Public record
Software health reportschema 0.27.0 · metrics 1.13.0 · 2026-07-23 18:10 UTC

varbees / rateguard

AI-native rate limiting SDK for Go, Node.js, and Python — middleware, not a proxy

TypeScript · Python · GoMIT★ 0 stars⑂ 0 forkssince Nov 2025View on GitHub ↗

varbees/rateguard holds a health index of 55 out of 100, placing it in the Moderate band. It scores highest on Vitality (76/100) and lowest on Community & Adoption (28/100). It was last updated 5 days ago. A single contributor accounts for most of its recent work.

55
overall / 100
Moderate

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

55
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

Harsha VardhanPersonal account
3 followers35 public repossince Oct 2020

This repository is owned by a personal account. A single-owner project carries more continuity risk than an organization-backed one.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publishTags
Gogithub.com/varbees/rateguard/packages/sdk-gov0.5.1-45 days ago
npm@varbees/rateguard-node0.5.132445 days agorate-limitingmiddlewarellmtoken-budgetapi-protection
PyPIvarbees-rateguard0.5.1-45 days ago

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

76Good · 22% of overall
How it's scored
36/36Push recency — last push 5 days ago
6.2/36Commit cadence — 9/52 weeks with commits
18/18Commit volume — 326 commits in the last year
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year326
human_commit_share1
days_since_last_push5
active_weeks_last_year9
How it's scored
27/27Ships releases — 1 releases published
36/36Release recency — latest release 68 days ago
12.6/27Release cadence — cadence unknown (single release)
0/10OpenSSF Scorecard: Signed-Releases — no data
Inputs used
releases_count1
latest_release_tagv0.1.0
releases_from_tagsno
days_since_latest_release68
mean_days_between_releases
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

28Critical · 18% of overall
How it's scored
0/60Stars — 0 stars
0/25Forks — 0 forks
0/15Watchers — 0 watchers
Inputs used
forks0
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (MIT)
0/18CONTRIBUTING guide
0/13.5Code of conduct
0/7.2Issue template
0/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingno
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno
How it's scored
33.5/80Monthly downloads — 324 downloads/month across go, npm, pypi
0/20Registry dependents — not reported by this ecosystem
Inputs used
packagesgithub.com/varbees/rateguard/packages/sdk-go, @varbees/rateguard-node, varbees-rateguard
dependents
ecosystemsgo, npm, pypi
total_downloads
monthly_downloads324
Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

46At risk · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
0/22.5Commit distribution — top contributor authored 100% of commits
1.4/13.5Contributor breadth — 1 contributors
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Inputs used
bus_factor1
contributors_sampled1
top_contributor_share1
How it's scored
0/46.8Issue resolution — no issues or no data
28.7/38.3PR acceptance — 3/4 decided PRs merged
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Inputs used
merged_prs3
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs1
Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.
How it's scored
10/30Ownership backing — personal (user) account
0/20Verified domain — not applicable to user accounts
4.3/25Owner reach — 3 followers of varbees
22.8/25Track record — 35 public repos, account ~5 yr old
Inputs used
followers3
owner_typeUser
is_verified
owner_loginvarbees
public_repos35
account_age_days2,094
Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.
How it's scored
25/25Published & resolvable — 3 package(s) on go, npm, pypi
35/35Publish recency — latest publish 5 days ago
12/20Version history — 4 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packagesgithub.com/varbees/rateguard/packages/sdk-go, @varbees/rateguard-node, varbees-rateguard
ecosystemsgo, npm, pypi
any_deprecatedno
min_days_since_publish5

Engineering Quality

Are baseline engineering and documentation practices in place?

72Good · 20% of overall
How it's scored
24/24CI workflows — 2 workflow(s)
24/24Tests present
0/16Linter config
0/9.6Pre-commit hooks
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — no data
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configno
has_precommit_configno
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.

Documentation

90Excellent
How it's scored
30/30README
25/25Documentation directory
15/15Documentation / homepage site — https://rateguard.antharmaya.com
10/10Repository description
0/10Topics
10/10Wiki
Inputs used
topics
has_wikiyes
homepagehttps://rateguard.antharmaya.com
has_readmeyes
has_docs_diryes
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

47At risk · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — no data
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
5/5Fuzzing — project is fuzzed
2.5/2.5License — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — no SAST tool detected
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — no data
7.5/7.5Token-Permissions — GitHub workflow tokens follow principle of least privilege
0/7.5Vulnerabilities — 27 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate4.7
Excluded from scoring (no data or not applicable): ci_tests, signed_releases. Remaining weights renormalized.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

76Good · 0% of overall
How it's scored
45/45Agent instructions — AGENTS.md
15/15Machine-readable docs (llms.txt) — llms.txt present
40/40Legible commit history — 100 of 100 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtyes
legible_history_share1
agent_instruction_filesAGENTS.md
agent_instruction_max_bytes14,911
How it's scored
12.6/18One-command bootstrap — packages/sdk-go/go.mod (toolchain convention, no task runner)
22/22Automated tests
0/11Lint / format config
11/11Static type checking — packages/dashboard/tsconfig.json, packages/sdk-node/tsconfig.json, packages/sdk-python/rateguard/py.typed, site/tsconfig.json
10/10Reproducible environment — Dockerfile, lockfile
0/10Demonstrated agent practice — no agent-authored commits among the last 100
0/8Automated maintenance — no automated dependency updates observed
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Inputs used
has_nixno
has_testsyes
lockfilesgo.sum, package-lock.json, uv.lock
has_dockerfileyes
typed_languageyes
bootstrap_files
has_devcontainerno
has_linter_configno
typecheck_configspackages/dashboard/tsconfig.json, packages/sdk-node/tsconfig.json, packages/sdk-python/rateguard/py.typed, site/tsconfig.json
agent_commit_share0
toolchain_manifestspackages/sdk-go/go.mod
dependency_bot_commit_share0
How it's scored
45/45Type-checkable code — TypeScript (statically typed)
55/55Manageable file sizes — 0/360 source files over 60KB
Inputs used
primary_languageTypeScript
largest_source_bytes41,728
source_files_sampled360
oversized_source_files0
How it's scored
0/40API schema (OpenAPI/GraphQL/proto)
20/20MCP server
40/40Runnable examples — examples
Inputs used
example_dirsexamples
has_mcp_signalyes
api_schema_files

Key facts

0GitHub stars
1contributors
326commits, last 12 months
5days since last push
1releases
1bus factor
0open issues
npmpackage ecosystems

Data collection warnings

  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository
  • deps.dev does not index npm:@varbees/rateguard-node@0.5.1; advisories assessed against the repository dependency graph instead

More detail

OpenSSF Scorecard 4.7 / 10
4.7aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-23 18:09 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
n/aCI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
10Fuzzingproject is fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTno SAST tool detected
0Security-Policysecurity policy file not detected
n/aSigned-Releasesno releases found
10Token-PermissionsGitHub workflow tokens follow principle of least privilege
0Vulnerabilities27 existing vulnerabilities detected
Direct dependencies 30
RegistryPackageVersion constraintManifest
npm@opennextjs/cloudflare^1.20.0site/package.json
npmframer-motion^12.23.24site/package.json
npmmotion-dom12.23.23site/package.json
npmmotion-utils12.23.6site/package.json
npmnext^15.4.9site/package.json
npmreact^19.2.1site/package.json
npmreact-dom^19.2.1site/package.json
npmshiki^4.3.1site/package.json
npm@base-ui/react^1.6.0packages/dashboard/package.json
npmclass-variance-authority^0.7.1packages/dashboard/package.json
npmclsx^2.1.1packages/dashboard/package.json
npmlucide-react^1.23.0packages/dashboard/package.json
npmmotion^12.42.2packages/dashboard/package.json
npmnext^15.4.9packages/dashboard/package.json
npmnext-themes^0.4.6packages/dashboard/package.json
npmreact^19.2.1packages/dashboard/package.json
npmreact-dom^19.2.1packages/dashboard/package.json
npmrecharts^3.9.2packages/dashboard/package.json
npmshadcn^4.13.0packages/dashboard/package.json
npmsonner^2.0.7packages/dashboard/package.json
npmtailwind-merge^3.6.0packages/dashboard/package.json
npmtw-animate-css^1.4.0packages/dashboard/package.json
Gogithub.com/redis/go-redis/v9v9.17.0packages/sdk-go/go.mod
Gogo.opentelemetry.io/otelv1.44.0packages/sdk-go/go.mod
Gogo.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpcv1.39.0packages/sdk-go/go.mod
Gogo.opentelemetry.io/otel/metricv1.44.0packages/sdk-go/go.mod
Gogo.opentelemetry.io/otel/sdkv1.44.0packages/sdk-go/go.mod
Gogo.opentelemetry.io/otel/sdk/metricv1.44.0packages/sdk-go/go.mod
Gogo.opentelemetry.io/otel/tracev1.44.0packages/sdk-go/go.mod
Gogolang.org/x/textv0.36.0packages/sdk-go/go.mod
All dependencies not collected

The resolved dependency set could not be collected for this report: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 10252,
      "has_wiki": true,
      "homepage": "https://rateguard.antharmaya.com",
      "languages": {
        "Go": 673254,
        "CSS": 8132,
        "Shell": 3403,
        "Python": 751076,
        "Dockerfile": 2010,
        "JavaScript": 8365,
        "TypeScript": 915947
      },
      "pushed_at": "2026-07-18T15:25:15Z",
      "created_at": "2025-11-22T12:54:24Z",
      "owner_type": "User",
      "updated_at": "2026-07-18T15:25:20Z",
      "description": "AI-native rate limiting SDK for Go, Node.js, and Python — middleware, not a proxy",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript",
        "Python",
        "Go"
      ]
    },
    "owner": {
      "blog": null,
      "name": "Harsha Vardhan",
      "type": "User",
      "login": "varbees",
      "company": null,
      "location": null,
      "followers": 3,
      "avatar_url": "https://avatars.githubusercontent.com/u/73575236?v=4",
      "created_at": "2020-10-28T05:51:33Z",
      "is_verified": null,
      "public_repos": 35,
      "account_age_days": 2094
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.1.0",
          "kind": "minor",
          "published_at": "2026-05-16T15:29:33Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "031443ff4fc21f6deec11f3ccf2618e55c129db7",
          "body": "The amber accent read as a Claude Code clone and was doing everything (active\nnav, kickers, links, callout labels, the bucket illustration, CTAs). Replaced\nwith a single ink accent — no hue — the way Stripe/Linear/Vercel work: near-\nmonochrome foundation, generous whitespace, one 'accent' that is co\n[…]\ns\n  are two-tone monochrome line icons; CTAs are ink-on-paper.\n\nBuild green, 25 static pages, tsc clean. Applies the docs-UX research\n(monochrome + whitespace + one accent + high contrast) end to end.",
          "is_bot": false,
          "headline": "design: monochrome light system site-wide — remove all orange",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-18T15:24:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d64b14f421347b6741796d7e4b8f629857ceb080",
          "body": "…-dark)\n\nDocs code was flat grey text — nothing to help a reader parse it. Now every\nCodeTabs/CodeBlock is highlighted with Shiki at build time (baked HTML, zero\nclient JS: docs bundles stay ~1KB).\n\nPalette is GitHub-dark-default on purpose: a docs reader is a developer who\nreads that exact palette \n[…]\nching + cross-tab localStorage persistence. Page-level API unchanged.\nBackground stripped so tokens sit on the block's own near-black brand surface.\n\nBuild green, 25 static pages generated, tsc clean.",
          "is_bot": false,
          "headline": "feat(docs): syntax-highlight code blocks at build time (Shiki, GitHub…",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-18T08:37:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3001d978ee7cc86e0c4abdf1400b1156235f7447",
          "body": "The deterministic demo (go run ./examples/runaway-demo, no API key) recorded to\nan animated SVG: an agent burning a 5,000-token budget call by call, then\nBLOCKED with a synthesized 429 the moment it's exhausted — in-process, before\nthe spend. 16KB, crisp at any scale, renders on the landing page and GitHub.\n\nThis is the single highest-value marketing asset: a Show HN / README that shows\nthe runaway getting halted is a different pitch from one that describes it.",
          "is_bot": false,
          "headline": "docs: add the runaway-agent demo to the README hero (animated SVG)",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-18T08:11:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3031ab6523aa885ff76286baedd3c9154d50d469",
          "body": "No code changes from 0.5.1. Exists to ship what 0.5.1 could not: a fully signed\nrelease (npm provenance + PyPI attestations + cosign SBOM) so the verify\ncommands in the docs actually resolve. Tag it once the npm automation token and\nPyPI Trusted Publisher are configured; the pipeline does the rest.",
          "is_bot": false,
          "headline": "release: cut v0.5.2 — the first end-to-end signed release (unreleased)",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-18T07:59:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c4438b91eb16fb98eb9aeb7e0eded903b0b5cbe6",
          "body": "Expert-lens launch audit: the README and SIGNING.md told a reviewer to run\n'npm audit signatures' and 'cosign verify-blob' — and both FAIL for 0.5.1.\nThere is no GitHub Release for the tag, npm 0.5.1 was published without\nprovenance, and PyPI without attestations, because the security fix went out\no\n[…]\n signed pipeline activates on the next tag. The model docs\nstay (correct for future releases); the false 'every release is signed' and\nthe runnable-but-failing commands are gone from the front matter.",
          "is_bot": false,
          "headline": "docs: stop advertising signatures 0.5.1 does not have",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-18T07:51:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dd55761405ff33eaf6ab74f2c4819c4e225373f1",
          "body": "All three registries verified serving 0.5.1, and the negative-usage DoW clamp\nconfirmed present in each SHIPPED artifact (npm dist esm+cjs, PyPI wheel, Go\nmodule) — not just the tag. The security fix is in users' hands everywhere.",
          "is_bot": false,
          "headline": "docs(changelog): mark 0.5.1 released — live on npm, PyPI, and Go",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-18T07:45:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4ae761e0237e3e8bf012882af54d3b3d71fe5558",
          "body": "…pm pending\n\nThe 'every release is Sigstore-signed' line was aspirational: 0.5.1's PyPI was\na manual token upload (no attestations) and the SBOM sign job never ran because\nthe release workflow failed on npm 2FA and PyPI trusted-publishing config. Say\nwhat actually happened and what unblocks the fully-signed flow, rather than\nclaim a guarantee 0.5.1 does not have.",
          "is_bot": false,
          "headline": "docs(changelog): honest 0.5.1 signing status — Go+PyPI out-of-band, n…",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-18T07:33:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b314f4a1f88ed93dbc4bfdcd9f2ac3421281e21c",
          "body": "The first real run of the Go-tag automation failed with 'fatal: empty ident\nname' — an annotated tag needs a committer, and the runner has none. Sets the\ngithub-actions[bot] identity. The v0.5.1 Go tag was pushed by hand this time;\nthis makes the automation work for the next release.",
          "is_bot": false,
          "headline": "fix(ci): give the go-tag job a committer identity (empty ident name)",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-18T07:33:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "44b95813dde4bd0d70bcdd0105eb7309eb41e5cc",
          "body": "…egistries\n\nGo modules resolve off packages/sdk-go/vX.Y.Z, not the repo-wide tag. That was\na manual step and it was forgotten for 0.5.0, so the proxy stayed on 0.3.0 while\nnpm and PyPI moved. Now a repo-wide vX.Y.Z tag mints the matching Go submodule\ntag in CI, and the confirm job fetches all three (npm, PyPI, and Go via\ngo list -m, which both populates the proxy and proves it resolves). The three\nregistries can no longer drift on version silently.",
          "is_bot": false,
          "headline": "release: mint the Go submodule tag automatically, confirm all three r…",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-18T07:24:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4ec5ca9959ae3ac31fb3f038c88494ad61cac4db",
          "body": "0.5.0 was tagged at 146acbc and published to npm and PyPI from there — a commit\nthat PREDATES the negative-usage denial-of-wallet fix (79baca9) and the Go\ndependency vuln patches (92539e2). So the packages users can install right now\ncarry a known budget-refund vulnerability. Go never got 0.5.0 at a\n[…]\nether (including the Go submodule tag that was missed).\nIt also carries the Sigstore signing that did not exist when 0.5.0 was tagged,\nso 0.5.1 is the first actually-signed release.\n\nDo not use 0.5.0.",
          "is_bot": false,
          "headline": "release: cut v0.5.1 — security patch over a stale 0.5.0",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-18T07:22:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "19849d43b3a70bdde5ce6114a1938565410bd356",
          "body": "…n SBOM)\n\nEarlier I deferred this because touching the release flow the night of a publish\nis the wrong risk. The founder asked for it, so it's here — built so it CANNOT\nendanger the publish: the sign-release job runs only after npm, PyPI, and the\nserve-confirmation all pass, and it creates the GitH\n[…]\nadict\nits own thesis; this doesn't. SIGNING.md documents the full model and the\none-command verify, and connects it to FRAMEWORK.md.\n\nReference repos pulled to _external/cosign and _external/sigstore.",
          "is_bot": false,
          "headline": "release: sign every release with Sigstore keyless (npm + PyPI + cosig…",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-18T07:07:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2edde57244281888ed255cd8ca4472f6daab2c11",
          "body": "Extends the catalogue to two more money paths (task: realtime + redis):\n\n- realtime voice sessions are billed per-second and can run for minutes; the\n  cost breach is the DoW guard for that substrate. Mutating it to never fire\n  models an unbounded voice loop.\n- outbound fails open on a Redis error by design (budgets still cap spend\n  in-memory), but the trail must not report a phantom rate-limit; the mutation\n  drops the err==nil guard so a Redis EVAL error reads as a real 429.",
          "is_bot": false,
          "headline": "test: add realtime cost-cap and Redis fail-open mutations",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-18T06:53:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6b4162c174b77a0e428f8e8df3f8b102057ef181",
          "body": "…am case\n\nAGENTS.md rule 11 (deliver the provider's exact bytes, never buffer a stream\nwhole) was fuzzed in Go and asserted inline in Python, but Node only checked\npassthrough on a small single-shot SSE body. Node is the SDK where the SSE bug\nlived, so the gap was in the worst place.\n\nAdds a ~500KB \n[…]\nuffer whole' — plus exotic framing (CRLF,\nheartbeat comments, no trailing newline) that must reach the caller unnormalized.\nUsage is still extracted from the final chunk: passthrough is not blindness.",
          "is_bot": false,
          "headline": "test(sdk-node): name the byte-transparency rule, cover the large-stre…",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-18T06:50:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d2babcfea9cc0516dbb6e60ce7f4db00df2e1907",
          "body": "The reusable method behind the repo, written as a trust story for launch: the\nfour questions test count cannot answer (what is it / do surfaces match / do\nbehaviours match / are the tests real) and the tool that answers each —\ngraphify, parity_guard, conformance vectors, mutate.py — plus the live matrix\nfor truth vs self-consistency. Led by the 100% mutation score. None of it is\nRateGuard-specific; a general method for proving any multi-language SDK.",
          "is_bot": false,
          "headline": "docs: FRAMEWORK.md — how we prove three SDKs are one product",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-18T06:43:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "79baca9aa80a478994de3eb08b7cc71d1ce17b54",
          "body": "The adversarial suite (new) found a real cross-language denial-of-wallet\nvector: a compromised or buggy provider reporting output_tokens=-1_000_000 had\nthat negative COMMITTED against the budget, which DECREASES recorded usage — an\nattacker-controlled refund that lets a runaway agent spend past its \n[…]\nil-safe).\nAdversarial suites in all three SDKs pin it (hostile values, malformed SSE,\ntruncated JSON, null bytes — none crash, none go negative), and mutate.py locks\nthe clamp so removing it fails CI.",
          "is_bot": false,
          "headline": "fix: negative provider usage refunded the budget — clamp it, all 3 SDKs",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T17:37:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8c2c781e3f05e2fbac5d75f755b390de0c84b363",
          "body": "Adds a supply-chain job. The scoping is the point: fail on what a USER\ninstalls, report on dev tooling that never leaves the repo.\n\n- Go: govulncheck traces actual called code (the gold standard). It found the\n  x/net and otel/sdk vulns already fixed, and is why CI now pins go 1.25.x —\n  the seven s\n[…]\nip-audit against a --no-deps install is the shipped surface.\n\nA gate that fails on unreachable vulns trains everyone to ignore it. This one\nonly fires on something a user could actually be exposed to.",
          "is_bot": false,
          "headline": "ci: scan dependencies for known vulnerabilities, scoped to what ships",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T17:23:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "92539e266e7f157fbfc7c0b6de38fdfd01966de7",
          "body": "govulncheck (now wired into CI) flagged 8 vulnerabilities in called code. Two\nare in shipped dependencies and are fixed here:\n\n  golang.org/x/net    v0.47.0 -> v0.53.0  (GO-2026-4918, http2)\n  go.opentelemetry.io/otel/sdk v1.39.0 -> v1.44.0  (GO-2026-4394, hijacking)\n\nThe other seven are Go standard\n[…]\n go directive moves to 1.25.0 and CI pins a patched\ntoolchain so they resolve there. A crypto library that ships known-vulnerable\ntransitive deps has no business asking anyone to trust its signatures.",
          "is_bot": false,
          "headline": "fix(sdk-go): patch two dependency vulnerabilities before launch",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T17:16:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "146acbcc506891aeceb754b2f9dd347fc04b926d",
          "body": "Mutation survivor (python/budget-boundary-off-by-one), the same gap Node had.\nEvery budget test used hour_limit=0 or the month window, so flipping the hour\ncheck to '>' — a one-token overspend on every budget — went unnoticed.\n\nRecords exactly hour_limit and asserts BudgetExceeded; records one below and\nasserts the call runs. Both ports hid this; the symmetric catalogue caught it\nin both.",
          "is_bot": false,
          "headline": "test(sdk-python): pin the hourly-cap boundary — >= not >",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T15:20:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "47a4994356fa8dcfe26bd9976a5a723bdcf81dcd",
          "body": "Node hid a one-token overspend at the hourly cap that its suite did not catch,\nsurfaced only once its catalogue matched Go's. Python has the same '>=' at\ntoken_budget.py:347 and, until now, no mutation probing it. Adding it to check\nwhether the same gap exists on the third SDK.",
          "is_bot": false,
          "headline": "test: add Python budget-boundary mutation — does the port hide it too?",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T15:19:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3d7c90f5bd8a5580a6ebcb326984d59795c51b41",
          "body": "Mutation testing survivor (node/budget-boundary-off-by-one). Flipping the\nhour-window check from 'used >= limit' to 'used > limit' — a one-token\noverspend on every budget, forever — left the whole Node suite green.\n\nEvery existing budget test either disabled the hour window (hourLimit: 0) or\nexercis\n[…]\nentire argument for\nsymmetric mutation coverage: the port hid a boundary bug the reference did not.\n\nRecords exactly hourLimit and asserts block; records one below and asserts\nallow. Kills the mutant.",
          "is_bot": false,
          "headline": "test(sdk-node): pin the hourly-cap boundary — >= not >",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T15:17:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1ad88d95c57dba140cf18236c4272137b0d34bda",
          "body": "The catalogue had 11 Go mutations to Node's 4, and the engine's own asymmetry\ncheck fired on it. Node is where the SSE bug actually lived, so testing the\nreference SDK twice as hard as the port is the exact bias that let it through.\n\nMirrors six of Go's money-path mutations into Node: MAX->SUM usage merge,\nbudget boundary off-by-one, the DoW estimate->zero hole, freeze-does-not-halt,\nbreaker recovery, and rule-5 peek-not-record.",
          "is_bot": false,
          "headline": "test: close the Node mutation gap (4 -> 10) the engine warned about",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T15:15:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3bf8d3ff1672fa6383a1b23f9db51503407b321b",
          "body": "graphify's semantic pass flagged that test/provider counts disagree across\ndocs. Audited every current-facing surface:\n\n- llms.txt (what AI crawlers read) was badly stale: '~650 total, 188 Go funcs,\n  226 Node, 237 Python, 44 mypy files, 3 conformance suites'. Real numbers:\n  800+ total (253/298/323\n[…]\n276 for v0.4.0) are left alone\n— those are historical and correct for the version they describe.\n\nProvider counts already agree across current docs (28 = 23 compat + 5 native);\nno change needed there.",
          "is_bot": false,
          "headline": "docs: make the numbers coherent across surfaces before launch",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T15:14:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "41ab7c65d5aef15f2b7b663d41031bf96381101a",
          "body": "Found by the graphify semantic pass, which read both docs and noticed they\ncontradict. API_REFERENCE.md said 'Known current exception: retry_after_ms\nrounding differs across SDKs... not yet unified, see AGENTS.md rule 13' — and\nAGENTS.md rule 13 says the opposite: it IS unified. The stale doc pointe\n[…]\nence was documenting a bug that had already been fixed,\ntelling readers the three SDKs drift where they demonstrably do not. Worse\nthan a stale number: a live warning about a defect we no longer have.",
          "is_bot": false,
          "headline": "docs: API_REFERENCE claimed retry_after_ms was not unified — it is",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T14:03:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b1dfcbf2fed8f053a414f8d2ce3f8d1b2edcc014",
          "body": "100% over 4 mutations is not the same claim as 100% over 11, and printing them\nin one column implies it is. The asymmetry also has a direction: the reference\nSDK accumulates mutations because it is the one we read, while the ports — where\nthe SSE bug actually lived — accumulate fewer. A benchmark that flatters the\nbest-read implementation is measuring our attention, not our tests.",
          "is_bot": false,
          "headline": "test: warn when the mutation catalogue is asymmetric across SDKs",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T12:43:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "473cb7ce5446fce341f9a0a28a7bb1c847f4d054",
          "body": "Extends the catalogue to money paths it had not reached. The freeze mutations\nmatter most: freeze is the operator's stop button, the thing you reach for at\n3am while the bill climbs. A freeze that does not halt is worse than no freeze,\nbecause you believe you stopped it.\n\nAlso mirrors Go's rule-5 mutation into Python — Go had it from the start and\nPython did not, which is the same reference-SDK bias the catalogue exists to\neliminate.",
          "is_bot": false,
          "headline": "test: mutate the kill switch, the breaker, and rule 5 in Python",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T12:41:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dde6c31d9bacbd2b01030e8a38111b9e2a0474e3",
          "body": "'800+ tests' tells a reader almost nothing — this repo had ~800 green tests\nwhile two SDKs metered zero tokens for the most common streaming shape in the\necosystem. Test count measures effort. Mutation score measures detection.\n\nPublishes 100% across all three SDKs (17/17), with the honest caveat: t\n[…]\npicked and small on purpose, which is what makes a 100% gate\ndefensible rather than a spray of equivalent mutants nobody triages.\n\nOne command, ~50s, and the mutations are this repo's own bug history.",
          "is_bot": false,
          "headline": "docs: publish the mutation score, since 800 tests is not a number",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T12:34:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7da38cdfae270702f378f54bb34691dcdbb41b4d",
          "body": "The catalogue had 8 Go mutations to Node's 3 and Python's 4 — the REFERENCE\nSDK was the best-defended, while Node and Python, the two that silently\nmetered zero tokens for months, were the least. That is precisely the bias\nthat let the SSE bug through: we scrutinise the SDK we already trust.\n\nFor a product whose entire thesis is that three SDKs behave identically, an\nasymmetric mutation catalogue is testing the wrong thing.",
          "is_bot": false,
          "headline": "test: mirror Go's reservation-accounting mutation into Node and Python",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T12:32:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "edcaec441dd53d45137d7ebac114e642e0faeed2",
          "body": "Coverage measures whether a line RAN. This measures whether a test would\nNOTICE the line being wrong — the only question that matters, and one that\n~800 green tests answered 'no' to three times this month.\n\nFails below 100%. That threshold is defensible only because the catalogue is\nsmall and hand-p\n[…]\nn reproduces\na defect this repo actually shipped, so there are no equivalent mutants to\nexcuse. A survivor means we could ship that bug again today and stay green.\n\nRuns in ~50s across all three SDKs.",
          "is_bot": false,
          "headline": "ci: gate on mutation score, not coverage",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T12:31:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "38a991f54aea6a6819d8e4517427cdb1c963eeb5",
          "body": "…ored\n\nFound by scripts/mutate.py. Removing the body's size from the unknown-schema\nestimate — so every unrecognized body reserves a flat 4096 — left the suite\ngreen. The mutant survived.\n\nThe bounds assertions look thorough and are not: 4096 > 0 holds, and\n4096 <= len(body) + 4096 holds for ANY bod\n[…]\nperty instead: a bigger unknown body reserves more, and by an\namount that tracks the bytes. I wrote the weak test this morning and was\nconfident about it; hand-review had already passed over it twice.",
          "is_bot": false,
          "headline": "test(sdk-python): the unknown-body test passed while the size was ign…",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T12:29:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0e43edfa66b067f3a9bbac3efc3dd09f33076e5e",
          "body": "Line coverage measures whether code RAN. It cannot measure whether a test\nwould NOTICE the code being wrong. Only the second question matters, and this\nrepo has the receipts: ~800 green tests failed to notice that Node and Python\nmetered ZERO tokens for the most common streaming shape, that the tran\n[…]\nlready had, would\nanyone notice? A survivor means we could ship it again today and stay green.\n\nRefuses to run on a dirty tree and re-verifies cleanliness afterwards, because\nit rewrites source files.",
          "is_bot": false,
          "headline": "test: mutation engine — do the tests notice when the money paths lie?",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T12:26:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "25d33d73cbe3ee9d84e3b1caf972d6c22e27054e",
          "body": "d61b48c replaced the false headline claim but only where I happened to look.\nThree survived, and the two worst were the most-read text on the project:\n\n  * README's opening paragraph — \"No proxy, no gateway, no added latency\"\n  * site meta description — what Google and every link preview shows\n  * d\n[…]\nrence, npm, PyPI, and license badges. The npm and PyPI badges\nwill read 0.2.0 until the packages are published — that is accurate, and a\nstanding reminder that cutting a release is not publishing one.",
          "is_bot": false,
          "headline": "docs: kill the last three \"no latency\" claims, add badges",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T10:34:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4ed46c426af5581f0bf07c74e94b91aa0ce0a896",
          "body": "… to guard\n\ntest_packaging.py imported tomllib, which is 3.11+. This package declares\nrequires-python >=3.10 and the CI matrix tests that floor deliberately — so the\ntest written to catch metadata drift immediately failed on the oldest supported\ninterpreter.\n\nSkips below 3.11 via importorskip. The c\n[…]\nata, not runtime\nbehaviour, so it is identical on every interpreter and one matrix leg is full\ncoverage. Adding tomli would mean giving a zero-dependency package a dependency\nto test that it has none.",
          "is_bot": false,
          "headline": "fix(sdk-python): the packaging test broke the 3.10 floor it was meant…",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T10:30:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c7fb3a793ef910e524e7e98c2fb23776840f13aa",
          "body": "Said \"696 tests\" — the real number is 873 (Go 253 funcs, Node 300, Python 320).\nUnder-claiming is safer than over-claiming but it is still wrong, and a\nhardcoded count on a landing page rots on every commit.\n\nNow \"800+\", a floor that stays true as tests are added and only breaks if tests\nare deleted\n[…]\nanyway. Also mentions the live\nmatrix, since the interesting claim was never the count: it is that the same\nsuite runs against real provider APIs, because a passing suite only proves\nself-consistency.",
          "is_bot": false,
          "headline": "docs: the landing page under-claimed its own test count by 177",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T10:27:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d069351d09e0ab32c2d1f7b7864f94fccc60b740",
          "body": "…ipping it\n\nThe real-Redis suite documents its own contract: \"if spawning fails for any\nreason (binary missing, sandboxed environment, port conflict), the suite skips\ninstead of failing.\" It did not. On a machine without redis-server it failed\nthe entire run with ENOENT.\n\nspawn() does not throw sync\n[…]\neal, and stops\nspawning a server on CI at all — the suite already skips there by design, so\nit was starting a process to prove nothing.\n\nVerified with CI=true: 298 passed, 8 skipped, 0 errors, exit 0.",
          "is_bot": false,
          "headline": "fix(sdk-node): a missing redis-server crashed the suite instead of sk…",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T10:27:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8f1e20537487ec37005e29f913a9c431d4cbcdbf",
          "body": "A contributor following the README got 4 collection errors: fastapi, starlette,\nand cryptography were missing from the dev extra. Every dev box had them from\nsomewhere else, so the suite passed here and collapsed on the first clean CI\nrunner. Verified in a fresh venv — 320 pass now, 4 errors before.\n[…]\nskip (pipecat, livekit) are\ncorrectly excluded: those are deliberately optional and skip themselves.\n\nProven, not assumed: removing fastapi from the backend makes the test fail\nnaming the exact drift.",
          "is_bot": false,
          "headline": "fix(sdk-python): `pip install -e '.[dev]'` could not run the test suite",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T10:27:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "18f5298080d7952c1cf77665ce5208124514e95a",
          "body": "Bumps sdk-node/package.json, sdk-python/pyproject.toml, and __version__. Go\nderives its version from the module tag.\n\nA genuine minor bump, not housekeeping: budget reservations are now MEASURED\nfrom each request rather than assumed to be 4096, which changes behaviour for\nanyone who relied on the ol\n[…]\nangelog that pretends otherwise is the same failure in a\nnew file.\n\nNOT PUBLISHED by this commit. Tagging is the founder's call:\n    git push && git tag -a v0.5.0 -m \"v0.5.0\" && git push origin v0.5.0",
          "is_bot": false,
          "headline": "release: cut v0.5.0 — the honesty release",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T10:11:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fed137575e64feb5d0c1ad4cf9821fc3cc110142",
          "body": "v0.3.0 and v0.4.0 were cut and never published. npm and PyPI have served 0.2.0\nthis whole time while the site advertised features nobody could install — and\nv0.4.0's own commit message says it was cut to close that exact gap, then fell\ninto it too.\n\ndocs/RELEASE_CHECKLIST.md was never the problem. I\n[…]\nbun, with bun.lock\ncommitted and `bun run test` in the checklist since forever. It would have\nfailed on its first run. Both workflows now install with bun; npm is used only\nto publish, for provenance.",
          "is_bot": false,
          "headline": "ci: make pushing a tag publish, because cutting a release never did",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T10:11:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dd0f2db755559c15e83290c08bdad27b3c5ef438",
          "body": "Rule 5 (\"Peek, never Allow\") is a SECURITY property, not a nicety. The agent\nstory is that a model asks \"can I afford this call?\" before making it. If the\nasking spends, the safety check IS the leak — and the more careful the agent,\nthe faster it burns. It lived in AGENTS.md as prose with exactly on\n[…]\nrequire the test to fail. The first two didn't.\nThis one does, naming the exact violation. A test that cannot fail is not a\ntest — it is a green light that means nothing, which is worse than no light.",
          "is_bot": false,
          "headline": "test: mechanize agent rule 5 — pre-flight queries never consume",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T09:57:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "990534be623ef249b2a7e9afe6dd34f3e53a4965",
          "body": "RateGuard fails CLOSED inbound and OPEN outbound — same limiter, same error,\nopposite answers. The asymmetry was real and looked deliberate, but nothing\nstated it and only the inbound half was tested. An unreviewed security posture\nis a bug whichever way it points.\n\nNow stated, and coherent:\n\n  INBO\n[…]\ns backend, fail-open stops being defensible and that\ntest is where it breaks. Documented on the rate-limiting page — an operator\ndeploying with Redis has to know this before the outage, not during it.",
          "is_bot": false,
          "headline": "test: state what happens when Redis dies, and prove the spend cap holds",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T09:52:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "791972323cf919767aa88a9591cccc93c485476e",
          "body": "A doc sample that doesn't compile is a lie with syntax highlighting, and this\nrepo was telling several. Nothing had ever executed them.\n\nExtracts every Node and Python sample from site/app/docs/** and checks it\nagainst the real API: Node via the TypeScript checker, Python by validating\nRateGuard(...\n[…]\n that means nothing is worse than a red\n    one. The import is now injected when absent.\n\nProven, not assumed: re-introducing the exact bug that shipped makes it fail\nwith TS2353, and clean docs pass.",
          "is_bot": false,
          "headline": "ci: run the doc samples, so they cannot lie again",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T09:43:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b9ea304d3f206f765cef23ad7b44a212e4d3335b",
          "body": "The docs told users to write flat options that do not exist:\n\n    new RateGuard({ preset: 'llm-heavy', tokenBudgetPerHour: 250_000 })\n    RateGuard(preset=\"llm-heavy\", token_budget_per_hour=250_000)\n\nRateGuardOptions has no such field; the real option is nested (tokenBudget /\ntoken_budget). Python r\n[…]\nfer here by idiom; the lie was claiming otherwise.\n\nFound by pointing the new live harness at a real provider: a 60-token budget\nthat never blocked. The config had been ignored, not the budget broken.",
          "is_bot": false,
          "headline": "fix(docs): the Node and Python config samples did not work",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T09:43:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "977e9babf57f98d1b1d4caf01ce4034d3cf66a6a",
          "body": "Python had a live harness; Go and Node did not. That was backwards: Node is\nthe SDK that silently metered ZERO tokens for the most common streaming shape\nin the ecosystem (e6eba43) while all ~300 of its tests passed, and Go is the\none that got it right — unverified, which is indistinguishable from l\n[…]\n\nBoth derive the provider from the configured host via detectLLMCall rather\nthan assuming it, which is the mistake the Python harness made.\n\nVerified 2026-07-17 against NVIDIA NIM and Groq free tiers.",
          "is_bot": false,
          "headline": "test(live): port the live provider harness to Go and Node",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T09:43:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "898f4168d6758f791b3a87dca0c4d6cdf8899182",
          "body": "Which providers we have actually tested against, and when. No competitor\npublishes this, and it is the difference between \"works\" and \"verified\".\n\nIncludes what the captures found: Groq emits the same usage three times per\ncall, so a summing extractor bills 150 tokens for a 50-token call; DeepSeek\nc\n[…]\n; NIM sends a null audio_tokens.\n\nStates the denial-of-wallet coverage gap in the same breath as the green\nmatrix, because a reader who sees three ticks will otherwise assume it is\ncovered. It is not.",
          "is_bot": false,
          "headline": "docs: publish the live provider matrix and its gap",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T09:12:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c22b07eb02b4d337d58c63ded330295ba70a24df",
          "body": "…serted on\n\nThe live harness hardcoded its provider name to the literal \"nvidia\". That was\ninvisible while NVIDIA NIM was the only endpoint ever pointed at it, and broke\nthe moment the matrix pointed elsewhere: against Groq and DeepSeek it read the\nbudget key `global:nvidia:<model>:outbound` — which\n[…]\ntor\nand unit tests, never live. OpenAI would close it.\n\nAlso drops the stale \"use a local Ollama\" suggestion — local models are\npermanently off the table here; captured vectors serve that need better.",
          "is_bot": false,
          "headline": "test(live): run the provider suite as a matrix, and fix the key it as…",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T09:12:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "20fb8924c7995586542b5a2b74da158dc889e381",
          "body": "… vectors\n\nCaptured from live free-tier calls 2026-07-17 and replayed offline forever.\nAll three SDKs reproduce all three exactly.\n\nGroq is the find. It emits the SAME usage THREE times for one call: top-level\n`usage`, a nested `x_groq.usage` carrying identical numbers, then top-level\n`usage` again \n[…]\n from a real provider, replay\nforever. Deterministic, offline, no key, no GPU — strictly better than a\nlocal model as a regression fixture, and the only thing that has ever caught\na metering bug here.",
          "is_bot": false,
          "headline": "test: freeze real NVIDIA NIM, Groq, and DeepSeek bytes as conformance…",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T09:08:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d61b48c259679e0369868150831a5b5c765b5888",
          "body": "The claim was false. RateGuard costs ~26-37µs and ~7KB per admission\ndecision, and ~320-350µs on an outbound call. Every line of code costs\nsomething; a claim you cannot show a number for is not a claim.\n\nThe honest pitch was always the hop, not zero: a gateway adds a 1-30ms\nnetwork round trip, so t\n[…]\nry\n(Regulativ.ai's \"AI Governor\", aigovernor.app, the enterprise-GRC SEO swamp)\nand it was still live on the front page. llms.txt keeps the word only where\nit describes competitors, which is accurate.",
          "is_bot": false,
          "headline": "docs: replace \"no latency overhead\" with the measured number",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T08:59:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5f6e532dba161389410098193b8404b933d63b28",
          "body": "\"No proxy. No extra service. No latency overhead.\" was the headline claim and\nwas entirely unmeasured. An adjective is not a number, and \"how much?\" is the\nfirst question any technical reader asks.\n\nMeasures the public surface against the same handler and transport without\nRateGuard, so the delta is\n[…]\n\nestimate skips it, so the delta between the two IS the price of measuring,\nvisible rather than assumed away. It costs ~80-100µs.\n\nProfiling these found two real defects, fixed in 35384e9 and 9fad4df.",
          "is_bot": false,
          "headline": "test(sdk-go): benchmark what RateGuard actually costs",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T08:59:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9fad4dfd02a5899ec1a1a05cb11e97f9f1a8c712",
          "body": "…text\n\nEstimateRequestTokens accumulated every prompt chunk into one strings.Builder\nand estimated the joined result, which cost a full extra copy of the prompt.\nTokens are additive — there was never anything to gain by concatenating first.\n\nMeasured on a 100K-char context: 4.69ms -> 2.26ms and 386K\n[…]\nould need a hand-rolled scanner to remove.\nNot worth it: 2.26ms sits against a long-context LLM call taking 5-30 seconds,\nand the typical 14µs case is fixed reflection cost that copying never touched.",
          "is_bot": false,
          "headline": "perf(sdk-go): count prompt tokens incrementally, without joining the …",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T08:54:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "35384e9996bec254775202649fb2fd0b12c7ae5e",
          "body": "With no OTLP endpoint and no custom span processor configured — the default —\nthe SDK still built a real TracerProvider with AlwaysSample and a\nSimpleSpanProcessor wrapping a NOOP exporter. Every request allocated a\nrecording span, computed its attribute set, deduped it, and handed it to an\nexporter\n[…]\n NeverSample when nothing consumes the\nspans, AlwaysSample when something does. The tracer stays real and the API\ncontract is unchanged — a span is still returned, it just costs nothing to\nthrow away.",
          "is_bot": false,
          "headline": "perf(sdk-go): never record spans when nothing is exporting them",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T08:54:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4a45a495da978a4e646d23709e0cb0571cbd7e9a",
          "body": "The parity guard caught the same mistake as 7334db7: Node and Python export\nthe estimator, Go kept it unexported. It is legitimately public API — \"what\nwould this request cost?\" is the question the MCP pre-flight tool already\nanswers, and a user tuning EstimatedTokens needs to measure before choosing.\n\nLocks 88 capabilities in the manifest (was 85).",
          "is_bot": false,
          "headline": "fix(sdk-go): export EstimateRequestTokens for parity",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T08:35:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e1a7efbe19871de95c796098b020106ba0fa9110",
          "body": "… a constant\n\nPython port of 45dce5c (rule 3), completing the set. Both the sync and async\noutbound paths now pass the buffered body to reserve().\n\nRetargets test_outbound_streaming_without_usage_charges_estimate, which\nasserted usage == 4096 exactly. That pinned an implementation constant rather\nth\n[…]\nthe reservation, never\nzero\", and the reservation is now measured per request. It asserts the\ncontract now, and still fails if usage is ever recorded as zero — the\ndenial-of-wallet case it exists for.",
          "is_bot": false,
          "headline": "fix(sdk-python): measure the budget reservation from the request, not…",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T08:35:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "88652e4ab524d2d94b3bacfb4de49d277416d20e",
          "body": "… constant\n\nNode port of 45dce5c (rule 3). wrapFetch reserved a flat 4096 for every call,\nresolved at wrap time. Since overshoot is bounded by limit * (actual/estimate),\nthat under-reserved long-context calls ~25x — the workload most able to burn a\nbudget was the workload least protected by it.\n\nRes\n[…]\nn size rather than\nfalling back to reserve-all, which would serialize the budget key and throttle\na whole application on upgrade.\n\nSame 16 assertions as the Go suite, so the two are actually compared.",
          "is_bot": false,
          "headline": "fix(sdk-node): measure the budget reservation from the request, not a…",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T08:35:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "45dce5c30f84b0bea2c3b988aa421a676ec9f223",
          "body": "…onstant\n\nThe outbound transport reserved a flat 4096 tokens for every call, resolved\nonce at construction — before any request existed. Since overshoot is bounded\nby limit * (actual/estimate), that constant was fine for a typical chat call\nand ~25x wrong for a 100K-token RAG call: the workload most\n[…]\n hide a 100K prompt.\nReserve-all is now reserved for bodies there is nothing to measure.\n\nRule 6 holds: this reads bytes already buffered and never rewrites the request.\nNode and Python next (rule 3).",
          "is_bot": false,
          "headline": "fix(sdk-go): measure the budget reservation from the request, not a c…",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T08:27:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e198e538d3225dc9d9c9465c68c3ca6556372e2f",
          "body": "Budget enforcement is a shared-counter problem and shared counters are where\nraces become money, but every existing budget test drives one request at a\ntime — the one scenario a production agent never produces.\n\nPins the reservation model's real guarantee under -race: estimate=0 reserves\nthe whole r\n[…]\n each commit more. Measured:\n\n    overshoot <= limit * (actual / estimate)\n\nThe overshoot factor is exactly how wrong the estimate is. That number drove\nthe outbound estimation fix in the next commit.",
          "is_bot": false,
          "headline": "test(sdk-go): pin budget enforcement under concurrency",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T08:27:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ab2b5abfd1d82eac2d8cb600798bca5420cf838d",
          "body": "~790 tests across three SDKs and no CI at all — every run was manual. That is\nhow the SSE usage bug stayed green: a suite nobody runs automatically passes\nuntil the moment it matters.\n\nJobs: Go (build, vet, and -race — budget enforcement is a shared-counter\nproblem, so the race detector is the point\n[…]\nat claim was never tested. It is true — verified\nin a bare venv — and now it stays true.\n\ntests/live is explicitly excluded: it needs real provider keys, and a missing\nkey must never look like a pass.",
          "is_bot": false,
          "headline": "ci: add the pipeline this repo never had",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T08:15:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7334db704ccb790497a0c93c40190e92a499d862",
          "body": "Found by the parity guard on its first run. Node exports estimateWith and\nPython exports estimate_with; Go kept it unexported, so a Go user writing the\nsame \"use my tokenizer, else the default\" logic had to reimplement the nil\ncheck by hand.\n\nIntroduced in 314b231 (the CJK tokenizer commit) and invisible until something\ncompared the three surfaces.",
          "is_bot": false,
          "headline": "fix(sdk-go): export EstimateWith for parity with Node and Python",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T08:15:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3ea40b96387492ebf8dd890eb40c6eb8f6d92949",
          "body": "Rule 3 — a feature landing in Go lands in Node and Python next — was enforced\nby an agent remembering it, which is not a mechanism. The SSE usage bug\n(e6eba43) is what that costs: Go extracted streaming usage correctly, Node and\nPython silently did not, and nothing anywhere compared the three surfac\n[…]\nad, which is the\nsurface a Node user actually sees.\n\nNames only. Behaviour parity stays conformance/*.json's job — nothing here\nwould have caught the SSE bug, and it should not be sold as if it would.",
          "is_bot": false,
          "headline": "feat(ci): mechanize the cross-SDK parity guard (agent rule 3)",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T08:15:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ed10e0d33e38b4aa4be85af770842913d0bfde09",
          "body": "Everything else in the suite proves RateGuard is self-consistent. This proves\nit survives contact with a provider that was not built to our assumptions:\nreal usage schemas, real SSE framing, real latency.\n\nSkipped unless RATEGUARD_LIVE_BASE_URL/_API_KEY/_MODEL are set, so the default\nrun stays hermetic and offline. Verified against NVIDIA NIM free tier; any\nOpenAI-compatible endpoint works, including a local Ollama.\n\nThis is the harness that caught the single-event SSE usage bug.",
          "is_bot": false,
          "headline": "test: live provider suite — RateGuard against a real LLM API",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T07:42:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e6eba435c8266a37666c7bf695f0876365379ae4",
          "body": "Python and Node gated the SSE path on the body containing a newline, so an\nOpenAI-compatible stream whose usage rides only on the final chunk fell\nthrough to the JSON parser with the \"data: \" prefix still attached. It failed\nsilently and reported no usage, which meant the budget never decremented fo\n[…]\ns only surfaced against real\nprovider bytes. Locked with shared conformance vectors carrying captured\nNVIDIA NIM output plus the OpenAI null-usage, Anthropic split-field, and\nno-usage-anywhere shapes.",
          "is_bot": false,
          "headline": "fix: SSE usage extraction dropped usage for single-event streams",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T07:42:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3de78ea4eb148ca51de0ffb37ca61a6a7ee094a2",
          "body": "Rule 9: a feature isn't done until it's reachable. The evidence chain\nshipped exported and tested but undocumented, which for a compliance\nprimitive is worse than useless — the people who need it would never find\nit, and the ones who stumbled onto it would overclaim it.\n\nThree sections on the spend-\n[…]\nve edits on its own, a wholesale rewrite needs an\nexternally-witnessed head, \"independently verifiable\" needs an external\nkey, and none of it makes a deployment compliant.\n\nVerified: next build clean.",
          "is_bot": false,
          "headline": "docs(site): evidence chain, KMS signing, and evidence package",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T04:21:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e49d88361e98e8a3d5c47a126c68f2d2ad003ace",
          "body": "npm and PyPI were still serving 0.2.0. v0.3.0 reached the Go proxy and the\ndocs but never the other two registries, so anyone who followed the install\ninstructions got a package without the feature set the site describes. This\npublishes all three together and closes that gap.\n\nBumps sdk-node/package\n[…]\n a\n  KeySigner, exported the package, verified it, and confirmed a doctored\n  chain is rejected (\"entries missing or reordered\")\n- npm tarball installed into a clean project: same flow, same rejection",
          "is_bot": false,
          "headline": "release: cut v0.4.0 across all three SDKs",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T04:19:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f921a5a60e04e31fb223583f5cdf0787b59788e5",
          "body": "Tier 3 item 2 from the master plan: the honest Art. 12 story.\n\nA signed receipt proves one statement was not altered. It proves nothing\nabout the SET: an issuer holding its own key can drop the expensive\nreceipts, renumber what is left, and re-sign a tidier history — every\nremaining receipt still ve\n[…]\nors in semantic-loop and static-embedder tests. A gate that is always\nred hides real regressions — it nearly hid one of mine.\n\nTests: Go 225, Node 276, Python 296. Race, vet, mypy --strict, tsc clean.",
          "is_bot": false,
          "headline": "feat: evidence chain — tamper-evident spend history, external signers",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T04:15:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "214d3198b744ec9740091be68b0968feb6ed4b06",
          "body": "The static embedder loaded model files with no integrity check. The model\nis downloaded data, not a bundled dependency, so the bytes that reach the\nloader come from wherever the operator got them — a build step, an init\ncontainer, an ops runbook. Enterprise infosec flags exactly this, and we\nmarket \n[…]\nrather than silently\nweakening the load.\n\nUnverified load() stays, documented for the case where the model ships\nwith the code that loads it.\n\nTests: Go 207, Node 257, Python 276. mypy --strict clean.",
          "is_bot": false,
          "headline": "feat: pin .rgemb models by SHA-256, verify before parse",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-17T03:59:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "314b23123ce1a680d6ca3b0ab46ebe7be724b360",
          "body": "The chars/4 token heuristic in TokenLimitGuardrail undercounted Chinese,\nJapanese, and Korean prompts by ~75% — those scripts tokenize at roughly one\ntoken per character, not one per four — so a large CJK prompt slipped past a\nlimit sized in tokens. Worse, the three SDKs disagreed: Go counted bytes,\n[…]\no under-count so\nthe limit fails safe. A Tokenizer interface is the plug-in point for exact\ncounts (e.g. tiktoken); the default stays zero-dependency. Guardrails doc page\ngains a token-limits section.",
          "is_bot": false,
          "headline": "feat: CJK-aware token estimation with pluggable Tokenizer",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-11T05:18:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ae9716445e18c9923b17eaee83fcca4d1990cfbc",
          "body": "Every RateGuard intervention on an outbound call — a budget it stopped, a\nrate limit it hit, a freeze it enforced — now lands in a bounded in-process\nring buffer (cap 1000, oldest dropped). Queryable two ways with no webhook:\n\n- in-process: EnforcementEvents/enforcementEvents/enforcement_events, new\n[…]\nnce)\n\nThe pull-side audit trail behind 'where did the spend go, and when did\nenforcement fire'. Go/Node/Python parity; records wired at the frozen,\nrate_limited, and token_budget_exceeded block sites.",
          "is_bot": false,
          "headline": "feat: enforcement event audit trail across all three SDKs",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-11T04:55:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5296ef70f006934c53b85e115e122367a7831b31",
          "body": "An agent going wrong in production needs a stop button that doesn't require a\nredeploy. FreezeController halts outbound LLM calls the instant it's tripped,\nfrom inside the process: freeze everything, or freeze one customer (the same\nX-RateGuard-Customer scope) to stop a single runaway user without t\n[…]\nK covers global halt/resume, per-customer\nscoping, and observe-mode bypass; the Go test also drives the admin endpoint.\n\nVerified: Go 197 (-race), Node 247, Python 262 (mypy --strict clean, 49 files).",
          "is_bot": false,
          "headline": "feat: runtime kill switch (freeze) — halt outbound calls, all 3 SDKs",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-11T04:34:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0e27c775e74bdbde4ea8ae446db6d7acce2f5920",
          "body": "…demo asset)\n\nThe moving demo the launch needs: a real RateGuard-wrapped client burning a\ntoken budget call by call, then getting halted at the budget line, live. Zero\nAPI key, zero spend, deterministic (a local fake provider), paced for recording.\n\n- examples/runaway-demo/main.go: the scene. Defaul\n[…]\nay\n  because it's reproducible) with the GIF-drop-in marker reserved.\n\nHarsha records the GIF when back at a machine; nothing else is needed from the\nprovider side. Go vet clean, Go suite green (193).",
          "is_bot": false,
          "headline": "demo: runnable runaway-agent example + recording runbook (the launch …",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-11T00:25:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5ded5267cf6e632eb730dca0baff3e9ae7aaf664",
          "body": "Rewrite the primary conversion surfaces to a terse dev-tool voice (the\nTailscale/Stripe standard: specifics over adjectives, code over claims) and\nstrip the strongest AI-writing tell — em-dash density — from all marketing\nprose. Concrete changes:\n\n- Landing + README now lead with the real, sourced h\n[…]\nfeature-table\n  cells and journalistic incident narratives keep theirs (not marketing slop).\n- Stale test stat 689 -> 696.\n\nAntharmaya Labs attribution already correct (header + footer + og siteName).",
          "is_bot": false,
          "headline": "content: human, specific marketing voice across landing + README",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-11T00:12:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e3e4cd4a5fcae97d211a9e20300e66c4d75f23f8",
          "body": "…om response\n\nCrewAI (and many stacks) route every LLM call through litellm.completion, which\nour httpx-client wrapper can't reliably intercept: litellm's documented\nclient_session injection is provider-inconsistent (it routes some providers over\naiohttp, silently bypassing the client) — a silent en\n[…]\n wrap primitives; CrewAI was the last gap.\n\nPython-only (CrewAI is Python). INTEGRATIONS.md: robust CrewAI recipe + AutoGen\nadded. Verified: Python 259 passing (4 new), mypy --strict clean (48 files).",
          "is_bot": false,
          "headline": "feat(sdk-python): CrewAI/litellm adapter — wrap_completion, budget fr…",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-10T23:51:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fc9f7b315aa894f8ec74f17f00cf51afd351d480",
          "body": "…ovider count\n\n- Document per-customer budgets/attribution (X-RateGuard-Customer) in the\n  README feature table and a new outbound-docs section.\n- Update the pricing surfaces (README, GENAI_OBSERVABILITY, observability page)\n  to reflect PricingProvider/StaticPricing + dated-ID normalization — the\n \n[…]\ne is extended by the user, not a fixed 14-model ceiling.\n- Fix a stale count: README said '16 provider hosts' — actual is 26 hosts\n  across 23 OpenAI-compatible providers + 5 special-cased (28 total).",
          "is_bot": false,
          "headline": "docs: reflect per-customer attribution + custom pricing; fix stale pr…",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-10T23:12:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "909d421e4593b1b9cabbb99a3d74de319832e695",
          "body": "Budgets scoped only per tenant:provider:model — no end-user dimension. This\nblocked every multi-tenant/commercial use: one runaway user could exhaust the\nwhole tenant's budget, and spend couldn't be attributed per customer. It was\nthe top table-stakes gap across all cross-model competitive research.\n[…]\nest each proving per-customer isolation (one\ncustomer exhausting their budget does not block another) and header stripping.\n\nVerified: Go 193 (-race), Node 244, Python 255 (mypy --strict clean) = 692.",
          "is_bot": false,
          "headline": "feat: per-customer budget attribution and spend scoping, all 3 SDKs",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-10T23:07:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b123f213de0a1a029f810b08cf309a267044c6fc",
          "body": "The cost estimate shipped a fixed 14-model table with exact-match lookup. Two\nreal gaps: a model not in the table priced at $0, and — worse — even the 14\ntabled models priced at $0 when called by the dated IDs providers actually\nreport (gpt-4o-2024-08-06, claude-sonnet-4-5-20250929, gemini-2.5-flash\n[…]\nentical behavior, with a normalization + override test each.\nDocs: outbound page gains a 'Pricing your own models' section.\n\nVerified: Go 192 (-race), Node 243, Python 254 (mypy --strict clean) = 689.",
          "is_bot": false,
          "headline": "feat: PricingProvider — user-owned custom-model pricing, no fetched file",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-10T13:48:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b7f0fb66208425b8e47725bdd1eb5d2957a7e7d5",
          "body": "…unmeasurable\n\nA streaming response without stream_options.include_usage, a body over the\nbuffer cap, or an unrecognized provider schema yields no token count at the\nwire. The budget then recorded ZERO for that call and released the\nreservation — so a runaway agent streaming without include_usage ne\n[…]\n-cache tests that relied on unmeasured calls being free were given\nbudget headroom (they test cache behavior, not budgets).\n\nVerified: Go 189 (-race), Node 227, Python 238 (mypy --strict clean) = 654.",
          "is_bot": false,
          "headline": "fix(outbound): commit a conservative estimate when provider usage is …",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-10T09:30:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f85b29bd28550929fb0c495d4edf1c676e581c17",
          "body": null,
          "is_bot": false,
          "headline": "docs(site): add Node and Python parity tabs to guardrails page",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-10T08:56:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "98b2a532d2674dba5fcb4d9dba05afa46c7519ea",
          "body": "A fresh competitive audit showed our old comparison table was falsifiable:\nLiteLLM and Kong AI Gateway both ship token-aware LLM rate limiting today,\nand LiteLLM's proxy is HTTP-callable from any language (not 'Python only').\nA single wrong cell in an OSS comparison table costs more trust than the\nw\n[…]\n\nAlign the $47K ping-pong reference in loop-detection with the denial-of-wallet\npage's honest framing: 'reported', not 'documented' (source is a community\npost-mortem, cited as reported/not-verified).",
          "is_bot": false,
          "headline": "docs: reframe competitor comparison around architecture, not a checklist",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-10T08:51:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "065b57a200ab6705cbea979fcf59374d9e015b06",
          "body": "Remove the ShieldReveal section — a 220vh scroll driving a 3D-tilt reveal of\nan AI-generated stock shield image (hero.webp). It carried no information and\nleft two-plus screens of dead scroll. Drop the ChaosField particle field\nbehind the hero and the per-card 3D pointer-tilt in FeatureCard; the surface\nnow reads clean and typographic rather than over-produced.\n\nCorrect the stale test count 540 -> 651 (verified: 188 Go -race, 226 Node,\n237 Python).",
          "is_bot": false,
          "headline": "refactor(site): strip landing decoration for a minimal, honest hero",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-10T08:51:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6153002e6774cdef79e19dc41b655ff6b3d4924f",
          "body": "…mantic sections\n\nTwo new docs pages (/docs/realtime-voice with the honest provider-schema\nprovenance and Pipecat/LiveKit recipes; /docs/spend-receipts with\ngrant→spend→proof, integer-only payload discipline, and the\nBilledCost=0 estimates caveat), nav entries, semantic-loop section on\nthe loop-dete\n[…]\n page (7 since v0.2.0) and added 5 README capability rows\n(receipts, FOCUS, realtime voice, async webhooks). All code samples\nverified against actual exports; site build clean, both pages\nprerendered.",
          "is_bot": false,
          "headline": "docs(site): v0.3.0 feature pages — realtime voice, spend receipts, se…",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-10T07:46:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1c29e4a0a63f78b31543bd7b8db4ae726d983d0c",
          "body": "…ence Pack\n\nThe revenue research's NOW-block: validate enterprise demand before\nbuilding. One landing section stating the verified EU AI Act facts\n(Aug 2, 2026 enforcement; Art. 12 record-keeping; Art. 14 oversight),\nwhat RateGuard's receipts/chains/FOCUS export already are (technical\nevidence), wha\n[…]\nady pack mapped to EU AI\nAct / NIST AI RMF / ISO 42001), and a contact CTA. Honesty constraints\ninline: 'evidence, not certification'. No pricing published — inbound\ninterest is the validation signal.",
          "is_bot": false,
          "headline": "content(site): Enterprise demand-validation section — Compliance Evid…",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-10T07:39:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fea788081eb008ad714d62d93423b18fdbe62e5a",
          "body": "INTEGRATIONS.md gains the two voice-framework recipes with signatures\ncopied from the verified adapters (pipecat-ai 1.5.0 / livekit-agents\n1.6.5) and the honest cost-rates caveat. examples/voice-budget replays\nthe REAL captured Gemini Live frames from the conformance vectors\nthrough a RealtimeSessionGuard — zero keys, zero network, zero deps —\nand was actually run: trips at turn 3 (1179 > 1000 tokens), on_exceeded\nfires once, peek() stays read-only after the trip.",
          "is_bot": false,
          "headline": "docs+examples: Pipecat/LiveKit recipes and runnable voice-budget demo",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-10T07:37:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e9ad6de1460c6ab022947ff24241f10ceb55386c",
          "body": "Version bumps to 0.3.0 (Node package.json, Python pyproject +\n__init__.py — build backend derives from __init__, wheel verified to\nproduce varbees_rateguard-0.3.0). RELEASE_NOTES v0.3.0 section covers\nall five release features with schema-provenance honesty (Gemini\nlive-verified, OpenAI documented-s\n[…]\nand\nmeasured test counts: 188 Go funcs / 226 Node / 237 Python (~650 —\nPython count corrected after the test_key collection fix in 2e87b9e).\n\nPublish steps (npm/PyPI/go tag) remain the founder's call.",
          "is_bot": false,
          "headline": "release: cut v0.3.0 — The Enforcement Release",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-10T07:35:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2e87b9e67d36ee0a11d520e59a2704e5cd2a7609",
          "body": "test_key() is a signing-key helper, not a test, but its test_ prefix made\npytest collect it — emitting a PytestReturnNotNoneWarning because it returns\na key. Rename to signing_key() and update call sites. Suite now warning-free.",
          "is_bot": false,
          "headline": "test(sdk-python): rename test_key helper so pytest stops collecting it",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-10T07:29:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "beb69eafcae38f1ef0515e720e8267ac08b55c06",
          "body": "packages/connect is a local-only companion (gitignored, untracked) and must\nnot surface on the public repo. The v0.2.0-dev release note narrated the\nproxy pattern, the Hermes-derived origin, and internal Cursor/Claude Code\nbase-URL behaviors. Scrub it from the current notes to match the local-only\nrule.",
          "is_bot": false,
          "headline": "docs: remove packages/connect section from public release notes",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-10T07:28:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ab11ba2971857a1ed55e76788e33f9c062e3e4f3",
          "body": null,
          "is_bot": false,
          "headline": "chore: update gitignore, add Python lockfile",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-10T03:57:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "86defb16355d920cea8bb45b18ffd422ae0c67a1",
          "body": "AGENTS.md gains the adapters row (Python-only, marked n/a for Go/Node\ndeliberately — Pipecat and LiveKit Agents are Python frameworks);\nllms.txt's 'pending' note replaced with the shipped reality. User-facing\nINTEGRATIONS.md + docs-site recipes are named as landing with the v0.3.0\nrelease docs pass, not silently omitted.",
          "is_bot": false,
          "headline": "docs: voice framework adapters reflected on agent-facing surfaces",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-10T03:45:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3986e7f65090b45c9d6193395695b4af317d5535",
          "body": "The market-facing face of realtime enforcement (6613f55), implementing\nthe adversarial-research verdict: production voice runs through\nframeworks that terminate media server-side, so enforcement lives\nINSIDE the pipeline/session — not on a raw provider socket.\n\n- rateguard.integrations.pipecat_adapt\n[…]\nents 1.6.5 — API shapes read from installed source, tests run\nin an env with both installed: 4 passed). Repo env without the\nframeworks skips cleanly; mypy --strict clean on 47 files; 238 tests\ngreen.",
          "is_bot": false,
          "headline": "feat(sdk-python): Pipecat + LiveKit Agents voice adapters",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-10T03:44:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cb98eca5c17e7cbcff261d54c109ec964ee62345",
          "body": "Feature rows state schema provenance precisely (Gemini live-verified,\nOpenAI documented-schema with live check pending) and that Pipecat/\nLiveKit adapters are pending — no overclaiming. Counts from actual\nruns: 188 Go test funcs / 226 Node / 238 Python, ~650 total; mypy\n--strict 44 files.",
          "is_bot": false,
          "headline": "docs: realtime session enforcement across surfaces, counts refreshed",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-10T02:48:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a8989016f76c1e62c0407df495ddff15c69a1874",
          "body": "Port of the Go reference (5de93dc): OpenAI Realtime + Gemini Live usage\nparsers (Gemini schema live-verified 2026-07-10, per-turn semantics\nproven), per-session guard with limits on total tokens / audio tokens /\nturns / duration / caller-priced cost. Terminal on breach, onExceeded\nfires exactly once; peek is derived-only; tick for timer loops.\nConformance cases replay the REAL captured Gemini frames.\n\n226 tests green, tsc strict build clean.",
          "is_bot": false,
          "headline": "feat(sdk-node): realtime session enforcement — the voice substrate",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-10T02:48:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6613f55124cf84086dce8b03319be028e72d4cf4",
          "body": "Port of the Go reference (5de93dc): OpenAI Realtime + Gemini Live usage\nparsers (Gemini schema live-verified 2026-07-10, per-turn semantics\nproven with a two-turn session), per-session guard with limits on total\ntokens / audio tokens / turns / duration / caller-priced cost. Terminal\non breach, on_ex\n[…]\noops a mutating\ntime-observation. Conformance cases replay the REAL captured Gemini\nframes. This is the module the Pipecat/LiveKit adapters build on.\n\n238 tests green, mypy --strict clean on 44 files.",
          "is_bot": false,
          "headline": "feat(sdk-python): realtime session enforcement — the voice substrate",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-10T02:45:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5de93dc733f1e0656b046343a4cd1ce5c0406c64",
          "body": "Voice sessions are one WebSocket that can burn dollars per minute for\nhours; request-based rate limiting is structurally blind to them. This\nis the substrate the Pipecat/LiveKit adapters sit on:\n\n- realtime_usage.go: server-event usage parsers. Gemini Live schema\n  LIVE-VERIFIED today against the re\n[…]\nansport-agnostic: RateGuard never touches the socket; the integrator\nfeeds inbound frames. Works with any WS library and any framework.\n\nFull suite green with -race. Parity: Node/Python next (rule 1).",
          "is_bot": false,
          "headline": "feat(sdk-go): realtime session enforcement — the voice substrate",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-10T02:43:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "240ce38ed2e735fab3c1bb010a1d934cbde99840",
          "body": "AGENTS.md gains the two feature rows (receipts, FOCUS export) with the\nhonesty constraints inline (integer-only signing payload; BilledCost\nalways 0 — estimates, never invoice truth). llms.txt features +\nconformance list updated. Counts from actual runs: 181 Go test funcs /\n214 Node / 232 Python, ~625 total; mypy --strict 43 files.",
          "is_bot": false,
          "headline": "docs: spend receipts + FOCUS export across surfaces, counts refreshed",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-10T02:32:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "69af37925afb2e4975e52e98ac43252bbb130043",
          "body": "Port of the Go reference (5923c0f). Reuses budget attestation's KeyObject\nhelpers (privateKeyFromRaw/publicKeyToRaw); node:crypto sign/verify with\nEd25519. Signing payload byte-identical with Go's via JSON.stringify\ninsertion-order guarantee — asserted against\nconformance/spend_receipt_vectors.json at SIGNATURE level. FOCUS CSV\nmatches Go cell-for-cell (RFC-4180 escaping, \\n termination).\n\n214 tests green, tsc strict build clean.",
          "is_bot": false,
          "headline": "feat(sdk-node): spend receipts + FOCUS-aligned cost export",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-10T02:32:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3d4407083555d3c995077e47f0ec1ef746fd0d4e",
          "body": "Port of the Go reference (5923c0f). Reuses budget attestation's key\nhelpers (private_key_from_raw, lazy cryptography import — zero-core-deps\npreserved). Signing payload is byte-identical with Go's (integers and\nstrings only; compact JSON, fixed key order) — asserted against\nconformance/spend_receipt_vectors.json at SIGNATURE level, not just\npayload. FOCUS CSV matches Go cell-for-cell (%g float formatting,\n\\n line termination).\n\n232 tests green, mypy --strict clean on 43 files.",
          "is_bot": false,
          "headline": "feat(sdk-python): spend receipts + FOCUS-aligned cost export",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-10T02:32:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5923c0f09c67a8b8411c1d1a6c052096b0d75cae",
          "body": "Spend receipts close the attestation loop: budget attestation proves an\nagent was AUTHORIZED to spend; a receipt is the Ed25519-signed,\noffline-verifiable statement of what it DID spend (key, window, tokens,\nestimated cost, policy, optional attestation-token binding — full chain\nbinding lands with a\n[…]\namper detection\n(claims, issue time, wrong issuer, integrity-only mode), claim\nvalidation, CSV parses back with exact column values. Full suite green\nwith -race. Parity: Node and Python next (rule 1).",
          "is_bot": false,
          "headline": "feat(sdk-go): signed spend receipts + FOCUS-aligned cost export",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-09T14:21:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ad25c572c5c4e96e648952799fab5160916cc4ff",
          "body": "…efreshed\n\nAGENTS.md events row + llms.txt now state the async-by-default contract\n(bounded queue, non-blocking emit, drop-with-counter, drained by\nshutdown). Counts from actual runs: 175 Go test funcs / 209 Node / 226\nPython, ~610 total.",
          "is_bot": false,
          "headline": "docs: async webhook emission reflected across surfaces, test counts r…",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-09T14:06:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e45591e4142b263a461e3f547950a647e3b7dd7c",
          "body": "Port of Go's AsyncEventEmitter (4a9e13e): a bounded queue.Queue drained\nby one daemon worker thread — a thread rather than an asyncio task so\nthe same wrapper serves both ASGI and WSGI/sync call sites. emit() is\nasync-signature but returns immediately (put_nowait); overflow drops\nwith a visible .dro\n[…]\n mirror Go's SDK.Shutdown.\n\nThe pre-existing create_event_emitter test asserting a bare\nHTTPEventEmitter was updated to the new contract deliberately.\n226 tests green, mypy --strict clean on 41 files.",
          "is_bot": false,
          "headline": "feat(sdk-python): async webhook emission off the request hot path",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-09T14:05:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0cb84069f53f069a6c08e449fdfa309aa4b83741",
          "body": "Port of Go's AsyncEventEmitter (4a9e13e): the middleware used to await\nthe webhook POST (up to its 5s timeout) inside every request.\nAsyncEventEmitter wraps any emitter with a bounded FIFO (default 1024,\neventQueueSize option) and a sequential pump — emit() enqueues and\nresolves immediately, overflo\n[…]\nshutdown() mirrors\nGo's SDK.Shutdown.\n\nThe pre-existing createEventEmitter test asserting a bare\nHTTPEventEmitter was updated to the new contract deliberately. 209\ntests green, tsc strict build clean.",
          "is_bot": false,
          "headline": "feat(sdk-node): async webhook emission off the request hot path",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-09T14:00:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4a9e13e0d11ee8409e038b1bf3905adccf9f94c2",
          "body": "Closes the long-deferred debt: HTTPEventEmitter used to post\nsynchronously inside every request (up to its 5s timeout), using the\nrequest's own context — so a canceled request also canceled its event\ndelivery. AsyncEventEmitter wraps any EventEmitter with a bounded queue\n(default 1024, Config.EventQ\n[…]\n delivers; queue overflow drops exactly\nthe overflow; Close times out honestly and a later Close observes the\ndrain. Full suite green with -race.\n\nParity: Node and Python in the next commits (rule 1).",
          "is_bot": false,
          "headline": "feat(sdk-go): async webhook emission off the request hot path",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-09T13:52:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a4d05b7731ea713bf0610c5cd2f8036eee31a1c7",
          "body": "AGENTS.md feature rows (explicitly marked 'public primitive, NOT yet\nwired into middleware' — no overclaiming), README capability rows,\nllms.txt features + both copies synced. Test counts updated from actual\nruns: 169 Go test funcs / 202 Node / 219 Python, ~590 total, mypy\n--strict now 41 files. Conformance suite list gains\nstatic_embedding_vectors.json (generated from the reference model2vec\nlibrary, not from our own code).",
          "is_bot": false,
          "headline": "docs: static embedder + semantic loop detection across all surfaces",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-09T13:44:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d3d14a130aeab62fc8c4b668aa7e62d3895456df",
          "body": "Port of the Go reference (7812dee): StaticEmbedder loads .rgemb models\nwith Node stdlib only (Buffer + String.normalize NFD + Unicode property\nregexes), implements the Embedder interface; SemanticLoopDetector\nmirrors the calibrated defaults (threshold 0.90, window 8, minRepeats 2)\nwith check/peek sp\n[…]\nests green (23 new), tsc strict build clean\n(noUncheckedIndexedAccess), golden conformance passes against the real\npotion-base-2M model, loop reproduction trips with all-distinct SHA-256\nfingerprints.",
          "is_bot": false,
          "headline": "feat(sdk-node): static embedder + semantic loop detection",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-09T13:42:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4988869fd235ae26d6ed998780e99eed36602a97",
          "body": "Port of the Go reference (7812dee), idiomatic to the async Embedder\nprotocol: StaticEmbedder loads .rgemb models with pure stdlib (struct,\njson, unicodedata for NFD), embed() satisfies the async protocol with an\nembed_sync() escape hatch; SemanticLoopDetector mirrors the calibrated\ndefaults (thresho\n[…]\n (token\nids exact vs the reference HF tokenizer, embeddings within 1e-4 of\nmodel2vec output), and the $47K-shape reworded ping-pong reproduction\ntrips at step 4 with all-distinct SHA-256 fingerprints.",
          "is_bot": false,
          "headline": "feat(sdk-python): static embedder + semantic loop detection",
          "author_name": "varbees",
          "author_login": "varbees",
          "committed_at": "2026-07-09T13:42:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        }
      ],
      "releases_count": 1,
      "commits_last_year": 326,
      "latest_release_at": "2026-05-16T15:29:33Z",
      "latest_release_tag": "v0.1.0",
      "releases_from_tags": false,
      "days_since_last_push": 5,
      "active_weeks_last_year": 9,
      "days_since_latest_release": 68,
      "mean_days_between_releases": null
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 42,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/varbees/rateguard/packages/sdk-go",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/varbees/rateguard/packages/sdk-go",
          "is_deprecated": false,
          "latest_version": "v0.5.1",
          "repository_url": "https://github.com/varbees/rateguard",
          "versions_count": 4,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-18T07:24:07Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        },
        {
          "name": "@varbees/rateguard-node",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "rate-limiting",
            "middleware",
            "llm",
            "token-budget",
            "api-protection"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@varbees/rateguard-node",
          "is_deprecated": false,
          "latest_version": "0.5.1",
          "repository_url": "https://github.com/varbees/rateguard",
          "versions_count": 4,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 324,
          "first_published_at": "2026-05-16T15:06:15.058000Z",
          "latest_published_at": "2026-07-18T07:39:14.959000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        },
        {
          "name": "varbees-rateguard",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "pypi",
          "matches_repo": true,
          "registry_url": "https://pypi.org/project/varbees-rateguard/",
          "is_deprecated": false,
          "latest_version": "0.5.1",
          "repository_url": "https://github.com/varbees/rateguard",
          "versions_count": 4,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": "2026-05-16T15:13:44.688418Z",
          "latest_published_at": "2026-07-18T07:31:29.610330Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0,
        "collected_at": null
      },
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": true,
      "has_dockerfile": true,
      "has_mcp_signal": true,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "packages/dashboard/tsconfig.json",
        "packages/sdk-node/tsconfig.json",
        "packages/sdk-python/rateguard/py.typed",
        "site/tsconfig.json"
      ],
      "toolchain_manifests": [
        "packages/sdk-go/go.mod"
      ],
      "largest_source_bytes": 41728,
      "source_files_sampled": 360,
      "oversized_source_files": 0,
      "agent_instruction_files": [
        "AGENTS.md"
      ],
      "agent_instruction_max_bytes": 14911
    },
    "dependencies": {
      "manifests": [
        "site/package.json"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "@opennextjs/cloudflare",
          "manifest": "site/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.20.0"
        },
        {
          "name": "framer-motion",
          "manifest": "site/package.json",
          "ecosystem": "npm",
          "version_constraint": "^12.23.24"
        },
        {
          "name": "motion-dom",
          "manifest": "site/package.json",
          "ecosystem": "npm",
          "version_constraint": "12.23.23"
        },
        {
          "name": "motion-utils",
          "manifest": "site/package.json",
          "ecosystem": "npm",
          "version_constraint": "12.23.6"
        },
        {
          "name": "next",
          "manifest": "site/package.json",
          "ecosystem": "npm",
          "version_constraint": "^15.4.9"
        },
        {
          "name": "react",
          "manifest": "site/package.json",
          "ecosystem": "npm",
          "version_constraint": "^19.2.1"
        },
        {
          "name": "react-dom",
          "manifest": "site/package.json",
          "ecosystem": "npm",
          "version_constraint": "^19.2.1"
        },
        {
          "name": "shiki",
          "manifest": "site/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.3.1"
        },
        {
          "name": "@base-ui/react",
          "manifest": "packages/dashboard/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.6.0"
        },
        {
          "name": "class-variance-authority",
          "manifest": "packages/dashboard/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.7.1"
        },
        {
          "name": "clsx",
          "manifest": "packages/dashboard/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.1.1"
        },
        {
          "name": "lucide-react",
          "manifest": "packages/dashboard/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.23.0"
        },
        {
          "name": "motion",
          "manifest": "packages/dashboard/package.json",
          "ecosystem": "npm",
          "version_constraint": "^12.42.2"
        },
        {
          "name": "next",
          "manifest": "packages/dashboard/package.json",
          "ecosystem": "npm",
          "version_constraint": "^15.4.9"
        },
        {
          "name": "next-themes",
          "manifest": "packages/dashboard/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.4.6"
        },
        {
          "name": "react",
          "manifest": "packages/dashboard/package.json",
          "ecosystem": "npm",
          "version_constraint": "^19.2.1"
        },
        {
          "name": "react-dom",
          "manifest": "packages/dashboard/package.json",
          "ecosystem": "npm",
          "version_constraint": "^19.2.1"
        },
        {
          "name": "recharts",
          "manifest": "packages/dashboard/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.9.2"
        },
        {
          "name": "shadcn",
          "manifest": "packages/dashboard/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.13.0"
        },
        {
          "name": "sonner",
          "manifest": "packages/dashboard/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.0.7"
        },
        {
          "name": "tailwind-merge",
          "manifest": "packages/dashboard/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.6.0"
        },
        {
          "name": "tw-animate-css",
          "manifest": "packages/dashboard/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.4.0"
        },
        {
          "name": "github.com/redis/go-redis/v9",
          "manifest": "packages/sdk-go/go.mod",
          "ecosystem": "go",
          "version_constraint": "v9.17.0"
        },
        {
          "name": "go.opentelemetry.io/otel",
          "manifest": "packages/sdk-go/go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc",
          "manifest": "packages/sdk-go/go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.39.0"
        },
        {
          "name": "go.opentelemetry.io/otel/metric",
          "manifest": "packages/sdk-go/go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/sdk",
          "manifest": "packages/sdk-go/go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/sdk/metric",
          "manifest": "packages/sdk-go/go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/trace",
          "manifest": "packages/sdk-go/go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "golang.org/x/text",
          "manifest": "packages/sdk-go/go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.36.0"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 3,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 1
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "varbees",
          "commits": 325,
          "avatar_url": "https://avatars.githubusercontent.com/u/73575236?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "release.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum",
        "package-lock.json",
        "uv.lock"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 10,
            "reason": "project is fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 10,
            "reason": "GitHub workflow tokens follow principle of least privilege",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "27 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "031443ff4fc21f6deec11f3ccf2618e55c129db7",
        "ran_at": "2026-07-23T18:09:55Z",
        "aggregate_score": 4.7,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-18T18:27:07Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-04T09:30:30Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/varbees/rateguard",
    "host": "github.com",
    "name": "rateguard",
    "owner": "varbees"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 55,
      "inputs": {
        "security": 47,
        "vitality": 76,
        "community": 28,
        "governance": 46,
        "engineering": 72
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 76,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 70,
            "inputs": {
              "commits_last_year": 326,
              "human_commit_share": 1,
              "days_since_last_push": 5,
              "active_weeks_last_year": 9
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "9/52 weeks with commits",
                "points": 6.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 9
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "326 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 326
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "good",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 84,
            "inputs": {
              "releases_count": 1,
              "latest_release_tag": "v0.1.0",
              "releases_from_tags": false,
              "days_since_latest_release": 68,
              "mean_days_between_releases": null
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "1 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 68 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 68
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "cadence unknown (single release)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "release_cadence_unknown",
                    "params": {}
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 5,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 5 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 28,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "at_risk",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 42,
            "inputs": {
              "packages": [
                "github.com/varbees/rateguard/packages/sdk-go",
                "@varbees/rateguard-node",
                "varbees-rateguard"
              ],
              "dependents": null,
              "ecosystems": "go, npm, pypi",
              "total_downloads": null,
              "monthly_downloads": 324
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "324 downloads/month across go, npm, pypi",
                "points": 33.5,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 324,
                      "ecosystems": "go, npm, pypi"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 46,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "moderate",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 54,
            "inputs": {
              "merged_prs": 3,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 1
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "3/4 decided PRs merged",
                "points": 28.7,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 3,
                      "decided": 4
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 46,
            "inputs": {
              "followers": 3,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "varbees",
              "public_repos": 35,
              "account_age_days": 2094
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "3 followers of varbees",
                "points": 4.3,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 3,
                      "login": "varbees"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "35 public repos, account ~5 yr old",
                "points": 22.8,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 35
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 5
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "packages": [
                "github.com/varbees/rateguard/packages/sdk-go",
                "@varbees/rateguard-node",
                "varbees-rateguard"
              ],
              "ecosystems": "go, npm, pypi",
              "any_deprecated": false,
              "min_days_since_publish": 5
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "3 package(s) on go, npm, pypi",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 3,
                      "ecosystems": "go, npm, pypi"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 5 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "4 published versions",
                "points": 12,
                "status": "partial",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 72,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 60,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "2 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": "https://rateguard.antharmaya.com",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://rateguard.antharmaya.com",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 47,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 47,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 4.7
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is fuzzed",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "GitHub workflow tokens follow principle of least privilege",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "27 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 76,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "has_llms_txt": true,
              "legible_history_share": 1,
              "agent_instruction_files": [
                "AGENTS.md"
              ],
              "agent_instruction_max_bytes": 14911
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "AGENTS.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "AGENTS.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": "llms.txt present",
                "points": 15,
                "status": "met",
                "details": [
                  {
                    "code": "llms_txt_present",
                    "params": {}
                  }
                ],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "100 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 100,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 56,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum",
                "package-lock.json",
                "uv.lock"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "packages/dashboard/tsconfig.json",
                "packages/sdk-node/tsconfig.json",
                "packages/sdk-python/rateguard/py.typed",
                "site/tsconfig.json"
              ],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "packages/sdk-go/go.mod"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "packages/sdk-go/go.mod (toolchain convention, no task runner)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "toolchain_convention",
                    "params": {
                      "files": "packages/sdk-go/go.mod"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "packages/dashboard/tsconfig.json, packages/sdk-node/tsconfig.json, packages/sdk-python/rateguard/py.typed, site/tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "packages/dashboard/tsconfig.json, packages/sdk-node/tsconfig.json, packages/sdk-python/rateguard/py.typed, site/tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 41728,
              "source_files_sampled": 360,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/360 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 360,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "moderate",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": true,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
    "deps.dev does not index npm:@varbees/rateguard-node@0.5.1; advisories assessed against the repository dependency graph instead"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-23T18:10:02.678835Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/v/varbees/rateguard.svg",
  "full_name": "varbees/rateguard",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsGo, npm, PyPI.