "published_at": "2026-05-27T07:32:06Z"
        },
        {
          "tag": "v1.18.0",
          "kind": "minor",
          "published_at": "2026-05-26T10:28:36Z"
        },
        {
          "tag": "v1.17.1",
          "kind": "patch",
          "published_at": "2026-05-25T14:32:40Z"
        },
        {
          "tag": "v1.17.0",
          "kind": "minor",
          "published_at": "2026-05-25T13:49:36Z"
        },
        {
          "tag": "v1.16.0",
          "kind": "minor",
          "published_at": "2026-05-25T07:39:13Z"
        },
        {
          "tag": "v1.15.0",
          "kind": "minor",
          "published_at": "2026-05-24T13:02:28Z"
        },
        {
          "tag": "v1.14.0",
          "kind": "minor",
          "published_at": "2026-05-24T08:37:01Z"
        },
        {
          "tag": "v1.13.3",
          "kind": "patch",
          "published_at": "2026-05-23T15:41:54Z"
        },
        {
          "tag": "v1.13.2",
          "kind": "patch",
          "published_at": "2026-05-23T13:05:30Z"
        },
        {
          "tag": "v1.13.1",
          "kind": "patch",
          "published_at": "2026-05-23T10:52:18Z"
        },
        {
          "tag": "v1.13.0",
          "kind": "minor",
          "published_at": "2026-05-23T09:19:51Z"
        },
        {
          "tag": "v1.12.0",
          "kind": "minor",
          "published_at": "2026-05-23T07:56:10Z"
        },
        {
          "tag": "v1.11.0",
          "kind": "minor",
          "published_at": "2026-05-22T15:04:58Z"
        },
        {
          "tag": "v1.10.1",
          "kind": "patch",
          "published_at": "2026-05-22T10:12:10Z"
        },
        {
          "tag": "v1.10.0",
          "kind": "minor",
          "published_at": "2026-05-22T09:16:46Z"
        },
        {
          "tag": "v1.9.0",
          "kind": "minor",
          "published_at": "2026-05-22T08:09:45Z"
        },
        {
          "tag": "v1.8.0",
          "kind": "minor",
          "published_at": "2026-05-22T07:04:32Z"
        },
        {
          "tag": "v1.7.0",
          "kind": "minor",
          "published_at": "2026-05-22T04:56:24Z"
        },
        {
          "tag": "v1.6.0",
          "kind": "minor",
          "published_at": "2026-05-22T02:16:34Z"
        },
        {
          "tag": "v1.5.1",
          "kind": "patch",
          "published_at": "2026-05-21T07:36:35Z"
        },
        {
          "tag": "v1.5.0",
          "kind": "minor",
          "published_at": "2026-05-21T06:24:53Z"
        },
        {
          "tag": "v1.4.0",
          "kind": "minor",
          "published_at": "2026-05-20T23:46:55Z"
        },
        {
          "tag": "v1.3.0",
          "kind": "minor",
          "published_at": "2026-05-20T13:12:17Z"
        },
        {
          "tag": "v1.2.0",
          "kind": "minor",
          "published_at": "2026-05-20T09:25:13Z"
        },
        {
          "tag": "v1.1.0",
          "kind": "minor",
          "published_at": "2026-05-20T06:58:52Z"
        },
        {
          "tag": "v1.0.2",
          "kind": "patch",
          "published_at": "2026-05-20T04:55:24Z"
        },
        {
          "tag": "v1.0.1",
          "kind": "patch",
          "published_at": "2026-05-19T11:07:27Z"
        },
        {
          "tag": "v1.0.0",
          "kind": "major",
          "published_at": "2026-05-19T08:49:34Z"
        },
        {
          "tag": "v0.9.0-alpha.0",
          "kind": "prerelease",
          "published_at": "2026-05-19T05:21:38Z"
        },
        {
          "tag": "v0.8.0-alpha.0",
          "kind": "prerelease",
          "published_at": "2026-05-19T01:11:40Z"
        },
        {
          "tag": "v0.7.0-alpha.0",
          "kind": "prerelease",
          "published_at": "2026-05-18T22:49:34Z"
        },
        {
          "tag": "v0.6.0-alpha.0",
          "kind": "prerelease",
          "published_at": "2026-05-18T09:37:45Z"
        },
        {
          "tag": "v0.5.0-alpha.0",
          "kind": "prerelease",
          "published_at": "2026-05-18T05:54:43Z"
        },
        {
          "tag": "v0.4.0-alpha.0",
          "kind": "prerelease",
          "published_at": "2026-05-17T15:23:30Z"
        },
        {
          "tag": "v0.3.0-alpha.0",
          "kind": "prerelease",
          "published_at": "2026-05-17T11:00:00Z"
        },
        {
          "tag": "v0.2.0-alpha.0",
          "kind": "prerelease",
          "published_at": "2026-05-17T07:58:02Z"
        },
        {
          "tag": "v0.1.0-alpha.0",
          "kind": "prerelease",
          "published_at": "2026-05-16T16:16:42Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "509af64900017a06e58fb3ffef90f1f38f5eda30",
          "body": "* P81: register Lifecycle-Aware Review Evidence phase and P81-T1 task\n\n* P81-T1: update declared writes to cover all touched files\n\n* P81-T1: implement lifecycle-aware review evidence classifier\n\n* P81-T1: record done event and contract lock\n\n* P81-T1: closeout phase\n\n* P81-T1: recompute write_audit\n[…]\ny in classifier unit tests for CI\n\n* P81-T2: register task in phase YAML\n\n* P81-T2: implement own-phase boundary and record progress events\n\n* P81-T2: finalize task\n\n* P81: closeout phase after P81-T2",
          "is_bot": false,
          "headline": "P81-T2: own-phase lifecycle boundary closeout (#545)",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-21T14:28:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1447d8988ff312933d38eae9567dc4db8563071b",
          "body": "* plan: register P80-T2 qualified one-pair trial\n\n* P80-T2: remove historical P80-T1 dependency to enable task lock\n\n* P80-T2: complete qualified one-pair effectiveness trial\n\n* P80-T2: update lock phase_blob_sha after finalize\n\n* P80-T1: record historical trial closeout and update archive SHA\n\n* P8\n[…]\n\n\n* P80-T2E: make trial evidence authenticity verifiable\n\n* P80-T2F: register negative-verifier authenticity closeout\n\n* P80-T2F: close negative-verifier authenticity\n\n* P80-T2F: finalize phase status",
          "is_bot": false,
          "headline": "P80-T2: qualified one-pair effectiveness trial (#542)",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-21T12:10:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9e580485602d2300bae6064e1a0a085cc5aa939e",
          "body": "* P80-T1: record one-pair post-P79 effectiveness trial\n\n* P80-T1: correct one-pair classification and evidence status",
          "is_bot": false,
          "headline": "docs: decide P80-T1 one-pair effectiveness trial (#541)",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-21T06:19:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f3b46e39aca02c3612c1b3a1283f734e8d191f89",
          "body": "Bumps the github-actions group with 1 update: [actions/setup-node](https://github.com/actions/setup-node).\n\nUpdates `actions/setup-node` from 6.4.0 to 7.0.0\n- [Release notes](https://github.com/actions/setup-node/releases)\n- [Commits](https://github.com/actions/setup-node/compare/48b55a011bda9f5d6ae\n[…]\n\n  dependency-version: 7.0.0\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n  dependency-group: github-actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/setup-node in the github-actions group",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-21T03:36:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f40228df30c500f8042aaaf13ab28a25c7bf38f4",
          "body": "* P78-T1: add single-file execution eligibility and exact edit\n\n* P78-T2: one-shot executor engine and lifecycle integration\n\n* P78-T3: experimental CLI and public documentation for one-shot execution\n\n* P78-T3: register task execute error codes in KNOWN_CODES, contract docs, and troubleshooting\n\n* \n[…]\nh verification evidence\n\n* P79-T5: finalize task\n\n* P79-T5: reconcile phase to done\n\n* P79-T5: add cli-contract docs, test coverage, and verify verification_ref format\n\n* P79-T5: regenerate doc blocks",
          "is_bot": false,
          "headline": "P78: one-shot single-file execution (#539)",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-21T03:31:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "aa94f6858f273679e421da0f853db3cb7228d973",
          "body": null,
          "is_bot": false,
          "headline": "Minimize the default Agent work order and align all contract consumers",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-18T14:15:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7ff7c0340eff9f70b5678fec770c0ae6e2525895",
          "body": null,
          "is_bot": false,
          "headline": "chore: add GitHub Sponsors funding link (#535)",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-17T12:54:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ad1abf7b8f6cf5b9c620722b4e5c517cff77411b",
          "body": "* chore(release): prepare v2.7.0\n\n* chore(release): complete v2.7.0 archive hygiene\n\n* chore(release): compact archived progress events\n\n* fix(scripts): read done events from archived event packs\n\n* fix(scripts): checkpoint-aware development-efficiency check\\n\\n- Add scripts/development-efficiency-c\n[…]\n unknown done\\n  task failure, invalid checkpoint, and prospective checks.\\n- Update docs/maintainers/token-efficient-development.md with checkpoint usage\\n  and operational requirements.\\n\\nRefs #533",
          "is_bot": false,
          "headline": "chore(release): prepare v2.7.0",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-17T05:15:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b2d044c4b583e446a644afc716be565d90734fac",
          "body": "* docs(decision): evaluate stable core task delta\n\n* fix(plan): finalize P55 decision lifecycle",
          "is_bot": false,
          "headline": "docs(decision): defer stable core task delta",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-17T00:44:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5f100c88b17f582108e2f806a57978a6c9492bb0",
          "body": null,
          "is_bot": false,
          "headline": "fix(plan): remove P66 dependency cycle (#531)",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-16T14:32:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a30c6d28c8ec244ef483c8a84e3ccaf3246c77b2",
          "body": null,
          "is_bot": false,
          "headline": "test(harness): add closed token-efficiency scenarios (#530)",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-16T13:42:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "43d850105dc0d0cc0f48c01b9c7c6d19ee1128a1",
          "body": "… fixes\n\nThis reverts commit 17f3ceb3d9d07068eea5586301c70ed40d55ae1e, reversing\nchanges made to e1cbe3fdda79acbec512926523a1161c10932a0a.",
          "is_bot": false,
          "headline": "P63: exact-match local failure recall and development-efficiency gate…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-16T12:16:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b42be37c26a07d046e999e167315b1c8ddf3dd48",
          "body": "* docs(memory): accept local loop memory contract\n\n* feat(memory): add bounded loop episode store\n\n* feat(memory): record task complete episodes\n\n* feat(memory): add loop memory CLI and doctor checks\n\n* chore(design): mark loop memory phase done\n\n* fix(memory): harden local episode identity\n\n* fix(m\n[…]\nfix(memory): complete corrupt entry accounting\n\n* fix(memory): report exact prune outcomes\n\n* docs(memory): reconcile prune accounting contract\n\n* chore(design): mark loop memory accounting phase done",
          "is_bot": false,
          "headline": "Add bounded local loop memory (#526)",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-15T05:27:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7f68dadde2fbd79436d7080e811f72afdf111528",
          "body": "* chore(release): prepare 2.6.0\n\n* chore(design): archive P57 phase\n\n* chore(state): compact P57 event history",
          "is_bot": false,
          "headline": "Release 2.6.0 (#525)",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-14T10:02:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b9f0fbbf3c227d51618717b6c4d10858a5b9189b",
          "body": "* docs(plan): define regression evidence contract\n\n* feat(plan): advise missing bugfix regression evidence\n\n* test(process): stabilize process tree timeout\n\n* docs(plan): document regression evidence examples\n\n* chore(design): mark P57 done\n\n* chore(design): add P57 follow-up task\n\n* fix(plan): require concrete regression artifacts\n\n* chore(design): mark P57 follow-up done",
          "is_bot": false,
          "headline": "feat(plan): advise missing bugfix regression evidence (#524)",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-14T09:22:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fc04622b9d2a4a8f7b4322c034604c685d0d0659",
          "body": "* chore(release): prepare 2.5.0\n\n* chore(design): archive p54 phase\n\n* chore(state): compact P54 release history\n\n* chore(state): compact P54 event history",
          "is_bot": false,
          "headline": "Release 2.5.0 (#523)",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-14T07:44:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e02ac08f1da3b15a086bae9105cb1fbe624545e2",
          "body": "* docs(context): define structural projection contract\n\n* feat(context): project read globs by directory\n\n* feat(context): project decision commitments\n\n* test(context): add projection fixtures\n\n* chore(plan): mark structural projection done\n\n* chore(plan): clean projection task writes\n\n* chore(plan\n[…]\normance output followup\n\n* fix(adapter): complete projection conformance output\n\n* docs(adapter): document projection conformance output\n\n* chore(plan): finalize projection conformance output followup",
          "is_bot": false,
          "headline": "Structural context projection (#522)",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-14T07:02:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "afde4a5c65722cfb86bc041f36162638a26a5a88",
          "body": "* chore(release): prepare 2.4.0\n\n* chore(release): finalize v2.4.0 state\n\n* chore(release): compact legacy event state",
          "is_bot": false,
          "headline": "Prepare 2.4.0 release (#521)",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-14T02:32:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c745290f1e74163fe0eb7f505eb5baca60e905e4",
          "body": "* feat(context): apply recommended context budgets\n\n* feat(context): support recommended budget profiles\n\n* docs(context): document recommended budget application\n\n* chore(plan): mark P53 done\n\n* chore(plan): tighten P53 write surfaces\n\n* chore(plan): add P53 corrective task\n\n* fix(context): close recommended budget contract gaps\n\n* chore(plan): add P53 closure task\n\n* fix(context): keep validation cleanup scoped",
          "is_bot": false,
          "headline": "Add recommended context budget application (#520)",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-14T01:38:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7bafee0e21aaa6b851199c79fad7c84a5c8dfa2d",
          "body": "* chore(release): prepare 2.3.0\n\n* chore(design): archive p52 phase\n\n* chore(state): compact P52 release history",
          "is_bot": false,
          "headline": "Prepare 2.3.0 release (#519)",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-13T14:03:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d8fbe0d3c15f80121cc22537d65dd039012606c9",
          "body": "* docs(context): specify reversible deferral contract\n\n* feat(context): add reversible deferral core\n\n* feat(context): add context show retrieval\n\n* docs(context): document deferred retrieval flow\n\n* chore(context): mark p52 complete\n\n* fix(context): enforce deferred write invariants\n\n* fix(context): close missing readback mapping",
          "is_bot": false,
          "headline": "Add reversible context deferral (#518)",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-13T13:21:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c0feafdb96b755981ba018e6118061b0efd1d7c8",
          "body": "* chore: prepare 2.2.0 release\n\n* chore: archive completed P51 phase\n\n* docs: clarify agent-detail evidence fixture wording",
          "is_bot": false,
          "headline": "Prepare 2.2.0 release (#517)",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-13T08:39:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a5295f77ff2ee918063b34a55769ca79c0eede3f",
          "body": "* docs: define bounded repair contract\n\n* feat: add bounded repair policy recommendation\n\n* feat: teach adapters bounded repair guidance\n\n* docs: document bounded repair loop\n\n* chore: mark p51 phase done\n\n* chore: keep p51 writes lint-clean\n\n* fix: correct repair policy guidance paths\n\n* fix: gate bounded repair adapter checks\n\n* docs: close p51 conformance contract gaps",
          "is_bot": false,
          "headline": "Add bounded repair recommendation contract (#516)",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-13T07:33:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2ebe6ea3193cc58fc4a56f4a9e9c8fbcb5fa9f6f",
          "body": "* Add bounded repair roadmap phase\n\n* Add reversible context budget roadmap phases\n\n* Add failure learning roadmap phases\n\n* Remediate bounded repair roadmap\n\n* Tighten context roadmap contracts\n\n* Resolve context roadmap review gaps\n\n* Refine roadmap execution gates\n\n* Clarify context artifact contracts\n\n* Pin context materialization semantics\n\n* Close context roadmap traceability gaps\n\n* Tighten roadmap verification closure\n\n* Add recommended budget acceptance evidence",
          "is_bot": false,
          "headline": "Add bounded repair and context roadmap phases (#515)",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-13T05:40:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0db5153aa616017cf9a75fab57828b252dc4432e",
          "body": "* chore(toolchain): align pnpm version checks\n\n* chore(ci): dedupe local Vitest scopes",
          "is_bot": false,
          "headline": "chore(ci): dedupe local Vitest scopes (#514)",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-12T23:30:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c35f0b6e1d0a7eb246e1ac5254b9ab0669f00da8",
          "body": "* feat(scripts): add change-aware verification-scope classifier and tests\n\n* feat(ci): split package scripts into verify:base/smoke/deep:extra and update CI workflows\n\n* docs(contributing): update docs, PR template, and pre-push example for change-aware verification\n\n* chore(ci): align verification \n[…]\nfake git portable\n\n* fix(verify:local): preserve partial git scope\n\n* fix(ci): use trusted classifier from base\n\n* fix(verify:local): include working tree changes\n\n* fix(ci): harden deep status checks",
          "is_bot": false,
          "headline": "chore(ci): make verification change-aware (#513)",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-12T13:53:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f362b1533592da8a9e873d5b52017c90930f4ee4",
          "body": "* chore(deps): upgrade Vite to 8\n\n* docs(readme): clarify Node.js version requirements for contributors",
          "is_bot": false,
          "headline": "chore(deps): upgrade Vite to 8 (#512)",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-12T08:57:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b707ccc246f5c7a61ad743b9c311ac5de1f8bd64",
          "body": "* chore: declare root pnpm workspace\n\n* chore(deps): update typescript toolchain\n\n* chore(deps): bridge TypeScript compiler API\n\n* chore(deps): update Vitest patch range\n\n* chore(test): finish dependency update alignment\n\n* test: keep history noise out of unit gate",
          "is_bot": false,
          "headline": "chore(deps): update TypeScript toolchain (#511)",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-12T07:28:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4b0f51f534be62b44ca0d9cfd83b8e3c60e85f02",
          "body": "* chore(release): avoid duplicate release build\n\n* ci(publish): bound release jobs and artifact retention\n\n* test(release): verify release check build chain\n\n* test(release): require fail-fast release chains\n\n* test(release): require exact release commands",
          "is_bot": false,
          "headline": "Lean npm publish workflow (#510)",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-12T02:53:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1ac1cd8f2a4d4986446f8b499b214d098ef49176",
          "body": "* docs: fold community guidance into contributing\n\n* chore: simplify pull request template\n\n* docs: remove stale agent feedback note",
          "is_bot": false,
          "headline": "Reduce repository maintenance surface (#509)",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-11T14:36:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ce99ad72963fcbe336d03e2caef3e1c072d3e766",
          "body": "* chore: retire generic evidence harness\n\n* chore: separate agent detail evidence\n\n* docs: remove harness release coupling\n\n* docs: address harness retirement review",
          "is_bot": false,
          "headline": "Retire generic evidence harness (#508)",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-11T14:09:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "388795582497b1bd268103df4490162766737e88",
          "body": null,
          "is_bot": false,
          "headline": "fix(release): publish local tarball path",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-11T13:02:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c371e82a9c0a93bed731e5229ab01e7394301a26",
          "body": "* chore(release): prepare 2.1.0\n\n* chore(release): finish 2.1.0 prep",
          "is_bot": false,
          "headline": "chore(release): prepare 2.1.0 (#506)",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-11T09:55:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5845c56dfcfecbc94e06d38760f3fd855fe7b6be",
          "body": "* feat(evidence): add reversible failure capsules\n\n* feat(cli): expose agent detail evidence retrieval\n\n* docs(agent): document compact evidence flow\n\n* fix(evidence): bound agent detail capsules\n\n* fix(cli): tighten evidence detail contracts\n\n* fix(evidence): bound final agent envelopes\n\n* test(evi\n[…]\nfingerprints\n\n* docs(agent): clarify detail cause guidance\n\n* docs(agent): cover invalid state guidance\n\n* fix(evidence): respect custom URI schemes\n\n* fix(evidence): avoid single slash URI collisions",
          "is_bot": false,
          "headline": "Add compact agent evidence envelopes (#505)",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-11T08:58:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9f87e6f5c367f720818238270ced8ea3861827cb",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): prepare 2.0.1 (#504)",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-10T10:24:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e28b0414e2bef3c36cf4e27effe3b548905ba057",
          "body": "* docs(cli): clarify generated spec import ownership\n\n* test(cli): pin plan and phase subcommand guidance\n\n* docs(cli): address post-migration review notes\n\n* docs(cli): split generated reference pointers\n\n* docs(cli): polish remaining reference wording\n\n* docs(ci): clarify CLI reference ownership",
          "is_bot": false,
          "headline": "Clean up post-CommandSpec docs drift (#503)",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-10T06:01:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0afc41ae519d885cc5024bce4566ac1a59f796bf",
          "body": "* feat(cli): single-source spec command specs\n\n* docs(cli): route spec usage through generated reference\n\n* test(cli): cover spec specs and state guidance",
          "is_bot": false,
          "headline": "Single-source spec command specs (#502)",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-10T04:48:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0e73796d9d9581ce36df25703b5ad7433dea52e9",
          "body": "* feat(cli): single-source state command specs\n\n* docs(cli): route state usage through generated reference\n\n* test(cli): cover state command spec surfaces\n\n* fix(cli): derive decision unknown guidance from specs",
          "is_bot": false,
          "headline": "Single-source state command specs (#501)",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-10T04:22:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5e76c01602db2716a50c7aee4afef380dffc2de5",
          "body": "* feat(cli): single-source decision command specs\n\n* docs(cli): generate decision reference\n\n* test(cli): cover decision generated help",
          "is_bot": false,
          "headline": "Single-source decision command specs (#500)",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-09T14:13:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7556f4f1a5a97267e5112029657c93f660e22664",
          "body": "* feat(cli): single-source adapter command specs\n\n* docs(cli): generate adapter reference\n\n* test(cli): cover adapter generated help\n\n* fix(cli): derive adapter subcommand lists from specs",
          "is_bot": false,
          "headline": "Single-source adapter command specs (#499)",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-09T13:38:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "927b818a0aafa5fcafebf0f040bef25451110143",
          "body": "* feat(cli): single-source phase command specs\n\n* docs(cli): generate phase reference sections\n\n* test(cli): cover phase generated help\n\n* fix(cli): show rich help for phase next",
          "is_bot": false,
          "headline": "Single-source phase command specs (#498)",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-09T11:39:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8048d4ec045173ed0533af29d756b61d03b1194c",
          "body": "* feat(cli): single-source plan command specs\n\n* docs(cli): generate plan command reference\n\n* docs: clarify plan command ownership\n\n* test(cli): cover plan CommandSpec help",
          "is_bot": false,
          "headline": "Single-source plan command specs (#497)",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-09T11:00:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6c477f456c0d98491ec06d55cf085e77107e29d5",
          "body": "* ci: split required and deep gates\n\n* test: enforce tiered ci invariants\n\n* docs: document fast and deep ci gates\n\n* ci: shrink required smoke coverage\n\n* ci: share deep init smoke gate\n\n* test: guard tiered ci policy\n\n* docs: update docs gate wording",
          "is_bot": false,
          "headline": "ci: reduce required CI time (#496)",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-08T13:46:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5b08b6e2378113a8b19a7fa99394920f171644ad",
          "body": "* fix(adapter): prune safe dynamic handoff orphans\n\n* fix(adapter): surface dynamic handoff drift\n\n* fix(adapter): report dynamic handoff conformance drift\n\n* fix(adapter): lazy-load conformance desired hashes\n\n* docs(adapter): document dynamic handoff advisories",
          "is_bot": false,
          "headline": "fix(adapter): prune safe dynamic handoff orphans (#495)",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-08T12:49:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2699b9ed89c6dc8bc9a7a8462bc7952a69d83ede",
          "body": null,
          "is_bot": false,
          "headline": "fix(security): harden adapter doctor reads (#494)",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-08T07:36:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b3fa50d6f3a899aa21dd676f2da5f844a97cda0e",
          "body": "* chore(deps): update github actions\n\n* test: update supply-chain action pins",
          "is_bot": false,
          "headline": "chore(deps): bump the github-actions group with 4 updates (#493)",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-08T07:18:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f52d3e6a7b1964766fcc21c7d2761ef76b6b2b79",
          "body": "…ygiene (#492)\n\n* fix(deps): upgrade vite to 6.4.3 and pin esbuild >=0.28.1 (WP-01)\n\nFixes:\n- GHSA-fx2h-pf6j-xcff (vite, high) — upgrade vite ^6.4.2 → ^6.4.3\n- GHSA-v6wh-96g9-6wx3 (vite/launch-editor, moderate)\n- GHSA-g7r4-m6w7-qqqr (esbuild, low) — pnpm override >=0.28.1\n\nAudit result: 0 known vuln\n[…]\n\n\n* fix: restore fail-closed no-follow reads\n\n* fix: deflake Windows cancellation coverage\n\n* fix: keep Windows process tests off project reads\n\n* fix: avoid Windows CLI project reads in timeout tests",
          "is_bot": false,
          "headline": "fix(security): dependency CVE fixes, bounded verify execution, test h…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-08T06:56:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f4b14d6dcfc7dada318e413d0675d9fd609fe15c",
          "body": "* ci: pin GitHub Actions to full commit SHAs and add Dependabot\n\n- Pin actions/checkout, pnpm/action-setup, actions/setup-node to\n  40-character commit SHAs in ci.yml\n- Add top-level permissions: contents: read\n- Add persist-credentials: false to all checkout steps\n- Create .github/dependabot.yml fo\n[…]\nlaining why setup-node must not use registry-url\n(generates empty NODE_AUTH_TOKEN .npmrc that blocks OIDC) and why\nnpm view/publish use --registry CLI flag (prevents\nNPM_CONFIG_REGISTRY env override).",
          "is_bot": false,
          "headline": "Harden npm release supply chain (#490)",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-03T08:05:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "32eb4ed4dfb3c6341d169bb507877559048cca88",
          "body": "…#488)\n\n* fix(security): harden context, dry-run, manifest, and glob handling\n\nAddress the Codex security review (scan bd84281). Each fix adds attacker-\nscenario regression tests; behavior changes are documented in CHANGELOG +\ncli-contract.\n\n- Context pack: loadConstitution reads via resolveWithinPr\n[…]\nged transactions\n\n* chore(security): make filesystem authority checks capability-aware\n\n* refactor(security): add typed project filesystem wrappers\n\n* fix(adapter): formalize dynamic file ownership h…",
          "is_bot": false,
          "headline": "fix(security): harden context, dry-run, manifest, and glob handling (…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-07-02T13:15:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bd8428102b45c4f09177f3aee119176a2c72319d",
          "body": "…test (#486)\n\n`--check` is not a real harness option — read-only is the default (no `--write`)\nrun. The v2.0.0 release-prep pass corrected this everywhere (run.ts comment, docs)\nexcept the integration test's describe name + a header comment. This finishes that\ncleanup: \"default --check\" → \"default read-only mode\". No behavior change; the only\nremaining `harness ... --check` mentions are in the archived CHANGELOG history, which\nis verbatim point-in-time content and intentionally left as-is.",
          "is_bot": false,
          "headline": "test(harness): drop the stale \"--check\" wording from the integration …",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-18T13:53:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eb1228308b5632aea006715b98bcb5273d70e017",
          "body": "…485)\n\n* chore(decisions): retire 41 shipped ADRs into the archive bundle (v2.0.0 dogfood cleanup)\n\nDogfoods the v2.0.0 design-doc-deletion + bounded-archive flow on this repo's OWN\ndecision corpus, demonstrating the milestone end-to-end:\n\n- `decision retire --write` on every ACCEPTED + eligible dec\n[…]\non, build, check:docs\n[7 checks], check:release-version, validate, plan lint --strict, plan analyze --strict).\nThe clickable-link checker now covers every GitHub-rendered surface check-doc-links does.",
          "is_bot": false,
          "headline": "Release v2.0.0 — bounded archive maintenance + dogfood ADR cleanup (#…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-18T13:43:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8d7a048f92c44eb9eb29b46f240f0748ca64dd47",
          "body": "… to keep the archive bounded (v2.0 UX/DX) (#484)\n\n* feat(archive-maintain): add `state archive-maintain` — one honest command to keep the archive bounded (v2.0 UX/DX)\n\n`state archive-maintain [--keep-latest N] [--write] [--json]` is the high-level\noperator entry that orchestrates the existing archi\n[…]\nommits / internal recovery\" is on a\ncached anonymous render.\n\nFull suite green: typecheck, unit (3403), integration (43 files / 656), check:docs,\nvalidate, plan lint. Dogfooded (no .code-pact change).",
          "is_bot": false,
          "headline": "feat(archive-maintain): `state archive-maintain` — one honest command…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-18T09:37:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5d35bef9d0018a0cb17a85e7f5974baa5c0e9046",
          "body": "…mpletion (no logic change) (#483)\n\n* docs(archive-compaction): close the #482 review carryovers — milestone completion (no logic change)\n\nThe final cleanup of the archive-retention milestone (the removal surface is\ncomplete as of #482). Closes the three cheap #482 review carryovers; no production\nl\n[…]\n\ngarbage — the file-clutter problem is solved by compaction here); sharding /\n`archive-maintain` one-shot are NOT added (next milestone). Gate green (typecheck /\nvitest 4033 / check:docs / plan lint).",
          "is_bot": false,
          "headline": "docs(archive-compaction): close #482 review carryovers — milestone co…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-18T03:38:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e8cb4390417fd8ab36d11c395c5854bae0975dd4",
          "body": "…` by intent_kind (#480 P2 carryovers, v2.0 gate) (#482)\n\nThe capstone of the archive-retention milestone — the removal surface is complete\n(loose independent / loose pair / bundle pair / bundle independent all removed,\n`source: both` converges in ≤2 runs), so this PR proves the archive is BOUNDED a\n[…]\nair).\n\nGate green (typecheck / vitest 4045 / check:docs / plan lint). The measured dry-run\non this repo + the v2.0 tag are a release step (the user's call); the fixture here is\nthe reproducible proof.",
          "is_bot": false,
          "headline": "feat(archive-compaction): bounded-archive validation + tag `recovered…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-18T02:48:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a2f53bb1ef419b03f842203844a65050abd1c87c",
          "body": "…ion --write (single-kind Layer-1) (#481)\n\n* feat(archive-compaction): wire INDEPENDENT bundle records into retention --write (single-kind Layer-1) + #480 P2.3 mirror test\n\nRoutes the last unhandled destructive case into `state archive-retention --write`:\nan INDEPENDENT bundle-backed would_drop reco\n[…]\nis `skipped: needs_bundle_member_removal`,\nstill resolves, and appears in EXACTLY ONE terminal bucket). Gate green (typecheck /\nvitest 4041 / check:docs / plan lint). Did not run --write on this repo.",
          "is_bot": false,
          "headline": "feat(archive-compaction): wire INDEPENDENT bundle records into retent…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-18T02:29:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8f55b713affa243f5a53b14082abb140f7518480",
          "body": "…rite (bundle-backed pairs now removed) (#480)\n\n* feat(archive-compaction): wire bundle-pair removal into retention --write (bundle-backed pairs now removed) + #479 P2 carryovers\n\nRoutes the shipped bundle-pair removal (Layer 2) into the live\n`state archive-retention --write` apply: a `would_drop` p\n[…]\nbundle (a recovered bundle pair's loose copy may survive — not a loose delete), and\nstate the mixed-source resolution policy (compact-first vs a mixed journal) in the\nfinal bounded-archive validation.",
          "is_bot": false,
          "headline": "feat(archive-compaction): wire bundle-pair removal into retention --w…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-18T01:56:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "522cbab43c08968183f7be683eb5a1f19ef5b3cd",
          "body": "…oth-or-neither bundle-pair removal (UNWIRED) (#479)\n\n* feat(archive-compaction): bundle-member removal Layer 2 — journaled both-or-neither bundle-pair removal (UNWIRED)\n\nThe crash-safe removal of a phase_snapshot ↔ event_pack BUNDLE pair, committed\nthrough the delete-intent journal (mirroring the s\n[…]\nocumented that a phase_id appears at\nmost once across the whole journal (loose XOR bundle, never both in one run).\n\n17 bundle-pair tests; gate green (typecheck / vitest 4026 / check:docs / plan lint).",
          "is_bot": false,
          "headline": "feat(archive-compaction): bundle-member removal Layer 2 — journaled b…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-18T01:14:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f4e615772735bc98f49a7b9762bc9a55fc57ea8b",
          "body": "…estructive single-kind apply (#478)\n\n* feat(archive-compaction): bundle-member removal Layer 1a — read-only removal planner (+ #477 RFC P2s)\n\nFirst implementation step of the final retention layer (bundle-member removal),\nmirroring how retention split the read-only planner (#472) before the destruc\n[…]\n write and retire → old NOT retired. PR\ntitle/body were already reframed to \"Layer 1: planner + destructive apply\" (the\nreviewer's fetch was stale). Gate green (typecheck / vitest 4009 / docs / lint).",
          "is_bot": false,
          "headline": "feat(archive-compaction): bundle-member removal Layer 1 — planner + d…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-18T00:10:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "98990fffaed7f304bd4d6a2cf32211a0c84cb216",
          "body": "…emoval) + #476 doc carryovers (#477)\n\n* design: bundle-member removal RFC (supersede-by-removal) + fold #476 doc carryovers\n\nThe loose-pair retention layer is wired (#476). The remaining destructive layer is\nbundle-member removal: a would_drop record whose physical home is a BUNDLE (source\nbundle /\n[…]\nd-bytes), proof\n   re-derived from the on-disk new bundle.\n\n5. Invariants + layer-1 tests updated (durable barriers, expected-bytes gate,\n   injected-fsync-failure test).\n\nStill design-only — no code.",
          "is_bot": false,
          "headline": "design(archive-compaction): bundle-member removal RFC (supersede-by-r…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-17T16:30:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "43dc9355ae9a2f10d43e2b59b3cccf4043e5ca51",
          "body": "…nal into --write (pairs now deleted both-or-neither) (#476)\n\n* archive retention — WIRE the loose-pair journal into `state archive-retention --write`\n\nThis flips retention from \"defer every phase_snapshot↔event_pack pair\" to actually\nremoving a loose pair crash-safe via the delete-intent journal. T\n[…]\ne actually-gone kind reports `vanished` and\nthe surviving file is still on disk. A new `beforePairGate` apply hook (distinct from\nthe per-record `beforeGate`) injects the between-plan-and-gate vanish.",
          "is_bot": false,
          "headline": "feat(archive-compaction): retention — wire the loose-pair delete jour…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-17T16:01:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4af3492dbe1b017709292c0166a3675fc623c272",
          "body": "…ding intent = logically absent, unwired) (#475)\n\n* archive retention — reader-awareness: a pending delete-intent hides the pair from every reader\n\nThe delete-intent journal makes a phase_snapshot↔event_pack pair deletion\ncrash-safe, but between a crash and recovery the physical archive can show a\nh\n[…]\nmpaction loose-side-only filter are\nboth correct and complete.\n\nTest: +1 — a pair with a bundle copy is not journaled (needs_bundle_member_removal,\nno commit). RFC notes the invariant is now enforced.",
          "is_bot": false,
          "headline": "feat(archive-compaction): retention pair-delete reader-awareness (pen…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-17T14:57:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2b1c69bad018016beaadd6ccfe4dd38b726dd51e",
          "body": "…ery (foundation, unwired) (#474)\n\n* archive retention — delete-intent journal + crash recovery for a phase↔pack pair (foundation, unwired)\n\nPR-2a defers every phase_snapshot↔event_pack pair (`requires_atomic_pair_removal`)\nbecause the two are mutually bound and a filesystem cannot unlink two files\n\n[…]\nlus the duplicate-id-journal corrupt\nread. A module test seam (__setDeleteIntentDirFsyncForTests) injects the failure.\n\nRFC updated: the fsyncs are REQUIRED barriers with the unsupported/failed split.",
          "is_bot": false,
          "headline": "feat(archive-compaction): retention pair-delete journal + crash recov…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-17T13:22:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "838d1bcb450c268f06c4fb777518b4d01c04c1ab",
          "body": "…delete (PR-2a, gated truth drop) (#473)\n\n* The first layer that actually DROPS old archive truth. Conservative scope:\n`state archive-retention --write` (under the write lock) deletes ONLY loose-only\n`would_drop` records; a bundle-only / `both` would_drop is reported `skipped:\nneeds_bundle_member_re\n[…]\nstill work. docs/cli-contract.md updated for the\nindependent-records-only scope. An independent adversarial review (fresh context,\ntasked to find any pack delete or phase-with-pack delete) found none.",
          "is_bot": false,
          "headline": "feat(archive-compaction): Layer 4 retention — destructive loose-only …",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-17T11:59:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7489ce131cd78dcd08c4ad2a7f12b48241b898c9",
          "body": "…dry-run only, conservative foundation) (#472)\n\n* archive retention — keep-latest-N PLANNER (dry-run only, conservative foundation)\n\nThe non-destructive foundation for the most destructive archive layer: a planner\nthat bounds the archive's UNREFERENCED tail (keep-latest N) and is the DELETE\nAUTHORIT\n[…]\nks\nblocked, 3 decisions → keep 2 / drop 1.\n\nNow ALL inputs are authority-gated: phase ∧ decision ∧ event_pack record bytes, the\nSHADOWED bundle copy of a `both` record, and the store/enumeration view.",
          "is_bot": false,
          "headline": "feat(archive-compaction): Layer 4 retention — keep-latest-N planner (…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-17T02:12:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6bea188c45744a5e9c1af615636b032786a7319f",
          "body": "…471)\n\nTwo non-blocking carryovers from the #470 review of the refresh-after-compaction\nproducer flip:\n\n  - The file-top trust-boundary comments in phase-snapshot.ts and decision-record.ts\n    still described the ExpectedState guard as \"absent for write, exact raw bytes for\n    refresh\" — stale sinc\n[…]\n, rather than clobbers, when a\n    concurrent writer creates a loose at the path between plan and apply — and the\n    concurrent loose is left untouched.\n\nNo behavior change; comments + one test only.",
          "is_bot": false,
          "headline": "tighten the producer materialize contract (#470 review carryovers) (#…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-16T12:25:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7f5ed51aecb080fc2567ba669598baf6898de875",
          "body": "…TERIALIZES (engine ignition) (#470)\n\nReverses the #465 safety refusal now that the supersession compactor exists.\nRefreshing a record whose loose copy was compacted away (a \"bundle-only\" record)\nused to return ineligible compacted_record_refresh_unsupported — because the\nthen-current compactor coul\n[…]\neview's one non-blocking note.\n\nTests: the two bundle-only refresh tests now prove materialize→adopt end-to-end (loose\nwritten → compact supersedes + deletes → bundle authority is the fresher record).",
          "is_bot": false,
          "headline": "archive supersession — flip the producer: refresh-after-compaction MA…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-16T03:11:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4f2b71e81794b369d74c6c853693f97823f1cd05",
          "body": "…ging loose) (#469)\n\nActivates the supersede primitive in the compaction flow. When a loose record\nDIVERGES from its bundle member (a refreshed record), the fresher loose is\nadopted into the bundle (the member replaced in place), then the loose deleted —\nso refresh-after-compaction finally reduces f\n[…]\nR-then-ADOPT across two runs;\nmisnamed-bundle defer; unfoldable-fresh-loose stays bundle_stale; an end-to-end CLI\nintegration case (dry-run would_supersede, --write bundle=superseded + loose deleted).",
          "is_bot": false,
          "headline": "archive supersession — wire it into compaction (adopt a fresher diver…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-15T21:36:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a025161223846688804db5414310b9ddf971eb7f",
          "body": "…set bundle replace primitive (unwired) (#468)\n\n* archive supersession — intentional same-id-set bundle replace primitive (unwired)\n\nFirst piece of the Supersession milestone (user-locked order: rebundling →\nsupersession → retention). A record refreshed AFTER it was compacted leaves a\nfresher loose \n[…]\n non-canonically-named bundle holding the member → refuses the\ncolliding canonical create; and a degrade-to-create that collides with NO bundle still\nSUCCEEDS (the preflight is not over-conservative).",
          "is_bot": false,
          "headline": "feat(archive-compaction): Layer 4 supersession — intentional same-id-…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-15T15:05:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "af04b11736853db90628389faf9871ea36fbde15",
          "body": "…bound the bundle count) (#467)\n\n* feat(archive-compaction): Layer 4 — bundle consolidation/rebundling (bound the bundle count)\n\nThe first Layer-4 BOUND piece: make compactArchive CONSOLIDATE a kind's archive records\ninto ONE bundle and retire the now-superseded smaller bundle files, so repeated com\n[…]\nwrite_bundle conflict in BOTH dry-run and --write; nothing retired/deleted.\n\nDocs: failure-envelope phase list + dry-run honesty note now include\nretire_bundle and the predicted write_bundle conflict.",
          "is_bot": false,
          "headline": "feat(archive-compaction): Layer 4 — bundle consolidation/rebundling (…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-15T13:57:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "27a62e53d453769851079e2ff3e347ee9743be4f",
          "body": "… (run the fold + delete) (#466)\n\n* feat(archive-compaction): Layer 4a — `state compact-archive` CLI verb (run the fold + delete)\n\nThe user-facing entry that makes the whole Layer 1-3 stack runnable: fold loose archive\nrecords of a kind into content-addressed bundles and delete the verified loose co\n[…]\n completed_results/failed_kind/partial_applied\nin the envelope (earlier kind really applied); extra positional → CONFIG_ERROR;\nplanCompactArchive would_bundle/would_delete/would_skip matches the gate.",
          "is_bot": false,
          "headline": "feat(archive-compaction): Layer 4a — `state compact-archive` CLI verb…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-15T12:32:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "895ce9648c953111abf9a79ceae1140a5a1d58d6",
          "body": "…file-count drop) (#465)\n\n* feat(archive-compaction): Layer 3 — gated loose-record deletion (the file-count drop)\n\nThe first DESTRUCTIVE step: remove a loose archive record once a VERIFIED bundle\nholds it byte-identically. With it, compaction finally reduces the archive file\ncount instead of only re\n[…]\nthrow in archive-bundle-writer.ts\" — verified NOT\npresent: the existing-unreadable / different-bundle-conflict / atomic-write-failed throws\nare three distinct, reachable paths with distinct messages.)",
          "is_bot": false,
          "headline": "feat(archive-compaction): Layer 3 — gated loose-record deletion (the …",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-15T11:51:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3b28822a43de1612055ef048b03b0b4e21c58c0e",
          "body": "…(no delete) (#464)\n\nThe first thing that actually FOLDS loose archive records into bundles. Folds N\nloose records of one kind (phase_snapshot / event_pack / decision_record) into one\ncontent-addressed bundles/<kind>-<idsHash16>.json and verifies it reads back\nidentically — WITHOUT deleting the loos\n[…]\nempotent noop; fail-closed conflict;\nkind-genericity (decision_record); absent-dir noop; multi-member sort + member_ids_\nsha256; readback fail-closed (non-JSON / bundle_stale / missing folded member).",
          "is_bot": false,
          "headline": "feat(archive-compaction): Layer 2 — archive-bundle writer + readback …",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-15T08:15:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "255808a3d14b2145eedc04e3a09eb910fdc9fcdf",
          "body": "…g tolerate bundles (#463)\n\n* Closes Layer 1 (every archive reader resolves loose ∪ bundle before any writer\nproduces bundles). The phase-snapshot and decision readers were already wired\n(#460/#462); this wires the remaining event-pack readers.\n\n- event-pack-reader.ts: readEventPackFiles + readEvent\n[…]\n-surfaced (not silent green); loose-present (incl.\ncorrupt-loose) wins over a stale/garbage same-id bundle with no double-count; a\nwrong-internal-phase_id bundle member → invalid, injects no task ids.",
          "is_bot": false,
          "headline": "feat(archive-compaction): Layer 1 final — event-pack readers + bindin…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-15T07:47:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f47e50cdde2789392cd77ebbadc57ed9cd6fbf3a",
          "body": "…r + wire decision resolution (#462)\n\nIntroduce resolveArchiveRecordBytes: the ONE shared loose ∪ bundle resolver every\narchive reader routes through, so the two resolution modes stay identical across\nreaders instead of each re-implementing loose-vs-bundle handling and drifting.\n\n- resolve-archive-r\n[…]\nef → not_released,\nproving bind ≠ full authority).\n\nPosture per archive-level-compaction-rfc.md: gate-release is fail-closed strict;\nlint-soften is fail-soft (a corrupt bundle never crashes the lint).",
          "is_bot": false,
          "headline": "feat(archive-compaction): Layer 1c-ii-c — shared loose∪bundle resolve…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-15T06:49:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "57b3fba0261e6b5ae73dc6358955fe46da60a592",
          "body": "… POSTURE (orthogonal to mode) (#461)\n\nThe RFC's Tier-1/Tier-2 section had only the bare line \"a bundle failing either tier\nis dropped by lenient readers and throws in strict loaders\" — it never said WHICH\nreaders are lenient-drop and WHICH fail closed, so the next reader wiring would have\nto guess \n[…]\n\ndiscovery 4b, plan lint advisories). Same split as step4-archive-reader-invariants\n(4a strict / 4b fail-soft) and the event-pack strict-loader-vs-lenient-surface\nconvention. Doc-only; no code change.",
          "is_bot": false,
          "headline": "docs(archive-compaction): name the lenient-drop vs fail-closed reader…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-15T06:17:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "41e5ab49392f1f27b3fe62336f62728b1e6b16f2",
          "body": "…m loose ∪ bundle (#460)\n\n* feat(archive-compaction): Layer 1c-ii-b — resolve a missing phase from loose ∪ bundle\n\nWire the archive-bundle store into the FIRST reader: resolveMissingPhaseRef,\nwhich decides whether a roadmap-referenced phase whose live YAML is gone may be\ntolerated as an archived ter\n[…]\ns: document reconcileLooseAndBundle as the STRICT-RECONCILE\n  primitive (writer/readback / delete gate / explicit verify), NOT an every-reader\n  primitive; read paths use loose-wins and never call it.",
          "is_bot": false,
          "headline": "feat(archive-compaction): Layer 1c-ii-b — resolve a missing phase fro…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-15T06:04:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f0d376fcbb297c2586fce18a2080e4dfed77d3f4",
          "body": "…+ per-file Tier-1 + index, unwired) (#459)\n\nThe I/O foundation for archive-bundle resolution: read every\n`.code-pact/state/archive/bundles/*.json`, Tier-1-validate EACH file, and\nfold them into the cross-bundle member index built in Layer 1c-i.\n\nFail-closed by construction (heeds the #458 review's \n[…]\nader.ts: loadArchiveBundles(cwd) → { index, bundles }\n- tests: absent-dir, happy-path index, Tier-1-invalid fail-closed (code\n  asserted via captured error), cross-bundle conflict, `.json` subdir skip",
          "is_bot": false,
          "headline": "feat(archive-compaction): Layer 1c-ii-a — bundle-dir loader (readdir …",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-15T05:27:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7e2187a882eb760d326cfa9ee75b42d4a3292059",
          "body": "…e∪bundle reconcile (unwired) (#458)\n\nResolution PRIMITIVES for bounded-archive compaction. PURE, no I/O, NOT yet wired into any\nreader — the building blocks Layer 1c-ii will call. Splitting the pure logic from the\nload-bearing reader wiring keeps each step small + reviewable.\n\n- `buildBundleMemberI\n[…]\ng (the #457 review note).\n\n9 unit tests pin the dedupe / conflict / cross-kind / loose-wins / bundle-stale paths.\nVerification: typecheck + check:docs + full suite (3170 unit + 615 integration) green.",
          "is_bot": false,
          "headline": "feat(archive-compaction): Layer 1c-i — pure cross-bundle index + loos…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-15T05:11:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ff676c9ccf8ab5f6d30ad84a57b14b063a12893e",
          "body": "…ed) (#457)\n\nSecond implementation layer of bounded-archive compaction. Still non-destructive (a reader\nonly; no writes, no loose∪bundle wiring). Addresses the #456 review's two Layer-1b asks:\n\n- `archive-bundle-binding.ts` `bindBundleMember(kind, member)`: after Tier-1, parse the\n  member's bytes w\n[…]\nhere is per-member self/identity binding; cross-bundle global uniqueness and\nloose∪bundle wiring remain Layer 1c. Verification: typecheck + check:docs + full suite\n(3161 unit + 615 integration) green.",
          "is_bot": false,
          "headline": "feat(archive-compaction): Layer 1b — Tier-2 per-member binding (unwir…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-15T04:59:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d176bbd5f38f67b674212809fb5a6591105c81d1",
          "body": "…eader (unwired) (#456)\n\nFirst implementation layer of bounded-archive compaction (RFC archive-level-compaction).\nNon-destructive: a new schema + a self-consistency reader, NOT yet wired into any archive\nreader and NOT yet written by anything — the foundation the later layers build on, shipped\nfirst\n[…]\n` code in error-code-surface KNOWN_CODES +\n  docs/cli-contract.md (project convention: new public code in both).\n\nVerification: typecheck + check:docs + full suite (3148 unit + 615 integration) green.",
          "is_bot": false,
          "headline": "feat(archive-compaction): Layer 1a — archive-bundle schema + Tier-1 r…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-15T04:43:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5b15aef9d035dd01064b28662c255732a645a131",
          "body": "…ntation (#455)\n\n* design: pin the three retention P1s before any archive-compaction implementation\n\nReview (on the merged #454) flagged three retention details to fix before the first\nimplementation PR — fixed in the RFC so an implementer can't fall back to \"bounded mode\nexists but the default is e\n[…]\n dropped, unless explicit `--drop-unmapped`.\n- Swept the Scope + Invariant 2 weak \"bounded-capable\" wording to the concrete default.\n\nDesign-only; check:docs + validate + typecheck + full suite green.",
          "is_bot": false,
          "headline": "design: pin the three retention P1s before archive-compaction impleme…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-15T04:27:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9619c32b04bcbbde8b79bf22396518f6f4e6df9e",
          "body": "… (#454)\n\n* design: RFC for archive-level compaction (the archive must compact too, not just grow)\n\nAddresses the core reframe from review: design-docs-ephemeral + event-pack compaction\n\"moved the pile\" — they turned many loose docs/events into ONE archive record per phase /\npack / decision, which s\n[…]\nalready relies on), not raw bytes or a re-canonicalization.\n\nRetitled \"Bounded archive — retention + compaction\"; index row reframed. Design-only;\ncheck:docs + validate + typecheck + full suite green.",
          "is_bot": false,
          "headline": "design: RFC — archive-level compaction (the archive must compact too)…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-15T04:09:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e000be809d6c01497585218e8b996712496e26ef",
          "body": "…(13 phases) (#452)\n\nGoes wide (per the \"do it all at once\" call), single-kind: archives every remaining\npre-ledger Population-B phase via maintainer attestation — P2, P3, P4, P5, P6, P7, P8,\nP38, P40, P41, P43, P45, P48 (13 phases, 52 done tasks). These predate the per-event\nledger: each `done` tas\n[…]\nt apart.)\n\nVerification (all green): validate + plan lint --strict (warnings 0) + check:docs +\ntypecheck + full suite (615 integration). 13 YAMLs removed, 13 snapshots added; no event\nor pack changes.",
          "is_bot": false,
          "headline": "migrate(dogfood): durabilize ALL Population-B phases via attestation …",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-15T03:53:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2dd850a907de7552b6360a25d63d907ac19e64b3",
          "body": "…es archived) (#453)\n\n* fix(check-doc-invariants): tolerate an absent design/phases (all phases archived)\n\nCI on the Population-B PR went red once the Population-A PR (#451) merged: with BOTH\nmerged, EVERY phase is archived, `design/phases/` is empty, and git does not track an\nempty directory — so o\n[…]\natching done snapshot → claim satisfied; absent dir +\n  no / wrong-phase_id / non-done / unparseable snapshot → fail-closed.\n\nVerification: typecheck + check:docs + full suite (615 integration) green.",
          "is_bot": false,
          "headline": "fix(check-doc-invariants): tolerate an absent design/phases (all phas…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-15T03:51:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "56c84b9fc31436f5a76865ebd86cd207eb8e272c",
          "body": "…ve + compact) (#451)\n\nGoes wide (per the \"do it all at once\" call): archives + compacts every remaining\ndone-evidenced Population-A phase in one single-kind PR — P18, P19, P20, P21, P24, P26,\nP27, P28, P29, P30, P31, P32, P33, P34, P36, P39, P42, P44, P46, P47, P49, P50 (22\nphases). For each: `phas\n[…]\n — kept separate).\n\nVerification (all green): validate + plan lint --strict (warnings 0) + check:docs +\ntypecheck + full suite (615 integration). Each archived phase resolves from its\nsnapshot + pack.",
          "is_bot": false,
          "headline": "migrate(dogfood): durabilize ALL remaining Population-A phases (archi…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-15T03:11:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "936693600ee7f84949f9bdd5b4d0bb299cf22625",
          "body": "…) (#450)\n\nSingle-kind Population-A archive + compact (RFC #440 cleanup). For each of P14, P15,\nP16, P17: `phase archive <id> --write` (snapshot + delete YAML) then `state compact\n<id> --write` (fold loose events into the pack, delete them). Counts: P14 cleaned 16,\nP15 10, P16 10, P17 10 — 46 loose \n[…]\ns is green with P16 archived (verified).\n\nVerification (all green): validate + plan lint --strict + check:docs + typecheck +\nfull suite (615 integration). Each phase resolves from its snapshot + pack.",
          "is_bot": false,
          "headline": "migrate(dogfood): durabilize Population-A batch 2 (P14, P15, P16, P17…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-15T02:50:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "36d4a14a4b7f28e9eee97b07f899feb3b26e0e32",
          "body": "…G \"closes Pxx\" rule (#449)\n\n* fix(check-doc-invariants): tolerate an archived phase in the CHANGELOG \"closes Pxx\" rule\n\nFound by dogfooding the durable-truth migration: rule #9 (a CHANGELOG \"closes Pxx\" claim\nmust reference a `done` phase) resolved the phase ONLY from a live `design/phases/*.yaml`.\n[…]\nchiving P16 keeps check-doc-invariants green; the unit\ntest guards the identity check independent of repo state.\n\nVerification: typecheck + check:docs + full suite (3133 unit + 615 integration) green.",
          "is_bot": false,
          "headline": "fix(check-doc-invariants): tolerate an archived phase in the CHANGELO…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-15T02:33:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "eabf5a7b9929d504fed582bbcb47531472c8cb88",
          "body": "… (#448)\n\nBatch cleanup of the dogfood durable-truth migration (RFC #440), incremental and\nsingle-kind per the review guidance: this PR is ONLY Population-A archive + compact\n(no attestation, no decision retire — those have different failure modes and ship\nin their own PRs).\n\nFor each of P9, P11, P1\n[…]\nm snapshots, evidence from packs) + check:docs + typecheck + full\nsuite (615 integration). The #442 producer fix holds with the larger archived set —\nP14's archive dry-run still returns would_archive.",
          "is_bot": false,
          "headline": "migrate(dogfood): durabilize Population-A batch 1 (P9, P11, P12, P13)…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-15T01:37:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "174c0df5b95088e44ce341c2cefede3c245ec694",
          "body": "* docs: fold accumulated RFC nits + record the v2.0.0 gate as demonstrated\n\nConsolidates the deferred review nits from #440/#444/#445/#446 now that the v2.0.0 gate\nis met, so the canonical RFC matches reality. Design/docs + one test comment only.\n\n- dogfood-durable-truth-migration-rfc.md:\n  - Status\n[…]\ned — the gate proof now lives in the gate section (anchored link),\n  not crammed into Status.\n\nVerification: check:docs (incl. the new intra-doc gate anchor) + validate + typecheck +\nfull suite green.",
          "is_bot": false,
          "headline": "docs: fold RFC nits + record v2.0.0 gate demonstrated (#447)",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-15T01:24:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "24becc4b8522725a2cd7bbd5cc3e825fa761fe57",
          "body": "… gate (#446)\n\n* migrate(dogfood): retire two shipped decisions — the decision-side durable-truth path\n\nStep 4 of the dogfood durable-truth migration (RFC #440): prove `decision retire` on this\nrepo and satisfy the v2.0.0 gate's \"≥2 retired decision records with live .md removed\".\n\nRetired two clear\n[…]\n\n\nCHANGELOG history references and the migration RFC's `Related` link stay as-is (historical\ncontext, not live-content claims).\n\ncheck:docs + validate + typecheck + full suite (615 integration) green.",
          "is_bot": false,
          "headline": "migrate(dogfood): retire two shipped decisions — completes the v2.0.0…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-15T00:56:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "46bb1b981489ee774e99b2ce70cce0a8b1bb93be",
          "body": "…ledger) path (#445)\n\nThe first Population-B phase converted to durable truth. P1 (Foundations) predates the\nper-event ledger: P1-T1 / P1-T2 are `done` in the YAML but have no `done` event anywhere\n(the durable ledger has zero P1 events). Per RFC #440 these are NOT events forged from\n`status: done` \n[…]\n plane intact) + check:docs + typecheck + full suite (615 integration). The #442\nproducer fix still holds on real data — with P1 + P10 + P22 archived, P9's archive\ndry-run still returns would_archive.",
          "is_bot": false,
          "headline": "migrate(dogfood): archive P1 via attestation — the Population-B (pre-…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-15T00:13:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "eb50757ec6d6741f3327bab21c65a543f9efbe11",
          "body": "…resentative) (#444)\n\nThe first evidence-bound done-phase fully converted to durable truth, and the first\nLayer-3 event-pack compaction run on this repo's real history. Two shipped, reviewed\ncommands applied to P10:\n\n1. `phase archive P10 --write` — wrote the snapshot\n   `.code-pact/state/archive/ph\n[…]\ne + plan lint --strict (control plane\nintact, P10 resolves from snapshot, evidence resolves from the pack) + check:docs (no\nbroken link to the removed YAML) + typecheck + full suite (615 integration).",
          "is_bot": false,
          "headline": "migrate(dogfood): durabilize P10 — archive + compact (v2.0.0 gate rep…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-15T00:01:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9b027b23696ee5d6a8a7f9d64d535037236ddba9",
          "body": "…fail-closed claims (#443)\n\nFollow-up hardening for #442 (the archived-sibling tolerance fix). #442's central safety\nclaim — an archived sibling's task-ids still join the duplicate-task-id scan, so a\ncollision stays fail-closed — was only covered by the happy path. Pin it directly, plus\nthe broken-s\n[…]\n\nuses `resolveMissingPhaseRef` for archived siblings — one shared tolerance on every path.\n\nTest + comment only; no production logic change. typecheck + 3124 unit + 615 integration\n+ check:docs green.",
          "is_bot": false,
          "headline": "test(phase-archive): pin the archived-sibling collision + broken-ref …",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-14T23:47:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3fc396c36d29caedf1712a7febabc61bf22c1f81",
          "body": "…T regression) (#442)\n\nFound by dogfooding the durable-truth migration: after ONE phase is archived (its\ndesign/phases/<id>.yaml deleted, the roadmap ref kept), archiving ANY OTHER phase\ncrashed with an uncaught ENOENT on the gone YAML. validate / plan lint tolerate\nthe archived sibling (resolve it \n[…]\nNOENT), both resolve, control plane\ngreen. Fails before this fix.\n\nVerification: typecheck + 3124 unit + 613 integration + check:docs green. Reviewed by an\nindependent reviewer (no critical findings).",
          "is_bot": false,
          "headline": "fix(phase-archive): tolerate an already-archived sibling phase (ENOEN…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-14T23:33:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ce5eb389dce8beed0bb372397854d8484eed8ac6",
          "body": "…est (#441)\n\n* migrate(dogfood): archive the cancelled phase P22 — durable-truth smoke test\n\nFirst execution step of the dogfood durable-truth migration (RFC #440). P22 is the\ncancelled phase — the safest first archive (terminal, needs no done events), so it\nproves the archive→delete→green loop on t\n[…]\nons/README.md`: add the index row (next to the parent \"Design docs are\n  ephemeral\" directive it executes), so the accepted decision is discoverable.\n\ncheck:docs + validate + plan lint --strict green.",
          "is_bot": false,
          "headline": "migrate(dogfood): archive cancelled phase P22 — durable-truth smoke t…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-14T23:07:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0e43183811aec424eb54042e5c4686f5b4b1fd0f",
          "body": "* design: RFC for the dogfood durable-truth migration (design-only)\n\nThe design-docs-ephemeral v2.0 MECHANISM is shipped (phase archive / decision\nretire / state compact --write). What was missing is a DECISION doc for converting\nTHIS repo's history into the durable forms so the live design docs bec\n[…]\nelled is smoke-test only, insufficient for the product claim), plus\n  ≥2 retired decision records with live .md removed, gates green after deletion.\n\ncheck:docs green; design-only (no runtime change).",
          "is_bot": false,
          "headline": "design: RFC — dogfood durable-truth migration (design-only) (#440)",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-14T14:07:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "781096572d3673b0690957de3328969cce15bca7",
          "body": "…h table (#439)\n\nFollow-up to the `state compact --write` wiring (#438): align the DRY-RUN result `kind`s\nto the RFC truth table's dry-run column, so a dry-run name says what `--write` WOULD do\n(it cleans, not just packs). Non-destructive — no unlink/gate/reconciliation logic\ntouched; only the dry-r\n[…]\nhe stale \"remaining follow-up\" note removed.\n- unit tests pin cells 10/11/12/14; integration asserts `would_pack_and_cleanup`.\n\nFull suite green (typecheck + 3124 unit + 612 integration + check:docs).",
          "is_bot": false,
          "headline": "event pack compaction — migrate dry-run verdict names to the RFC trut…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-14T12:55:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cbdf38a3da5db0e077d4d3d6f59fcd28db0aeef5",
          "body": "…act --write` (first reachable destructive path) (#438)\n\n* event pack compaction — Layer 3b-2b-2d: wire runEventPackCleanup into `state compact --write` (first reachable destructive path)\n\nWires the merged, reviewed cleanup orchestrator into the CLI so `state compact\n--write` becomes the FIRST comma\n[…]\nly once the unlink loop is wired\" — now wired, made current.\n- human advisory hint pluralizes (`1 advisory` / `N advisories`).\n\nFull suite green (typecheck + 3122 unit + 612 integration + check:docs).",
          "is_bot": false,
          "headline": "event pack compaction — Layer 3b-2b-2d: wire cleanup into `state comp…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-14T12:34:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "12f6f712ae07890fdff088d73f810276c3e6ffee",
          "body": "…PackCleanup (unwired) (#437)\n\n* event pack compaction — Layer 3b-2b-2c: cleanup orchestrator runEventPackCleanup (unwired)\n\nThe cleanup orchestrator that assembles the merged parts into the public\nCleanupOutcome and performs the real unlink — NOT wired into runStateCompact/CLI yet\n(production `stat\n[…]\nack @ts-expect-error guard comment\n  (\"pack on disk\" → \"pack-step mutation happened\").\n\nComments / docs only; no code or behavior change. typecheck / test (156 files,\n3110) / build / check:docs green.",
          "is_bot": false,
          "headline": "event pack compaction — Layer 3b-2b-2c: cleanup orchestrator runEvent…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-14T10:22:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0e5b4e0351328d388468a9ec4caffda024b0b423",
          "body": "…nt the all-vanished edge (type only) (#436)\n\n* event pack compaction — Layer 3b-2b-2b (part 3): make `cleaned` represent the all-vanished edge\n\nType-only contract change so the cleanup orchestrator (next PR) can honestly report\nthe rare \"all-vanished\" edge: the unlink loop runs over a non-empty tar\n[…]\n review: the `state compact` success result-shape goes in\ndocs/cli-contract.md in the CLI-wiring PR.)\n\nComment + test only; no behavior change. typecheck / test (155 files) / build /\ncheck:docs green.",
          "is_bot": false,
          "headline": "event pack compaction — Layer 3b-2b-2b (part 3): make cleaned represe…",
          "author_name": "Pocket",
          "author_login": "toshtag",
          "committed_at": "2026-06-14T08:37:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        }
      ],
      "releases_count": 62,
      "commits_last_year": 532,
      "latest_release_at": "2026-07-21T08:35:37Z",
      "latest_release_tag": "P80-T2-evidence",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 9,
      "days_since_latest_release": 0,
      "mean_days_between_releases": 3.6
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 85,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "code-pact",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "ai",
            "agent",
            "cli",
            "claude",
            "codex",
            "design",
            "spec-driven"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/code-pact",
          "is_deprecated": false,
          "latest_version": "2.7.0",
          "repository_url": "https://github.com/toshtag/code-pact",
          "versions_count": 62,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 2102,
          "first_published_at": "2026-05-16T16:08:59.148000Z",
          "latest_published_at": "2026-07-17T05:23:25.305000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 4
        }
      ]
    },
    "popularity": {
      "forks": 1,
      "stars": 1,
      "watchers": 0,
      "fork_history": {
        "days": [
          {
            "date": "2026-05-20",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 1,
        "total_forks": 1
      },
      "star_history": {
        "days": [
          {
            "date": "2026-06-01",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 1,
        "total_stars": 1
      },
      "open_issues_and_prs": 1
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 80712,
      "source_files_sampled": 617,
      "oversized_source_files": 9,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "yaml",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.9.0"
        },
        {
          "name": "zod",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.4.3"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 537,
        "open_issues": 1,
        "closed_ratio": 0.833,
        "closed_issues": 5,
        "closed_unmerged_prs": 2
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "toshtag",
          "commits": 536,
          "avatar_url": "https://avatars.githubusercontent.com/u/119549809?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci-deep.yml",
        "ci.yml",
        "publish.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "pnpm-lock.yaml"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": null,
            "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "27 out of 27 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 10,
            "reason": "all dependencies are pinned",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 10,
            "reason": "GitHub workflow tokens follow principle of least privilege",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "509af64900017a06e58fb3ffef90f1f38f5eda30",
        "ran_at": "2026-07-21T23:06:35Z",
        "aggregate_score": 5.9,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-21T14:30:11Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-21T14:28:09Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 544,
          "created_at": "2026-07-21T07:26:57Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/toshtag/code-pact",
    "host": "github.com",
    "name": "code-pact",
    "owner": "toshtag"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 60,
      "inputs": {
        "security": 59,
        "vitality": 72,
        "community": 41,
        "governance": 51,
        "engineering": 77
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 72,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "commits_last_year": 532,
              "human_commit_share": 0.99,
              "days_since_last_push": 0,
              "active_weeks_last_year": 9
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "9/52 weeks with commits",
                "points": 6.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 9
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "532 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 532
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 62,
              "latest_release_tag": "P80-T2-evidence",
              "releases_from_tags": false,
              "days_since_latest_release": 0,
              "mean_days_between_releases": 3.6
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "62 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 62
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~3.6 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 3.6
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 41,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 1,
              "stars": 1,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "below_threshold"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "1 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "1 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "good",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 77,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 55,
            "inputs": {
              "packages": [
                "code-pact"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 2102
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "2,102 downloads/month across npm",
                "points": 44.3,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 2102,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 51,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 77,
            "inputs": {
              "merged_prs": 537,
              "open_issues": 1,
              "closed_issues": 5,
              "issue_closed_ratio": 0.833,
              "closed_unmerged_prs": 2
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "83% of issues closed",
                "points": 38.9,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 83
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "537/539 decided PRs merged",
                "points": 38.1,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 537,
                      "decided": 539
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 35,
            "inputs": {
              "followers": 3,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "toshtag",
              "public_repos": 6,
              "account_age_days": 1328
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "3 followers of toshtag",
                "points": 4.3,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 3,
                      "login": "toshtag"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "6 public repos, account ~3 yr old",
                "points": 13.4,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 6
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 3
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "code-pact"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 4
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 4 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 4
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "62 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 62
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 77,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "3 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "27 out of 27 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "topics": [
                "agent",
                "ai",
                "claude",
                "cli",
                "codex",
                "design",
                "spec-driven",
                "ai-agents",
                "claude-code",
                "cursor",
                "developer-tools",
                "gemini-cli"
              ],
              "has_wiki": false,
              "homepage": "https://www.npmjs.com/package/code-pact",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://www.npmjs.com/package/code-pact",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "12 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 12
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 59,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Branch-Protection, Packaging. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "branch_protection",
                    "packaging"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 59,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 5.9
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "27 out of 27 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "all dependencies are pinned",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "GitHub workflow tokens follow principle of least privilege",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 60,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.99,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "98 of 99 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 98,
                      "sampled": 99
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 61,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "pnpm-lock.yaml"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "tsconfig.json"
              ],
              "agent_commit_share": 0,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0.01
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "1 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 1,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "all dependencies are pinned",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 99,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 80712,
              "source_files_sampled": 617,
              "oversized_source_files": 9
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "9/617 source files over 60KB",
                "points": 54.2,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 617,
                      "oversized": 9
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
    "deps.dev does not index npm:code-pact@2.7.0; advisories assessed against the repository dependency graph instead"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-21T23:06:49.500113Z",
  "schema_version": "0.25.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/t/toshtag/code-pact.svg",
  "full_name": "toshtag/code-pact",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.25.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsnpm.