Public record
Software health reportschema 0.26.0 · metrics 1.13.0 · 2026-07-22 18:55 UTC

zylos-ai / zylos-core

🐙 Give your AI a life — open-source agent infrastructure for team collaboration.

JavaScriptMIT★ 1,136 stars⑂ 119 forkssince Feb 2026View on GitHub ↗

zylos-ai/zylos-core holds a health index of 68 out of 100, placing it in the Moderate band. It scores highest on Vitality (89/100) and lowest on Sustainability & Governance (55/100). It was last updated 2 days ago. A single contributor accounts for most of its recent work.

68
overall / 100
Moderate

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

68
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

Zylos-AIOrganization
115 followers36 public repossince Jan 2026

This repository is backed by an organization — shared, accountable stewardship that can outlive any single maintainer.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publish
npmweb-console0.0.06513998 days ago

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

89Excellent · 22% of overall
How it's scored
36/36Push recency — last push 2 days ago
16.6/36Commit cadence — 24/52 weeks with commits
18/18Commit volume — 588 commits in the last year
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year588
human_commit_share1
days_since_last_push2
active_weeks_last_year24

Release discipline

100Excellent
How it's scored
27/27Ships releases — 50 releases published
36/36Release recency — latest release 8 days ago
27/27Release cadence — a release every ~12 days
0/10OpenSSF Scorecard: Signed-Releases — no data
Inputs used
releases_count50
latest_release_tagv0.6.0
releases_from_tagsno
days_since_latest_release8
mean_days_between_releases12
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

70Good · 18% of overall
How it's scored
49.6/60Stars — 1,136 stars
17.3/25Forks — 119 forks
10.1/15Watchers — 66 watchers
Inputs used
forks119
stars1,136
watchers66
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

Community health

92Excellent
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (MIT)
18/18CONTRIBUTING guide
13.5/13.5Code of conduct
0/7.2Issue template
6.3/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingyes
has_issue_templateno
has_code_of_conductyes
has_pull_request_templateyes
How it's scored
24.3/80Monthly downloads — 65 downloads/month across npm
0/20Registry dependents — not reported by this ecosystem
Inputs used
packagesweb-console
dependents
ecosystemsnpm
total_downloads
monthly_downloads65
Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

55Moderate · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
10.4/22.5Commit distribution — top contributor authored 54% of commits
13.5/13.5Contributor breadth — 19 contributors
3/10OpenSSF Scorecard: Contributors — project has 1 contributing companies or organizations -- score normalized to 3
Inputs used
bus_factor1
contributors_sampled19
top_contributor_share0.538
How it's scored
27.6/46.8Issue resolution — 59% of issues closed
34.5/38.3PR acceptance — 374/415 decided PRs merged
15/15OpenSSF Scorecard: Code-Review — all changesets reviewed
Inputs used
merged_prs374
open_issues103
closed_issues149
issue_closed_ratio0.591
closed_unmerged_prs41
How it's scored
30/30Ownership backing — organization-owned
0/20Verified domain
14.8/25Owner reach — 115 followers of zylos-ai
12.5/25Track record — 36 public repos, account ~0 yr old
Inputs used
followers115
owner_typeOrganization
is_verified
owner_loginzylos-ai
public_repos36
account_age_days191
How it's scored
25/25Published & resolvable — 1 package(s) on npm
4/35Publish recency — latest publish 3,998 days ago
4/20Version history — 1 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packagesweb-console
ecosystemsnpm
any_deprecatedno
min_days_since_publish3,998

Engineering Quality

Are baseline engineering and documentation practices in place?

65Moderate · 20% of overall
How it's scored
24/24CI workflows — 1 workflow(s)
24/24Tests present
0/16Linter config
0/9.6Pre-commit hooks
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — 0 out of 30 merged PRs checked by a CI test -- score normalized to 0
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configno
has_precommit_configno

Documentation

90Excellent
How it's scored
30/30README
25/25Documentation directory
15/15Documentation / homepage site — https://zylos.ai
10/10Repository description
10/10Topics — 6 topics
0/10Wiki
Inputs used
topicsai, ai-worker, own-your-data, personal-ai-assistant, self-evolving, team-collaboration
has_wikino
homepagehttps://zylos.ai
has_readmeyes
has_docs_diryes
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

62Moderate · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
4.5/7.5Branch-Protection — branch protection is not maximal on development and all release branches
0/2.5CI-Tests — 0 out of 30 merged PRs checked by a CI test -- score normalized to 0
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
7.5/7.5Code-Review — all changesets reviewed
0.8/2.5Contributors — project has 1 contributing companies or organizations -- score normalized to 3
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — no data
6.8/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
2.2/7.5Vulnerabilities — 7 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate6.1
Excluded from scoring (no data or not applicable): signed_releases. Remaining weights renormalized.
How it's scored
10.2/35Direct dependencies free of known advisories — 3 affected: js-yaml 3.14.2 (high 7.5), js-yaml 4.1.1 (high 7.5), multer 2.1.1 (high 7.5)
0/25Indirect dependencies free of known advisories — transitive set not separable from development and test dependencies in this scope
40/40No advisories left outstanding — no advisory has been public longer than 90 days
Inputs used
sourceosv
advisories10
affected_packages7
assessed_packages413
unassessed_packages0
affected_by_severityhigh 5, low 2
direct_affected_packages3
Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories. Remaining weights renormalized. Matched 413 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

56Moderate · 0% of overall
How it's scored
45/45Agent instructions — CLAUDE.md
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 99 of 100 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share0.99
agent_instruction_filesCLAUDE.md
agent_instruction_max_bytes6,158
How it's scored
0/18One-command bootstrap
22/22Automated tests
0/11Lint / format config
0/11Static type checking
10/10Reproducible environment — Dockerfile, lockfile
10/10Demonstrated agent practice — 62 of the last 100 commits agent-authored or agent-credited
0/8Automated maintenance — no automated dependency updates observed
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Inputs used
has_nixno
has_testsyes
lockfilespackage-lock.json
has_dockerfileyes
typed_languageno
bootstrap_files
has_devcontainerno
has_linter_configno
typecheck_configs
agent_commit_share0.62
toolchain_manifests
dependency_bot_commit_share0
How it's scored
0/45Type-checkable code — JavaScript without a type-check config
54/55Manageable file sizes — 4/229 source files over 60KB
Inputs used
primary_languageJavaScript
largest_source_bytes124,245
source_files_sampled229
oversized_source_files4
How it's scored
0/40API schema (OpenAPI/GraphQL/proto)
0/20MCP server
40/40Runnable examples — examples
Inputs used
example_dirsexamples
has_mcp_signalno
api_schema_files

Key facts

1,136GitHub stars
19contributors
588commits, last 12 months
2days since last push
50releases
1bus factor
103open issues
npmpackage ecosystems

Data collection warnings

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • Could not fetch npm package 'zylos' from its registry
  • Could not fetch npm package 'zylos-scheduler-v2' from its registry
  • Could not fetch npm package 'comm-bridge' from its registry
  • Could not fetch npm package 'zylos-memory' from its registry

More detail

Star and fork history 0 ★ / 119 ⇿
0Stars
119Forks
46Releases

When each star and fork was added, collected from GitHub and bucketed by day. Cumulative growth sits directly above the daily additions it is made of, so the two read against each other: steady organic accretion looks nothing like an abrupt, short-lived burst. Where that difference is measurable, it is reported as growth authenticity.

02040608010012011962026-022026-042026-07
Major 0Minor 6Patch 39
OpenSSF Scorecard 6.1 / 10
6.1aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-22 18:54 UTC

10Binary-Artifactsno binaries found in the repo
6Branch-Protectionbranch protection is not maximal on development and all release branches
0CI-Tests0 out of 30 merged PRs checked by a CI test -- score normalized to 0
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
10Code-Reviewall changesets reviewed
3Contributorsproject has 1 contributing companies or organizations -- score normalized to 3
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
10Security-Policysecurity policy file detected
n/aSigned-Releasesno releases found
9Token-Permissionsdetected GitHub workflow tokens with excessive permissions
3Vulnerabilities7 existing vulnerabilities detected
Direct dependencies 15
RegistryPackageVersion constraintManifest
npmdotenv^16.4.7package.json
npmjs-yaml^4.1.1package.json
npmsmol-toml^1.6.1package.json
npmdotenv^16.6.1skills/activity-monitor/package.json
npmbetter-sqlite3^12.6.2skills/comm-bridge/package.json
npmbetter-sqlite3^12.6.2skills/scheduler/package.json
npmchrono-node^2.7.7skills/scheduler/package.json
npmcron-parser^4.9.0skills/scheduler/package.json
npmdotenv^16.6.1skills/scheduler/package.json
npmbetter-sqlite3^12.6.2skills/web-console/package.json
npmdotenv^16.6.1skills/web-console/package.json
npmexpress^4.18.2skills/web-console/package.json
npmmulter^2.1.1skills/web-console/package.json
npmws^8.20.1skills/web-console/package.json
npmdotenv^16.6.1skills/zylos-memory/package.json
All dependencies 413

Full resolved dependency set from the GitHub dependency graph: 10 direct and 403 indirect (transitive) packages. The transitive closure is complete when the repository commits a lockfile.

RegistryPackageVersionRelation
npmbetter-sqlite312.6.2direct
npmchrono-node2.9.0direct
npmcron-parser4.9.0direct
npmdotenv16.6.1direct
npmexpress4.22.1direct
npmjs-yaml3.14.2direct
npmjs-yaml4.1.1direct
npmmulter2.1.1direct
npmsmol-toml1.6.1direct
npmws8.21.0direct
npm@babel/code-frame7.29.0indirect
npm@babel/compat-data7.29.0indirect
npm@babel/core7.29.0indirect
npm@babel/generator7.29.1indirect
npm@babel/helper-compilation-targets7.28.6indirect
npm@babel/helper-globals7.28.0indirect
npm@babel/helper-module-imports7.28.6indirect
npm@babel/helper-module-transforms7.28.6indirect
npm@babel/helper-plugin-utils7.28.6indirect
npm@babel/helper-string-parser7.27.1indirect
npm@babel/helper-validator-identifier7.28.5indirect
npm@babel/helper-validator-option7.27.1indirect
npm@babel/helpers7.29.2indirect
npm@babel/parser7.29.2indirect
npm@babel/plugin-syntax-async-generators7.8.4indirect
npm@babel/plugin-syntax-bigint7.8.3indirect
npm@babel/plugin-syntax-class-properties7.12.13indirect
npm@babel/plugin-syntax-class-static-block7.14.5indirect
npm@babel/plugin-syntax-import-attributes7.28.6indirect
npm@babel/plugin-syntax-import-meta7.10.4indirect
npm@babel/plugin-syntax-json-strings7.8.3indirect
npm@babel/plugin-syntax-jsx7.28.6indirect
npm@babel/plugin-syntax-logical-assignment-operators7.10.4indirect
npm@babel/plugin-syntax-nullish-coalescing-operator7.8.3indirect
npm@babel/plugin-syntax-numeric-separator7.10.4indirect
npm@babel/plugin-syntax-object-rest-spread7.8.3indirect
npm@babel/plugin-syntax-optional-catch-binding7.8.3indirect
npm@babel/plugin-syntax-optional-chaining7.8.3indirect
npm@babel/plugin-syntax-private-property-in-object7.14.5indirect
npm@babel/plugin-syntax-top-level-await7.14.5indirect
npm@babel/plugin-syntax-typescript7.28.6indirect
npm@babel/template7.28.6indirect
npm@babel/traverse7.29.0indirect
npm@babel/types7.29.0indirect
npm@bcoe/v8-coverage0.2.3indirect
npm@emnapi/core1.9.1indirect
npm@emnapi/runtime1.9.1indirect
npm@emnapi/wasi-threads1.2.0indirect
npm@isaacs/cliui8.0.2indirect
npm@istanbuljs/load-nyc-config1.1.0indirect
npm@istanbuljs/schema0.1.3indirect
npm@jest/console30.3.0indirect
npm@jest/core30.3.0indirect
npm@jest/diff-sequences30.3.0indirect
npm@jest/environment30.3.0indirect
npm@jest/expect30.3.0indirect
npm@jest/expect-utils30.3.0indirect
npm@jest/fake-timers30.3.0indirect
npm@jest/get-type30.1.0indirect
npm@jest/globals30.3.0indirect
npm@jest/pattern30.0.1indirect
npm@jest/reporters30.3.0indirect
npm@jest/schemas30.0.5indirect
npm@jest/snapshot-utils30.3.0indirect
npm@jest/source-map30.0.1indirect
npm@jest/test-result30.3.0indirect
npm@jest/test-sequencer30.3.0indirect
npm@jest/transform30.3.0indirect
npm@jest/types30.3.0indirect
npm@jridgewell/gen-mapping0.3.13indirect
npm@jridgewell/remapping2.3.5indirect
npm@jridgewell/resolve-uri3.1.2indirect
npm@jridgewell/sourcemap-codec1.5.5indirect
npm@jridgewell/trace-mapping0.3.31indirect
npm@napi-rs/wasm-runtime0.2.12indirect
npm@pkgjs/parseargs0.11.0indirect
npm@pkgr/core0.2.9indirect
npm@sinclair/typebox0.34.48indirect
npm@sinonjs/commons3.0.1indirect
npm@sinonjs/fake-timers15.1.1indirect
npm@tybys/wasm-util0.10.1indirect
npm@types/babel__core7.20.5indirect
npm@types/babel__generator7.27.0indirect
npm@types/babel__template7.4.4indirect
npm@types/babel__traverse7.28.0indirect
npm@types/istanbul-lib-coverage2.0.6indirect
npm@types/istanbul-lib-report3.0.3indirect
npm@types/istanbul-reports3.0.4indirect
npm@types/node25.5.0indirect
npm@types/stack-utils2.0.3indirect
npm@types/yargs17.0.35indirect
npm@types/yargs-parser21.0.3indirect
npm@ungap/structured-clone1.3.0indirect
npm@unrs/resolver-binding-android-arm-eabi1.11.1indirect
npm@unrs/resolver-binding-android-arm641.11.1indirect
npm@unrs/resolver-binding-darwin-arm641.11.1indirect
npm@unrs/resolver-binding-darwin-x641.11.1indirect
npm@unrs/resolver-binding-freebsd-x641.11.1indirect
npm@unrs/resolver-binding-linux-arm-gnueabihf1.11.1indirect
npm@unrs/resolver-binding-linux-arm-musleabihf1.11.1indirect
npm@unrs/resolver-binding-linux-arm64-gnu1.11.1indirect
npm@unrs/resolver-binding-linux-arm64-musl1.11.1indirect
npm@unrs/resolver-binding-linux-ppc64-gnu1.11.1indirect
npm@unrs/resolver-binding-linux-riscv64-gnu1.11.1indirect
npm@unrs/resolver-binding-linux-riscv64-musl1.11.1indirect
npm@unrs/resolver-binding-linux-s390x-gnu1.11.1indirect
npm@unrs/resolver-binding-linux-x64-gnu1.11.1indirect
npm@unrs/resolver-binding-linux-x64-musl1.11.1indirect
npm@unrs/resolver-binding-wasm32-wasi1.11.1indirect
npm@unrs/resolver-binding-win32-arm64-msvc1.11.1indirect
npm@unrs/resolver-binding-win32-ia32-msvc1.11.1indirect
npm@unrs/resolver-binding-win32-x64-msvc1.11.1indirect
npmaccepts1.3.8indirect
npmansi-escapes4.3.2indirect
npmansi-regex5.0.1indirect
npmansi-regex6.2.2indirect
npmansi-styles4.3.0indirect
npmansi-styles5.2.0indirect
npmansi-styles6.2.3indirect
npmanymatch3.1.3indirect
npmappend-field1.0.0indirect
npmargparse1.0.10indirect
npmargparse2.0.1indirect
npmarray-flatten1.1.1indirect
npmbabel-jest30.3.0indirect
npmbabel-plugin-istanbul7.0.1indirect
npmbabel-plugin-jest-hoist30.3.0indirect
npmbabel-preset-current-node-syntax1.2.0indirect
npmbabel-preset-jest30.3.0indirect
npmbalanced-match1.0.2indirect
npmbase64-js1.5.1indirect
npmbaseline-browser-mapping2.10.11indirect
npmbindings1.5.0indirect
npmbl4.1.0indirect
npmbody-parser1.20.4indirect
npmbrace-expansion1.1.13indirect
npmbrace-expansion2.0.3indirect
npmbrowserslist4.28.1indirect
npmbser2.1.1indirect
npmbuffer5.7.1indirect
npmbuffer-from1.1.2indirect
npmbusboy1.6.0indirect
npmbytes3.1.2indirect
npmcall-bind-apply-helpers1.0.2indirect
npmcall-bound1.0.4indirect
npmcallsites3.1.0indirect
npmcamelcase5.3.1indirect
npmcamelcase6.3.0indirect
npmcaniuse-lite1.0.30001781indirect
npmchalk4.1.2indirect
npmchar-regex1.0.2indirect
npmchownr1.1.4indirect
npmci-info4.4.0indirect
npmcjs-module-lexer2.2.0indirect
npmcliui8.0.1indirect
npmco4.6.0indirect
npmcollect-v8-coverage1.0.3indirect
npmcolor-convert2.0.1indirect
npmcolor-name1.1.4indirect
npmconcat-map0.0.1indirect
npmconcat-stream2.0.0indirect
npmcontent-disposition0.5.4indirect
npmcontent-type1.0.5indirect
npmconvert-source-map2.0.0indirect
npmcookie0.7.2indirect
npmcookie-signature1.0.7indirect
npmcross-spawn7.0.6indirect
npmdebug2.6.9indirect
npmdebug4.4.3indirect
npmdecompress-response6.0.0indirect
npmdedent1.7.2indirect
npmdeep-extend0.6.0indirect
npmdeepmerge4.3.1indirect
npmdepd2.0.0indirect
npmdestroy1.2.0indirect
npmdetect-libc2.1.2indirect
npmdetect-newline3.1.0indirect
npmdunder-proto1.0.1indirect
npmeastasianwidth0.2.0indirect
npmee-first1.1.1indirect
npmelectron-to-chromium1.5.328indirect
npmemittery0.13.1indirect
npmemoji-regex8.0.0indirect
npmemoji-regex9.2.2indirect
npmencodeurl2.0.0indirect
npmend-of-stream1.4.5indirect
npmerror-ex1.3.4indirect
npmes-define-property1.0.1indirect
npmes-errors1.3.0indirect
npmes-object-atoms1.1.1indirect
npmescalade3.2.0indirect
npmescape-html1.0.3indirect
npmescape-string-regexp2.0.0indirect
npmesprima4.0.1indirect
npmetag1.8.1indirect
npmexeca5.1.1indirect
npmexit-x0.2.2indirect
npmexpand-template2.0.3indirect
npmexpect30.3.0indirect
npmfast-json-stable-stringify2.1.0indirect
npmfb-watchman2.0.2indirect
npmfile-uri-to-path1.0.0indirect
npmfinalhandler1.3.2indirect
npmfind-up4.1.0indirect
npmforeground-child3.3.1indirect
npmforwarded0.2.0indirect
npmfresh0.5.2indirect
npmfs-constants1.0.0indirect
npmfs.realpath1.0.0indirect
npmfsevents2.3.3indirect
npmfunction-bind1.1.2indirect
npmgensync1.0.0-beta.2indirect
npmget-caller-file2.0.5indirect
npmget-intrinsic1.3.0indirect
npmget-package-type0.1.0indirect
npmget-proto1.0.1indirect
npmget-stream6.0.1indirect
npmgithub-from-package0.0.0indirect
npmglob10.5.0indirect
npmglob7.2.3indirect
npmgopd1.2.0indirect
npmgraceful-fs4.2.11indirect
npmhas-flag4.0.0indirect
npmhas-symbols1.1.0indirect
npmhasown2.0.2indirect
npmhtml-escaper2.0.2indirect
npmhttp-errors2.0.1indirect
npmhuman-signals2.1.0indirect
npmiconv-lite0.4.24indirect
npmieee7541.2.1indirect
npmimport-local3.2.0indirect
npmimurmurhash0.1.4indirect
npminflight1.0.6indirect
npminherits2.0.4indirect
npmini1.3.8indirect
npmipaddr.js1.9.1indirect
npmis-arrayish0.2.1indirect
npmis-fullwidth-code-point3.0.0indirect
npmis-generator-fn2.1.0indirect
npmis-stream2.0.1indirect
npmisexe2.0.0indirect
npmistanbul-lib-coverage3.2.2indirect
npmistanbul-lib-instrument6.0.3indirect
npmistanbul-lib-report3.0.1indirect
npmistanbul-lib-source-maps5.0.6indirect
npmistanbul-reports3.2.0indirect
npmjackspeak3.4.3indirect
npmjest30.3.0indirect
npmjest-changed-files30.3.0indirect
npmjest-circus30.3.0indirect
npmjest-cli30.3.0indirect
npmjest-config30.3.0indirect
npmjest-diff30.3.0indirect
npmjest-docblock30.2.0indirect
npmjest-each30.3.0indirect
npmjest-environment-node30.3.0indirect
npmjest-haste-map30.3.0indirect
npmjest-leak-detector30.3.0indirect
npmjest-matcher-utils30.3.0indirect
npmjest-message-util30.3.0indirect
npmjest-mock30.3.0indirect
npmjest-pnp-resolver1.2.3indirect
npmjest-regex-util30.0.1indirect
npmjest-resolve30.3.0indirect
npmjest-resolve-dependencies30.3.0indirect
npmjest-runner30.3.0indirect
npmjest-runtime30.3.0indirect
npmjest-snapshot30.3.0indirect
npmjest-util30.3.0indirect
npmjest-validate30.3.0indirect
npmjest-watcher30.3.0indirect
npmjest-worker30.3.0indirect
npmjs-tokens4.0.0indirect
npmjsesc3.1.0indirect
npmjson-parse-even-better-errors2.3.1indirect
npmjson52.2.3indirect
npmleven3.1.0indirect
npmlines-and-columns1.2.4indirect
npmlocate-path5.0.0indirect
npmlru-cache10.4.3indirect
npmlru-cache5.1.1indirect
npmluxon3.7.2indirect
npmmake-dir4.0.0indirect
npmmakeerror1.0.12indirect
npmmath-intrinsics1.1.0indirect
npmmedia-typer0.3.0indirect
npmmerge-descriptors1.0.3indirect
npmmerge-stream2.0.0indirect
npmmethods1.1.2indirect
npmmime1.6.0indirect
npmmime-db1.52.0indirect
npmmime-types2.1.35indirect
npmmimic-fn2.1.0indirect
npmmimic-response3.1.0indirect
npmminimatch3.1.5indirect
npmminimatch9.0.9indirect
npmminimist1.2.8indirect
npmminipass7.1.3indirect
npmmkdirp-classic0.5.3indirect
npmms2.0.0indirect
npmms2.1.3indirect
npmnapi-build-utils2.0.0indirect
npmnapi-postinstall0.3.4indirect
npmnatural-compare1.4.0indirect
npmnegotiator0.6.3indirect
npmnode-abi3.87.0indirect
npmnode-int640.4.0indirect
npmnode-releases2.0.36indirect
npmnormalize-path3.0.0indirect
npmnpm-run-path4.0.1indirect
npmobject-inspect1.13.4indirect
npmon-finished2.4.1indirect
npmonce1.4.0indirect
npmonetime5.1.2indirect
npmp-limit2.3.0indirect
npmp-limit3.1.0indirect
npmp-locate4.1.0indirect
npmp-try2.2.0indirect
npmpackage-json-from-dist1.0.1indirect
npmparse-json5.2.0indirect
npmparseurl1.3.3indirect
npmpath-exists4.0.0indirect
npmpath-is-absolute1.0.1indirect
npmpath-key3.1.1indirect
npmpath-scurry1.11.1indirect
npmpath-to-regexp0.1.13indirect
npmpicocolors1.1.1indirect
npmpicomatch2.3.2indirect
npmpicomatch4.0.4indirect
npmpirates4.0.7indirect
npmpkg-dir4.2.0indirect
npmprebuild-install7.1.3indirect
npmpretty-format30.3.0indirect
npmproxy-addr2.0.7indirect
npmpump3.0.3indirect
npmpure-rand7.0.1indirect
npmqs6.15.2indirect
npmrange-parser1.2.1indirect
npmraw-body2.5.3indirect
npmrc1.2.8indirect
npmreact-is18.3.1indirect
npmreadable-stream3.6.2indirect
npmrequire-directory2.1.1indirect
npmresolve-cwd3.0.0indirect
npmresolve-from5.0.0indirect
npmsafe-buffer5.2.1indirect
npmsafer-buffer2.1.2indirect
npmsemver6.3.1indirect
npmsemver7.7.3indirect
npmsemver7.7.4indirect
npmsend0.19.2indirect
npmserve-static1.16.3indirect
npmsetprototypeof1.2.0indirect
npmshebang-command2.0.0indirect
npmshebang-regex3.0.0indirect
npmside-channel1.1.0indirect
npmside-channel-list1.0.0indirect
npmside-channel-map1.0.1indirect
npmside-channel-weakmap1.0.2indirect
npmsignal-exit3.0.7indirect
npmsignal-exit4.1.0indirect
npmsimple-concat1.0.1indirect
npmsimple-get4.0.1indirect
npmslash3.0.0indirect
npmsource-map0.6.1indirect
npmsource-map-support0.5.13indirect
npmsprintf-js1.0.3indirect
npmstack-utils2.0.6indirect
npmstatuses2.0.2indirect
npmstreamsearch1.1.0indirect
npmstring-length4.0.2indirect
npmstring-width4.2.3indirect
npmstring-width5.1.2indirect
npmstring_decoder1.3.0indirect
npmstrip-ansi6.0.1indirect
npmstrip-ansi7.2.0indirect
npmstrip-bom4.0.0indirect
npmstrip-final-newline2.0.0indirect
npmstrip-json-comments2.0.1indirect
npmstrip-json-comments3.1.1indirect
npmsupports-color7.2.0indirect
npmsupports-color8.1.1indirect
npmsynckit0.11.12indirect
npmtar-fs2.1.4indirect
npmtar-stream2.2.0indirect
npmtest-exclude6.0.0indirect
npmtmpl1.0.5indirect
npmtoidentifier1.0.1indirect
npmtslib2.8.1indirect
npmtunnel-agent0.6.0indirect
npmtype-detect4.0.8indirect
npmtype-fest0.21.3indirect
npmtype-is1.6.18indirect
npmtypedarray0.0.6indirect
npmundici-types7.18.2indirect
npmunpipe1.0.0indirect
npmunrs-resolver1.11.1indirect
npmupdate-browserslist-db1.2.3indirect
npmutil-deprecate1.0.2indirect
npmutils-merge1.0.1indirect
npmv8-to-istanbul9.3.0indirect
npmvary1.1.2indirect
npmwalker1.0.8indirect
npmwhich2.0.2indirect
npmwrap-ansi7.0.0indirect
npmwrap-ansi8.1.0indirect
npmwrappy1.0.2indirect
npmwrite-file-atomic5.0.1indirect
npmy18n5.0.8indirect
npmyallist3.1.1indirect
npmyargs17.7.2indirect
npmyargs-parser21.1.1indirect
npmyocto-queue0.1.0indirect
Dependency advisories 7

This repository publishes no package the index resolves, so its own dependency graph was assessed — 413 packages, which also include development and test pins that never ship: 7 carry known advisories, of which 3 are direct.

PackageVersionRelationSeverityAdvisoriesFixed in
js-yaml3.14.2directhigh24.3.0
js-yaml4.1.1directhigh24.3.0
multer2.1.1directhigh23.0.0-alpha.2
brace-expansion1.1.13indirecthigh15.0.7
brace-expansion2.0.3indirecthigh15.0.7
@babel/core7.29.0indirectlow18.0.0-rc.6
body-parser1.20.4indirectlow12.3.0

An advisory means the version recorded in the dependency graph falls inside an advisory’s affected range. Reachability is not analysed, and the graph includes development and test pins — a finding may concern tooling rather than shipped software.

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [
        "ai",
        "ai-worker",
        "own-your-data",
        "personal-ai-assistant",
        "self-evolving",
        "team-collaboration"
      ],
      "is_fork": false,
      "size_kb": 12528,
      "has_wiki": false,
      "homepage": "https://zylos.ai",
      "languages": {
        "CSS": 13354,
        "HTML": 3332,
        "Shell": 118053,
        "Dockerfile": 7514,
        "JavaScript": 2145500
      },
      "pushed_at": "2026-07-20T10:49:20Z",
      "created_at": "2026-02-02T07:56:39Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-20T19:41:16Z",
      "description": "🐙 Give your AI a life — open-source agent infrastructure for team collaboration.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "JavaScript",
      "significant_languages": [
        "JavaScript"
      ]
    },
    "owner": {
      "blog": "https://zylos.ai/",
      "name": "Zylos-AI",
      "type": "Organization",
      "login": "zylos-ai",
      "company": null,
      "location": "Singapore",
      "followers": 115,
      "avatar_url": "https://avatars.githubusercontent.com/u/254429536?v=4",
      "created_at": "2026-01-12T10:12:34Z",
      "is_verified": null,
      "public_repos": 36,
      "account_age_days": 191
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.6.0",
          "kind": "minor",
          "published_at": "2026-07-14T14:42:51Z"
        },
        {
          "tag": "v0.5.3",
          "kind": "patch",
          "published_at": "2026-06-17T15:39:14Z"
        },
        {
          "tag": "v0.5.2",
          "kind": "patch",
          "published_at": "2026-06-01T17:10:41Z"
        },
        {
          "tag": "v0.5.1",
          "kind": "patch",
          "published_at": "2026-05-25T11:32:50Z"
        },
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2026-05-14T09:43:51Z"
        },
        {
          "tag": "issue-520-assets",
          "kind": "other",
          "published_at": "2026-05-03T14:36:02Z"
        },
        {
          "tag": "v0.4.13",
          "kind": "patch",
          "published_at": "2026-04-11T16:43:15Z"
        },
        {
          "tag": "v0.4.12",
          "kind": "patch",
          "published_at": "2026-04-08T14:41:02Z"
        },
        {
          "tag": "v0.4.11",
          "kind": "patch",
          "published_at": "2026-04-02T12:41:45Z"
        },
        {
          "tag": "v0.4.10",
          "kind": "patch",
          "published_at": "2026-03-28T15:17:58Z"
        },
        {
          "tag": "v0.4.9",
          "kind": "patch",
          "published_at": "2026-03-27T16:35:11Z"
        },
        {
          "tag": "v0.4.8",
          "kind": "patch",
          "published_at": "2026-03-26T14:54:46Z"
        },
        {
          "tag": "v0.4.7",
          "kind": "patch",
          "published_at": "2026-03-26T14:25:47Z"
        },
        {
          "tag": "v0.4.6",
          "kind": "patch",
          "published_at": "2026-03-26T12:23:08Z"
        },
        {
          "tag": "v0.4.5",
          "kind": "patch",
          "published_at": "2026-03-25T22:08:33Z"
        },
        {
          "tag": "v0.4.4",
          "kind": "patch",
          "published_at": "2026-03-25T21:32:39Z"
        },
        {
          "tag": "v0.4.3",
          "kind": "patch",
          "published_at": "2026-03-21T16:39:31Z"
        },
        {
          "tag": "v0.4.2",
          "kind": "patch",
          "published_at": "2026-03-19T17:50:47Z"
        },
        {
          "tag": "v0.4.1",
          "kind": "patch",
          "published_at": "2026-03-19T06:48:01Z"
        },
        {
          "tag": "v0.4.0",
          "kind": "minor",
          "published_at": "2026-03-14T18:05:39Z"
        },
        {
          "tag": "v0.3.7",
          "kind": "patch",
          "published_at": "2026-03-11T09:52:13Z"
        },
        {
          "tag": "v0.3.6",
          "kind": "patch",
          "published_at": "2026-03-09T15:00:55Z"
        },
        {
          "tag": "v0.3.5",
          "kind": "patch",
          "published_at": "2026-03-06T11:01:41Z"
        },
        {
          "tag": "v0.3.4",
          "kind": "patch",
          "published_at": "2026-03-05T14:28:38Z"
        },
        {
          "tag": "v0.3.3",
          "kind": "patch",
          "published_at": "2026-03-04T15:22:55Z"
        },
        {
          "tag": "v0.3.2",
          "kind": "patch",
          "published_at": "2026-03-04T06:10:41Z"
        },
        {
          "tag": "v0.3.1",
          "kind": "patch",
          "published_at": "2026-03-04T02:41:14Z"
        },
        {
          "tag": "v0.3.0",
          "kind": "minor",
          "published_at": "2026-03-03T17:01:52Z"
        },
        {
          "tag": "v0.2.7",
          "kind": "patch",
          "published_at": "2026-02-28T15:18:38Z"
        },
        {
          "tag": "v0.2.6",
          "kind": "patch",
          "published_at": "2026-02-27T10:53:59Z"
        },
        {
          "tag": "v0.2.5",
          "kind": "patch",
          "published_at": "2026-02-26T15:25:26Z"
        },
        {
          "tag": "v0.2.4",
          "kind": "patch",
          "published_at": "2026-02-24T15:11:33Z"
        },
        {
          "tag": "v0.2.3",
          "kind": "patch",
          "published_at": "2026-02-22T09:16:04Z"
        },
        {
          "tag": "v0.2.2",
          "kind": "patch",
          "published_at": "2026-02-22T07:12:55Z"
        },
        {
          "tag": "v0.2.1",
          "kind": "patch",
          "published_at": "2026-02-22T06:31:51Z"
        },
        {
          "tag": "v0.2.0",
          "kind": "minor",
          "published_at": "2026-02-20T17:39:00Z"
        },
        {
          "tag": "v0.1.9",
          "kind": "patch",
          "published_at": "2026-02-20T16:31:14Z"
        },
        {
          "tag": "v0.1.8",
          "kind": "patch",
          "published_at": "2026-02-18T16:42:56Z"
        },
        {
          "tag": "v0.1.7",
          "kind": "patch",
          "published_at": "2026-02-18T16:42:47Z"
        },
        {
          "tag": "v0.1.6",
          "kind": "patch",
          "published_at": "2026-02-17T06:05:42Z"
        },
        {
          "tag": "v0.1.5",
          "kind": "patch",
          "published_at": "2026-02-15T15:37:18Z"
        },
        {
          "tag": "v0.1.4",
          "kind": "patch",
          "published_at": "2026-02-14T14:01:10Z"
        },
        {
          "tag": "v0.1.3",
          "kind": "patch",
          "published_at": "2026-02-13T14:01:07Z"
        },
        {
          "tag": "v0.1.2",
          "kind": "patch",
          "published_at": "2026-02-13T13:27:09Z"
        },
        {
          "tag": "v0.1.1",
          "kind": "patch",
          "published_at": "2026-02-12T16:02:56Z"
        },
        {
          "tag": "v0.1.0",
          "kind": "minor",
          "published_at": "2026-02-11T09:02:28Z"
        },
        {
          "tag": "v0.1.0-beta.18",
          "kind": "prerelease",
          "published_at": "2026-02-09T03:01:26Z"
        },
        {
          "tag": "v0.1.0-beta.17",
          "kind": "prerelease",
          "published_at": "2026-02-08T13:49:40Z"
        },
        {
          "tag": "v0.1.0-beta.9",
          "kind": "prerelease",
          "published_at": "2026-02-07T18:16:41Z"
        },
        {
          "tag": "v0.1.0-beta.8",
          "kind": "prerelease",
          "published_at": "2026-02-07T17:58:32Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "7a034ca2e55457bf114d4973b7df04ca207371eb",
          "body": "…l restart (#738)\n\nupgrade.md still instructed the agent to manually run post-upgrade hooks\nand restart services, but since PR #589 (v0.5.1) the CLI already does\nboth in steps 7 and 8. Every agent-driven upgrade has been double-running\nthe post-upgrade hook since then.\n\nChanges:\n- Remove manual pre-\n[…]\ny the CLI's\n  start_service step result\"\n- Apply the same fixes to C4 mode (Step 2 and Post-Upgrade Actions)\n\nPart of #730 (PR-1).\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(docs): eliminate post-upgrade hook double-run and redundant manua…",
          "author_name": "zylos-luna-coco",
          "author_login": "zylos-luna-coco",
          "committed_at": "2026-07-15T01:55:00Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d008294751efb79e170651707fc15064a85741c8",
          "body": "Split-layer instruction architecture, migration tooling, session-start\nshard system, and 20+ fixes accumulated since v0.5.3.\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): v0.6.0 (#734)",
          "author_name": "zylos-luna-coco",
          "author_login": "zylos-luna-coco",
          "committed_at": "2026-07-14T14:41:46Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b59c14e04b3023ea58338594349bc267c569c387",
          "body": "The activity monitor's API error scanner missed \"API Error: 400 Output\nblocked by content filtering policy\" because the regex required\n\"APIError:\" (no space). Widen the pattern to /API\\s*Error:\\s*\\d{3}/ and\nadd a dedicated /output blocked by content filtering policy/i pattern\nso the health engine triggers a session restart on content filter blocks.\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: detect content filtering API errors for session recovery (#737)",
          "author_name": "zylos-luna-coco",
          "author_login": "zylos-luna-coco",
          "committed_at": "2026-07-14T14:34:42Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9844f3cf189bbf5b1d08c5ee29fe9648105a5c2f",
          "body": "When 90-migration-prompt.md exists (written by upgrade step7 for C-class\nmigrations), session-start-prompt.js now sends a migration-specific\nprompt that instructs the agent to execute the Required action\nimmediately, rather than the generic \"continue ongoing tasks\" prompt\nwhich the agent ignores.\n\nT\n[…]\n prompt file is cleaned up on success by\nexecuteMigrationApply and retained on failure for retry — natural\nat-least-once behavior.\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: auto-trigger pending migration on session start (#736)",
          "author_name": "zylos-luna-coco",
          "author_login": "zylos-luna-coco",
          "committed_at": "2026-07-14T13:18:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "623ae84e8c24f589f2fb951b608e4ab85ec90959",
          "body": "* fix: C-class migration prompt includes system template path for accurate diff\n\nThe migration prompt previously only provided baseline SHA-256 hashes,\nleaving the agent unable to distinguish system-managed content from user\nadditions. Now passes the installed claude-system.md path so the agent\ncan \n[…]\no lose, and the backup already\nexists for safety.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: C-class migration prompt includes system template path (#735)",
          "author_name": "zylos-luna-coco",
          "author_login": "zylos-luna-coco",
          "committed_at": "2026-07-14T12:54:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "51b3f732e574d7577bd78507f626aaed1ab63b67",
          "body": "…732)\n\n* docs: add dev plan for issue #729 (P3 upgrade-path auto-migration)\n\nStep 7 auto-migrates A/B class machines on upgrade; C class gets a\nstructured self-migration prompt file for channel-only agents.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\n\n* docs: revise dev pla\n[…]\nhard\n\n* fix: warn against manual instruction migration\n\n---------\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\nCo-authored-by: howard_mini <howard@howard-minideMac-mini.local>",
          "is_bot": false,
          "headline": "feat: upgrade-path auto-migration for instruction split (#729, P3) (#…",
          "author_name": "zylos-luna-coco",
          "author_login": "zylos-luna-coco",
          "committed_at": "2026-07-14T11:32:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9744c21b4a79c142527260c9b1d3fbdecf99aace",
          "body": "…2) (#728)\n\n* docs: add dev plan for issue #722 P2 (migration tool + A3 hook normalization)\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n* docs: close R1 findings in #722 P2 dev plan (reachable-history corpus, provenance-gated B, no-discard conservation, A3 convergence)\n\nCo-Authored-By: \n[…]\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>\nCo-authored-by: howard_mini <howard@howard-minideMac-mini.local>",
          "is_bot": false,
          "headline": "feat: safe instruction migration tool + A3 hook normalization (#722 P…",
          "author_name": "zylos-luna-coco",
          "author_login": "zylos-luna-coco",
          "committed_at": "2026-07-14T06:43:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "29909d0ee23ee7968d634a5cc70008f28ca1457f",
          "body": "* feat: apply the approved #722 content redraft to the system templates\n\nTemplate content payload (redraft v2.5, Howard-approved section by section):\n- templates/claude-system.md / codex-system.md rewritten to the sealed\n  redraft: shared core (~162 lines) + per-runtime addon (14 / 23 lines),\n  addo\n[…]\nidge, scheduler,\nhttp, web-console, activity-monitor. Template pins repinned.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: #722 template content redraft (D8 template-only PR) (#726)",
          "author_name": "zylos-luna-coco",
          "author_login": "zylos-luna-coco",
          "committed_at": "2026-07-13T16:54:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2da71e5665e0afa472198c02e445ebb90b94bf31",
          "body": "…) (#723)\n\n* docs: add dev plan for issue #722 (split-layer instructions)\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n* docs: verify two dev-plan assumptions (template corpus + pre-v0.4 path)\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n* docs: close R1 findings in #722 dev \n[…]\nreview findings (#722)\n\n* fix: close split hook lifecycle gap (#722)\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>\nCo-authored-by: howard_mini <howard@howard-minideMac-mini.local>",
          "is_bot": false,
          "headline": "feat: ZYLOS.md/CLAUDE.md split-layer instructions (P1 mechanism, #722…",
          "author_name": "zylos-luna-coco",
          "author_login": "zylos-luna-coco",
          "committed_at": "2026-07-13T15:59:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e38759fffcf36c265320594bff9de825161daf36",
          "body": "…ons shard (#724) (#725)\n\nThe budgeted shard path no longer applies the dispatch-style per-message\n2KB spill (preview + attachment pointer): the DB stores originals, and the\nshard's whole-message newest-first budget packer already bounds the output,\nso compressing messages at session start made the \n[…]\ne orchestrator to tail-trim\n  blindly; the legacy no-budget path (no packer to bound output) is\n  unchanged\n- dispatcher delivery path untouched\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: emit original message content in the session-start c4-conversati…",
          "author_name": "zylos-luna-coco",
          "author_login": "zylos-luna-coco",
          "committed_at": "2026-07-13T01:38:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a12098a4ca46dc57135096196d91e597da9e3b07",
          "body": "…tart shard (#719) (#721)\n\n* docs: route machine-local standing directives to the custom session-start shard (#719)\n\nThe custom SessionStart shard (~/zylos/custom-hooks/session-start/*.md) was\nundiscoverable: ZYLOS.md's Memory System section never mentioned it, while\nthe preferences.md classificatio\n[…]\n is self-contained; the\nrepo doc remains as operator/developer documentation.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: route machine-local standing directives to the custom session-s…",
          "author_name": "zylos-luna-coco",
          "author_login": "zylos-luna-coco",
          "committed_at": "2026-07-12T13:19:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d0d7024ded88ed5b9eea3891cde26c17ef9cacff",
          "body": "…ict short-circuit (#717) (#718)\n\n* docs: add dev plan for issue #717\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n* docs: dev plan v2 for issue #717 — absorb plan-review R1 (cross-version visibility channel, self-upgrade test seam, ZYLOS_DIR paths, failure semantics)\n\nCo-Authored-By: Cl\n[…]\nce complete)\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>\nCo-authored-by: howard_mini <howard@howard-minideMac-mini.local>",
          "is_bot": false,
          "headline": "fix: preserve self-upgrade conflict backups + identical-content confl…",
          "author_name": "zylos-luna-coco",
          "author_login": "zylos-luna-coco",
          "committed_at": "2026-07-12T06:41:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "81d10647a4cf89dd6dc7cd902d67a8ceb5957961",
          "body": "…-dir scans (#715) (#716)\n\n* fix: generate manifests from authoritative package source, never dest-dir scans (#715)\n\n- smartSync: save newManifest (package source) after successful sync instead\n  of rescanning destDir; skip manifest/originals persistence when the sync\n  recorded errors (keep last kn\n[…]\n\n* refactor: commit merge baselines at outer success boundary (#715)\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>\nCo-authored-by: howard_mini <howard@howard-minideMac-mini.local>",
          "is_bot": false,
          "headline": "fix: generate manifests from authoritative package source, never dest…",
          "author_name": "zylos-luna-coco",
          "author_login": "zylos-luna-coco",
          "committed_at": "2026-07-12T04:31:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d29a0fa9e15c7796d62864609758d66d018c8842",
          "body": "…(#714)\n\n* fix: prevent spill-file path collision in truncateForDelivery (#713)\n\nSpill directories were named Date.now()-pid, so two large messages\nspilled by one process in the same millisecond resolved to the same\ndirectory and silently overwrote each other (observed when the\nsession-start rendere\n[…]\nt re-spill,\nid 0 as a valid id, and the fallback collision cases.\n\nFixes #713\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: prevent spill-file path collision in truncateForDelivery (#713) …",
          "author_name": "zylos-luna-coco",
          "author_login": "zylos-luna-coco",
          "committed_at": "2026-07-11T10:53:52Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a621828ab14a49028b3640e191cb15344498f2bc",
          "body": "… modes (#706) (#712)\n\nNon-JSON mode printed warnings but exited 0 when component checks failed,\nwhile --json exited 1 — scripts got different failure signals depending on\noutput mode. Non-JSON now sets process.exitCode = 1 on any check failure\n(exitCode, not process.exit, so prompts/upgrades/output\n[…]\nal-fail / all-fail ×\nJSON / non-JSON via upgrade --all --check (negative control verified:\nthe two non-JSON failure cases fail without the fix).\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: unify upgrade --all exit-code contract between JSON and non-JSON…",
          "author_name": "zylos-luna-coco",
          "author_login": "zylos-luna-coco",
          "committed_at": "2026-07-11T09:04:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ae4a02441cddb8dccf20296cbcf649fc34d22c85",
          "body": "…(#705) (#711)\n\nWithout a token, fetchRawFileOnce / fetchTagsJsonSync / fetchTagsJsonAsync\n(github.js) and curlDownloadOnce (download.js) re-fired the identical public\nrequest in the same retry round purely to surface an error, doubling failure\nlatency and adding rate-limit pressure. Capture and ret\n[…]\n a new recovery test proving the\nouter loop still clears transient rate limiting, and a new\ndownload-no-token.test.js pinning the download path.\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: remove same-round duplicate public request in no-token fallback …",
          "author_name": "zylos-luna-coco",
          "author_login": "zylos-luna-coco",
          "committed_at": "2026-07-11T08:53:40Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a6f9bff54c734a201905c56317e81d5d5d15f1d3",
          "body": "…08) (#710)\n\nThe two writeCodexConfig cases passed the fixed path /tmp/zylos-project as\nthe project dir. On a shared host where another user owns that directory,\nmkdirSync inside it fails and writeCodexConfig returns false, failing the\nsuite on any commit. Point the project dir inside each test's existing\nmkdtempSync root so it is unique per test and cleaned up by the existing\nrmSync teardown.\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test: use per-test tmpdir instead of hardcoded /tmp/zylos-project (#7…",
          "author_name": "zylos-luna-coco",
          "author_login": "zylos-luna-coco",
          "committed_at": "2026-07-11T07:28:53Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "d2bc8ef9999691225df830270a35bd36f7fe76bc",
          "body": "* feat(cli): install components from local sources\n\n* fix: secure local component sources\n\n* fix: fail aggregate component checks\n\n---------\n\nCo-authored-by: Jinglever <267884994+jinglever@users.noreply.github.com>\nCo-authored-by: howard_mini <howard@howard-minideMac-mini.local>",
          "is_bot": false,
          "headline": "feat(cli): install components from local sources (#700)",
          "author_name": "Jinglever",
          "author_login": "jinglever",
          "committed_at": "2026-07-11T05:11:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5fb5a45fcdc86e27c9d91b5c361d070aa358f84e",
          "body": "* fix: prefer authenticated GitHub API requests\n\n* fix: harden GitHub fallback retries\n\n---------\n\nCo-authored-by: Jinglever <267884994+jinglever@users.noreply.github.com>\nCo-authored-by: howard_mini <howard@howard-minideMac-mini.local>",
          "is_bot": false,
          "headline": "fix: prefer authenticated GitHub API requests (#699)",
          "author_name": "Jinglever",
          "author_login": "jinglever",
          "committed_at": "2026-07-11T05:08:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0051b005c9f9490d27eb65230a1d4d8f8101d52d",
          "body": "…2) (#704)\n\nstate.md is always-loaded but its rules only said \"keep it lean\", so\nMemory Sync kept accumulating completed-task narrative and run history —\na production instance grew to 19KB against the 16KB hard budget.\n\nSame structure as #697 did for references.md:\n\n- templates/ZYLOS.md: define allo\n[…]\n so memory-status.js\n  reports WARN and consolidate.js flags nearBudget, same wiring as #697\n- tests: cover the new threshold value\n\nCloses #702\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(zylos-memory): content rules + sync-time audit for state.md (#70…",
          "author_name": "FelixLin6",
          "author_login": "FelixLin6",
          "committed_at": "2026-07-10T17:26:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f5e801674c08171fb3e395f94feb86d89b81943a",
          "body": "…stom-hooks/session-start) (#703)\n\n* feat(session-start): add custom-inject core shard at chain position 2\n\nDeployment/user-provided standing directives injected right after identity:\nthe emitter reads ~/zylos/custom-inject/*.md in lexicographic order at every\nsession start (conf.d-style numeric pre\n[…]\nexicographic\nconcat, empty passthrough, content-not-code boundary) unchanged.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(session-start): custom-inject core shard at chain position 2 (cu…",
          "author_name": "FelixLin6",
          "author_login": "FelixLin6",
          "committed_at": "2026-07-10T15:33:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9ca24f9f46e68b81f775125b5157478d9e6322da",
          "body": "…red flag chain (fixes #686) (#698)\n\n* feat(session-start): shard sequencer, registry, and orchestrator --shard mode (#686)\n\nSplit the session-start injection into per-shard hook commands so each\nshard gets its own hook stdout budget instead of sharing one 10K cap:\n\n- shard-sequencer.js: flag-file s\n[…]\n registry-closure e2e (shard-mode output always\nwithin DEFAULT_SHARD_BUDGET).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(session-start): shard injection into per-section hooks with orde…",
          "author_name": "FelixLin6",
          "author_login": "FelixLin6",
          "committed_at": "2026-07-10T15:28:48Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "61774e37dc89d78132f8a625dec31c4cee802a6e",
          "body": "…pt (#701)\n\n#675 asserted the Codex launch spec args must be empty (no retired text\nbootstrap payload). #681 then deliberately added the 'hello' kick prompt\nto launch args to trigger the SessionStart hook, but did not update this\nassertion, leaving one deterministic failure on main (expected [] vs\na\n[…]\n'hello']). Pin the assertion to exactly ['hello'] so the test\nkeeps rejecting any resurrected bootstrap payload while accepting the\nkick prompt.\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test: update stale Codex launch-spec assertion for the #681 kick prom…",
          "author_name": "Luna",
          "author_login": "zylos-luna",
          "committed_at": "2026-07-10T04:49:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f94f149f8457d7297ad2bf64dc9d21ceab034397",
          "body": "… (#697)\n\nreferences.md is always-loaded but had only one narrow content rule\n(never duplicate .env values), so Memory Sync kept appending narrative\nhistory and a production instance grew to 14KB against a ~4-5KB core.\n\n- templates/ZYLOS.md: define allowed content classes (stable IDs,\n  endpoints, k\n[…]\nand budget,\n  consolidate.js report gains warnThresholds/nearBudget\n- tests: cover WARN_THRESHOLDS values and warn<budget invariant\n\nCloses #696\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(zylos-memory): content rules + sync-time audit for references.md…",
          "author_name": "FelixLin6",
          "author_login": "FelixLin6",
          "committed_at": "2026-07-09T14:42:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9568392b1bb9dd28aff962e3aa7da744b66b36cb",
          "body": "This reverts commit c5b4745535c9e75a879f8dd6ccdba12d49629588.",
          "is_bot": false,
          "headline": "Revert \"chore(release): v0.5.4 (#688)\" (#692)",
          "author_name": "Luna",
          "author_login": "zylos-luna",
          "committed_at": "2026-07-03T08:22:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a3efb7f9097110c4e8ee86ecaf91277d6ba348e8",
          "body": "Session-handoff summaries were piggybacked on the web-console channel,\nforcing every display surface to remember an endpoint_id='session-handoff'\nspecial case (#687). Introduce a virtual 'void' channel instead:\n\n- c4-send.js: channel 'void' records the row in c4.db (endpoint mandatory,\n  carries the\n[…]\nLI),\nmigration re-tag (c4-db CLI), void exclusion on web-console routes (jest),\nupdated session-handoff prompt assertion.\n\nRefs #687, #621, #619\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(c4): first-class void channel for internal messages (#689) (#690)",
          "author_name": "Luna",
          "author_login": "zylos-luna",
          "committed_at": "2026-07-03T08:11:23Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c5b4745535c9e75a879f8dd6ccdba12d49629588",
          "body": "Co-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): v0.5.4 (#688)",
          "author_name": "Luna",
          "author_login": "zylos-luna",
          "committed_at": "2026-07-02T14:34:07Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "50d7f1e2debf43824a35f82512f6646a28cf0cd8",
          "body": "…(#687)\n\n* fix(web-console): hide session-handoff messages from console display\n\nSession-handoff notes (channel=web-console, endpoint=session-handoff)\nare internal continuity messages, but the console rendered every row on\nthe web-console channel, exposing task state and internal IDs to any\nclient. \n[…]\nrows from the console. IS NOT treats NULL as distinct and keeps them\nvisible.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(web-console): hide session-handoff messages from console display …",
          "author_name": "Luna",
          "author_login": "zylos-luna",
          "committed_at": "2026-07-02T14:19:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "dadeca979d74385075bb97e5d1bc44886f788290",
          "body": "…B (#618)\n\n* docs: add dev plan for issue #618\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\n\n* docs: update dev plan per Jinglever review — fix read-side boundaries\n\n- formatConversations() stays clean (no reply via) for c4-fetch/Memory Sync\n- Session-init and dispatcher rec\n[…]\n: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\nCo-authored-by: howard_mini <howard@howard-minideMac-mini.local>",
          "is_bot": false,
          "headline": "fix(comm-bridge): store full inbound messages, strip reply-via from D…",
          "author_name": "Luna",
          "author_login": "zylos-luna",
          "committed_at": "2026-07-01T16:14:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "dff7c84bf3510745fab1b5b950efc8bb952d4359",
          "body": "PR #682 introduced JSON.stringify() quoting around hook script paths,\nproducing `node \"/path/to/script.js\"` — inconsistent with #678's format\nunification which removed quoting from Codex hooks.\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: remove unnecessary path quoting in desiredClaudeHooks (#684)",
          "author_name": "Luna",
          "author_login": "zylos-luna",
          "committed_at": "2026-07-01T10:14:55Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "48eac81f3c82ffe14d3f4e672da896cb6b2344a2",
          "body": "Co-authored-by: howard_mini <howard@howard-minideMac-mini.local>",
          "is_bot": false,
          "headline": "fix: generate Claude hooks at runtime (#682)",
          "author_name": "Luna",
          "author_login": "zylos-luna",
          "committed_at": "2026-07-01T09:56:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dcbf438762b86c83c6da17f2072e347ffde73c49",
          "body": "…k (#681)\n\n* fix: send kick message after Codex launch to trigger SessionStart hook (#680)\n\nCodex's SessionStart hook is lazy — it only fires on the first user\nmessage, not on process start. After PR #675 moved all bootstrap\ncontext into the SessionStart hook, a PM2-restarted Codex would sit\nuniniti\n[…]\n tmux session: codex \"hello\" in the shell command\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: send kick message after Codex launch to trigger SessionStart hoo…",
          "author_name": "Luna",
          "author_login": "zylos-luna",
          "committed_at": "2026-07-01T09:25:54Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3dcfc99229af58cb9b2a29eda789099a918cefd7",
          "body": "…8) (#679)\n\n`coreSessionStartCommand()` used `JSON.stringify(script)` which wrapped\nthe path in double quotes, while dashboard hooks use unquoted paths.\nStandardize on unquoted format since zylos paths never contain spaces.\n\nCloses #678\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: unify hook command format — remove unnecessary path quoting (#67…",
          "author_name": "Luna",
          "author_login": "zylos-luna",
          "committed_at": "2026-07-01T08:06:16Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "0549792c75c4991da0349afea1e3ca876fa8c34b",
          "body": "fix: migrate Codex bootstrap to native SessionStart hook (#652)\n\nReplaces text-based Codex bootstrap prompt with native SessionStart hook for context injection. Core owns hook installation, trust validation (hash + version + feature flags), and session-start content delivery. Removes buildCodexBootstrapPrompt and all text-bootstrap paths.\n\nVerified: 2-person code review (Luna + zylos0t), dual trust smoke, Docker e2e (no-auth), Docker real-auth (gpt-5.5 model consumption).\n\nCloses #652",
          "is_bot": false,
          "headline": "fix: migrate Codex bootstrap to native SessionStart hook (#675)",
          "author_name": "Jinglever",
          "author_login": "jinglever",
          "committed_at": "2026-07-01T07:44:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "336739aa675c5c784e90cffe4444a9e3a77bdf1a",
          "body": "…truth (#674)\n\nCHECKPOINT_THRESHOLD controls both how many unsummarized messages get\ninjected verbatim at session start (all of them when under threshold) and\nwhen an early in-session Memory Sync fires. 30 was too large for the\nsession-start path — up to 30 raw messages on top of identity/state/refs\n[…]\nready used here for tmux-input-state.js). The context-monitor engine is\nalready parameter-driven and needs no change.\n\nCloses #673\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: lower Memory Sync checkpoint threshold 30→15 + single source of …",
          "author_name": "Luna",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-29T13:39:16Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9799a87cce995560f726e829bce08cf5eca20b5f",
          "body": "…ummaries (#671)\n\n* fix: unify session-start context format + surface failures and null summaries\n\nMemory injection and C4 session init previously built their own ad-hoc\nsection framing (`=== LABEL ===` header-only vs `[Bracket Label]`), so the\ncombined session-start context read inconsistently. Int\n[…]\nANGELOG.md to match main; code changes\nunchanged.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: unify session-start context format + surface failures and null s…",
          "author_name": "Luna",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-28T18:13:57Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e2401fe0a35fc35a46c0ce4e7dc86fdb59c7bc7b",
          "body": "These are intermediate process artifacts left in the repo, no code or doc\nreferences them:\n- docs/dev-plan-issue-651.md          (dev plan for #651)\n- docs/impl-session-start-orchestrator.md (impl design doc for #651)\n- docs/impl-tmux-launcher-clean-env.md    (older PR's impl doc)\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: remove leftover process docs from PR #668/#651 line (#672)",
          "author_name": "Luna",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-28T18:09:51Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "773b239c5ceb10c5d648c2509290973404e45738",
          "body": "…(#668)\n\n* docs: add SessionStart orchestrator design document (#651)\n\nDesign document for consolidating 4 SessionStart hooks into a single\norchestrator script with per-step error isolation and bounded runtime.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>\n\n* feat: add SessionStart orches\n[…]\nden hook script path keys\n\n* test: make hook path fixtures portable\n\n---------\n\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>\nCo-authored-by: howard_mini <howard@howard-minideMac-mini.local>",
          "is_bot": false,
          "headline": "feat: consolidate SessionStart hooks into single orchestrator (#651) …",
          "author_name": "Luna",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-28T15:35:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ff1c2ae59e8b718c1d7f31dce402eb7242c7b938",
          "body": "* fix(upgrade): persist pm2 dump after component upgrade restart\n\n`zylos upgrade <component>` restarted the service but never called\n`pm2 save`, so the upgraded process lived only in PM2's in-memory list.\nOn the next reboot `pm2 resurrect` restored the pre-upgrade dump, silently\ndropping the upgrade\n[…]\nntext) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: owen0x6f <owen0x6f@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>\nCo-authored-by: zylos <creator@zylos.ai>",
          "is_bot": false,
          "headline": "fix(upgrade): persist pm2 dump after component upgrade restart (#669)",
          "author_name": "owen0x6f",
          "author_login": "owen0x6f",
          "committed_at": "2026-06-26T13:30:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2b8c7cd7015a49d42e7c7cdf36b0c2dbd43c82bf",
          "body": "…66) (#667)\n\n- Expand RATE_LIMIT_PATTERNS to match \"session limit\", \"weekly limit\",\n  \"Opus limit\", \"Sonnet limit\" and other named limit variants\n- Support curly apostrophe (') in addition to straight (')\n- Fix reset time regex to handle date-based formats like\n  \"resets Jun 29, 3am (Asia/Singapore)\n[…]\nme\n  is not parseable\n- Add 15 unit tests covering pattern matching and time parsing\n- Export test helpers for direct unit testing\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: broaden rate limit detection patterns and reset time parsing (#6…",
          "author_name": "Luna",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-25T06:39:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "bbc28c672ffc983656716fc18a8a5852ec7375f9",
          "body": "…hreshold (#662)\n\nWhen upgrading older instances, syncTemplateModelSetting() would backfill\nopus[1m] without checking whether the existing new_session_threshold is\ncompatible. An instance with threshold=70 (the old default) would end up\nwith opus[1m]+70%, effectively using ~700K context per session.\n[…]\ning the threshold,\nsince there is no provenance to distinguish \"user explicitly set 70\"\nfrom \"system old default 70\".\n\nCloses #661\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: guard opus[1m] model backfill against incompatible new_session_t…",
          "author_name": "Luna",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-23T17:30:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "27b7bc5ea7a1cdc292328505c0cdfd34177dc079",
          "body": "revert: Composio MCP integration (#656)",
          "is_bot": false,
          "headline": "Merge pull request #657 from zylos-ai/revert/composio-mcp-integration",
          "author_name": "Luna",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-22T03:39:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "edc695310f24905b3c9c64db156daaa18095feed",
          "body": "This reverts commit 69c40e9fa564baffee8fb21f7b9347dde899d9a0.",
          "is_bot": false,
          "headline": "Revert \"feat: Composio MCP integration (Tool Router, JIT tool-scoping)\"",
          "author_name": "zylos-luna",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-22T03:32:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "69c40e9fa564baffee8fb21f7b9347dde899d9a0",
          "body": "Adds safe Composio Tool Router MCP configuration persistence for Claude and Codex runtimes.",
          "is_bot": false,
          "headline": "feat: Composio MCP integration (Tool Router, JIT tool-scoping)",
          "author_name": "FelixLin6",
          "author_login": "FelixLin6",
          "committed_at": "2026-06-21T18:56:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6be3db26d628d957df3244a66dc643651197430e",
          "body": "Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: bump version to 0.5.3 (#654)",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-17T15:38:34Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3020a53705db61d14264eac193d14a33292ca153",
          "body": "* fix: pin process.execPath in tmux clean PATH to prevent node version mismatch (#445)\n\nWhen PM2 starts activity-monitor with a stripped PATH (no .nvm), _buildPath()\nproduced a PATH without the nvm node directory, causing tmux child processes\n(c4-control.js) to fall back to system node v18. Loading \n[…]\nux-env-execpath) already covers the verification.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: pin process.execPath in tmux clean PATH (#445) (#653)",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-17T15:17:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "90954039d221d6ed4ef3cd99e802effc335e29d1",
          "body": "…7) (#650)\n\n* docs: add dev plan for issue #647 (real-runtime smoke + service-health)\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n* docs: revise dev plan #647 per Jinglever R1 (preflight-before-build, per-skill resolve assertion)\n\nCo-Authored-By: Claude Opus 4.8 (1M contex\n[…]\nference. Drop it\nbefore merge so it doesn't ship.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(runtime): real-smoke + service-health integration scenarios (#64…",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-17T13:20:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "25ba2bd119bc08342f1734856fa2dec181dda30d",
          "body": "…ios) (#645) (#646)\n\n* docs: add dev plan for issue #645\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n* docs: revise dev plan #645 per Jinglever R1 (gate semantics, no-op guard, codex creds)\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n* docs: scop\n[…]\nen, zero NODE_MODULE_VERSION errors in build log.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test: add local runtime integration-test harness (env-injected scenar…",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-17T09:22:26Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "65e3afc9bf664a3fd1765032a689a79056e633e3",
          "body": "…te (#640) (#642)\n\n* docs: add dev plan for issue #640 (checkAuth tristate + --no-validate)\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n* docs: tighten dev plan #640 per Jinglever R1 (wording + test assertion clarity)\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@\n[…]\n docs: remove dev plan doc post-acceptance (#640)\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: unify runtime checkAuth into explicit tristate + add --no-valida…",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-16T13:47:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "48ac162466554f9a912fd76b2159f346d24bc87b",
          "body": "…aude + Codex) (#641)\n\n* fix: init Claude auth check keys off loggedIn field, not exit code\n\nisClaudeAuthenticated() previously returned `result.status === 0` from\n`claude auth status`, treating the process exit code as the auth signal.\nThat conflated several distinct outcomes — genuinely not logged\n[…]\nt afterEach drains it);\ncleaned once via after().\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: runtime auth checks key off explicit signals, not exit codes (Cl…",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-16T10:21:52Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1c635f556c2e57b36ae4b62d2cfda5a3e2227b09",
          "body": "…model backfill (#638)\n\nFresh installs default the provisioned Claude model to opus[1m] (latest Opus, 1M context) instead of claude-opus-4-6. The Claude new_session_threshold default is paired with the model: fresh installs and upgrade-time opus[1m] model backfills write an explicit new_session_thre\n[…]\nd; runtime fallback stays 70. Codex (codex_new_session_threshold=75) is unaffected. Not gated by current runtime. Doc wording in activity-monitor SKILL.md points to config.json as the source of truth.",
          "is_bot": false,
          "headline": "feat: default to opus[1m] and pair Claude new-session threshold with …",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-15T14:06:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "65585999e7c3f2e5335ef39e70c824fa07e3bc48",
          "body": "* docs: add dev plan for issue #629 (web-console attachments)\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n* docs: address #629 plan review R1 (realpath allowlist, 2KB offload guard, attachment-only gates)\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n* feat: add web console a\n[…]\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>\nCo-authored-by: howard_mini <howard@howard-minideMac-mini.local>",
          "is_bot": false,
          "headline": "feat: web-console image and file upload/display (#629) (#636)",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-15T12:07:10Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7fdf42c01c4079ef2ed18568349fb4d7a679f895",
          "body": "…e (#633)\n\nGitHub calls in the CLI (tags listing, raw file fetch, tarball\ndownload) were single-shot: an HTTP 403 (primary rate limit, 60/h\nunauthenticated per IP) or 429 (secondary limit) failed the command\nimmediately. Customer instances on shared egress IPs without a token\nhit this during onboard\n[…]\nstill\nfalls through to the authenticated endpoint before any sleep.\nNon-rate-limit failures keep failing fast. Delays are overridable\nvia ZYLOS_GH_RETRY_DELAY_MS for tests and ops tuning.\n\nCloses #632",
          "is_bot": false,
          "headline": "fix: auto-retry GitHub API calls on rate limiting in zylos add/upgrad…",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-12T10:34:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2fc61cf0a72ee260679c629fa693c22275160cf3",
          "body": "* fix: raise zylos-memory state budget to 16kb\n\n* fix: align core memory budgets\n\n* docs: clarify memory consolidation trigger wording\n\n* docs: prevent Codex memory sync PM2 sidecars\n\n---------\n\nCo-authored-by: howard_mini <howard@howard-minideMac-mini.local>",
          "is_bot": false,
          "headline": "Raise zylos-memory core file budgets to 16KB (#623)",
          "author_name": "Jinglever",
          "author_login": "jinglever",
          "committed_at": "2026-06-10T08:33:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8ee9bd9007edab46f766f3574e0ad56cf69268c2",
          "body": "chore: release v0.5.2",
          "is_bot": false,
          "headline": "Merge pull request #608 from zylos-ai/chore/release-v0.5.2",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-01T17:10:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b2ea816635dd54c452a907bdc9e16b445af527a7",
          "body": "Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: release v0.5.2 (#608)",
          "author_name": "zylos",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-01T17:05:50Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "d51d6a00975088a469da97bda00228e7d2c63c1d",
          "body": "fix: preserve external settings in Codex config (#606)",
          "is_bot": false,
          "headline": "Merge pull request #607 from zylos-ai/fix/issue-606-config-merge",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-01T16:47:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3adc6c8791aab746bb946ab5371bf889c6e4489a",
          "body": null,
          "is_bot": false,
          "headline": "fix: add codex project managed defaults",
          "author_name": "howard_mini",
          "author_login": null,
          "committed_at": "2026-06-01T16:40:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "62834d8ff711f61ad81aaff0e5d6f7dd6dd2978d",
          "body": null,
          "is_bot": false,
          "headline": "refactor: use smol-toml for codex config merge",
          "author_name": "howard_mini",
          "author_login": null,
          "committed_at": "2026-06-01T16:20:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7610dd23195cfd580f5493f81df53c2d21dacb31",
          "body": null,
          "is_bot": false,
          "headline": "docs: remove dev plan (review complete)",
          "author_name": "zylos",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-01T15:04:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "92ac79af9b3b10e656c6ea5b93608f3f792ff20f",
          "body": null,
          "is_bot": false,
          "headline": "fix: preserve codex config ownership boundaries",
          "author_name": "howard_mini",
          "author_login": null,
          "committed_at": "2026-06-01T14:59:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6440052c82a6bd94d9f2098a3b29c901321efb03",
          "body": null,
          "is_bot": false,
          "headline": "docs: fix dev plan issue #606 per Jinglever R1",
          "author_name": "zylos",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-01T14:51:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "871b841875482442063fc01bc66e2d4ab5197e50",
          "body": null,
          "is_bot": false,
          "headline": "docs: add dev plan for issue #606",
          "author_name": "zylos",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-01T14:48:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bd38923ee352dd26edbadd646c84b962c0c97d6b",
          "body": "Co-authored-by: linfan.lin <linfan.lin@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(caddy): show manual route config when unavailable (#602)",
          "author_name": "leslielin2025",
          "author_login": "leslielin2025",
          "committed_at": "2026-05-27T12:15:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c1e7a0ac282afa2b063d1bc76d97bbe7e63d99a3",
          "body": "Co-authored-by: linfan.lin <linfan.lin@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(c4): store status cooldowns in sqlite (#604)",
          "author_name": "leslielin2025",
          "author_login": "leslielin2025",
          "committed_at": "2026-05-27T12:13:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3bd74fe0c16dc205b3174ad36244e45dd8170ab4",
          "body": "* fix(c4): cooldown repeated status replies\n\n* fix(c4): harden status cooldown persistence\n\n* fix(c4): reserve status cooldown before notify\n\n---------\n\nCo-authored-by: linfan.lin <linfan.lin@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(c4): cooldown repeated status notices (#599)",
          "author_name": "leslielin2025",
          "author_login": "leslielin2025",
          "committed_at": "2026-05-27T07:45:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "33a54135eb893ac79d02075b0d8dcf46507bbcd5",
          "body": "Co-authored-by: Zylos <zylos@zylos.ai>",
          "is_bot": false,
          "headline": "chore: release v0.5.1 (#596)",
          "author_name": "zylos0t",
          "author_login": "zylos0t",
          "committed_at": "2026-05-25T11:32:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "39bb59928da8bcde30d4a1367725ee663b95bb05",
          "body": "Run component post-upgrade hooks from the upgrade pipeline while preserving JSON output semantics.\n\n- capture hook stdout/stderr and replay only in human mode\n- keep hook failures non-fatal with diagnostics in step metadata\n- validate hook paths, including symlink resolution, stay within the component directory\n- add focused coverage for hook success, failure, JSON isolation, and path escape cases",
          "is_bot": false,
          "headline": "feat(upgrade): run post-upgrade hook automatically",
          "author_name": "gavin",
          "author_login": "gavin09527",
          "committed_at": "2026-05-25T11:09:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "106fbdfdd477b5ed177d47f619dbbdd47d0a489a",
          "body": "… (#591)\n\nReplace Chinese user message catalog with English equivalents for\nbroader accessibility. Update test assertions accordingly.\n\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(activity-monitor): translate user-facing messages to English…",
          "author_name": "leslielin2025",
          "author_login": "leslielin2025",
          "committed_at": "2026-05-21T06:22:39Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "0f23cbc68e976eedec5f14f736680eac81d81808",
          "body": "* chore: bump version to 0.5.0\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\n\n* chore: clarify upgrade notes — restart AM after upgrade\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\n\n* chore: upgrade notes — require AM stop for v0.4.13 and earlier\n\nCo-\n[…]\nd manifest manual copy note for v0.4.13 upgraders\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: release v0.5.0 (#587)",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-05-14T09:42:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b55cde0bd1fa8ee96cbe7b9298dd5dc3a7e69d52",
          "body": "Add health_check_enabled config gate (default: true) to the health-check\ntask, following the same pattern as daily_upgrade_enabled. Disable with\n`zylos config set health_check_enabled false`.\n\nCloses #585\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(activity-monitor): add toggle for 24h health check (#586)",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-05-14T08:18:26Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "0d086d2816e843fa60c2d119ec266ab8f6762863",
          "body": "* docs: implementation plan for tmux-launcher clean env\n\nBased on the approved proposal-clean-env-v2, this document details\nthe implementation approach for replacing the shell source mechanism\nwith a launcher-based pipeline (Level 1 env allowlisting).\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthro\n[…]\nale doc comment — buildCompatEnv no longer labeled as default.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: tmux-launcher clean env (Level 1 allowlisting) (#576)",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-05-14T07:20:28Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6e33f49014572a6ba649b0ad9caeb1e86f7cf604",
          "body": "* fix(activity-monitor): detect image dimension limit errors\n\n* fix(runtime): add timeout to all execSync calls in runtime adapters\n\nRuntime adapter execSync calls (tmux has-session, list-panes, ps, pgrep,\nkill-session, capture-pane, etc.) lacked timeouts. When the tmux server\nbecomes unresponsive (\n[…]\no-authored-by: linfan.lin <linfan.lin@users.noreply.github.com>\nCo-authored-by: leslielin2025 <225646034+leslielin2025@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(activity-monitor): detect image dimension limit errors (#579)",
          "author_name": "leslielin2025",
          "author_login": "leslielin2025",
          "committed_at": "2026-05-11T10:22:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "cd9adfb6403f00500d12a5a5a1c0cb5dd11ac06b",
          "body": "Co-authored-by: zylos0t <zylos0t@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(upgrade): harden symlinked skills rollback (#577)",
          "author_name": "zylos0t",
          "author_login": "zylos0t",
          "committed_at": "2026-05-11T06:18:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9834ae927396d861e0f42ad058bb720eeb47cac6",
          "body": "* feat: support component configure hooks\n\n* fix: bound configure hook execution\n\n---------\n\nCo-authored-by: Zylos <zylos@zylos.ai>",
          "is_bot": false,
          "headline": "feat: support component configure hooks (#578)",
          "author_name": "zylos0t",
          "author_login": "zylos0t",
          "committed_at": "2026-05-10T17:29:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b6091c79570bee062aa84e4374b106f1c1bbcef8",
          "body": "…572)\n\n* fix(upgrade): run post-install steps from new package\n\n* docs(upgrade): add PM2 env retry note\n\n* fix(upgrade): avoid rollback after finalizer handoff\n\n---------\n\nCo-authored-by: linfan.lin <linfan.lin@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(upgrade): run self-upgrade post-install steps from new package (#…",
          "author_name": "leslielin2025",
          "author_login": "leslielin2025",
          "committed_at": "2026-05-08T10:52:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "83b8ee6a56f3a277ac77de9cdc5f48522835d164",
          "body": "Co-authored-by: Zylos <zylos@zylos.ai>",
          "is_bot": false,
          "headline": "fix: route handoff summaries to internal channel (#571)",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-05-08T09:17:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ae10a152fddb8517c8150c07410c4fc72a2de734",
          "body": "SQLite stores UTC timestamps without timezone indicator, causing the\nbrowser to interpret them as local time. Append 'Z' suffix so the\nbrowser correctly parses them as UTC, then convert to the configured\ntimezone from .env for display.\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(web-console): respect TZ config for timestamp display (#568)",
          "author_name": "summingyu",
          "author_login": "summingyu",
          "committed_at": "2026-05-08T09:04:46Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2d0d0a09b64e8bf48cbd9006d7ae5c0da62f6b8f",
          "body": "Co-authored-by: linfan.lin <linfan.lin@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(upgrade): verify activity monitor env via pm2 jlist (#570)",
          "author_name": "leslielin2025",
          "author_login": "leslielin2025",
          "committed_at": "2026-05-08T08:46:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "59b2f60e433e229a8ec57e7c124612c4aeb32ba0",
          "body": "Co-authored-by: linfan.lin <linfan.lin@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(claude): default settings model to opus 4.6 (#567)",
          "author_name": "leslielin2025",
          "author_login": "leslielin2025",
          "committed_at": "2026-05-08T07:23:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1e97a173f9f100fca0403899cc675605370ea6a7",
          "body": "* docs: add Activity Monitor design doc (C4 model)\n\nNew design document for Activity Monitor as a clean-slate module design,\nstructured using the C4 model (Context/Containers/Components/Code).\nIncludes 34 key design decisions extracted from PR #501 review.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@a\n[…]\no-authored-by: leslielin2025 <225646034+leslielin2025@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>\nCo-authored-by: linfan.lin <linfan.lin@users.noreply.github.com>",
          "is_bot": false,
          "headline": "refactor(am): Activity Monitor v3 — modular architecture (#545)",
          "author_name": "leslielin2025",
          "author_login": "leslielin2025",
          "committed_at": "2026-05-08T04:31:15Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "34946391cd821a37472cefe7108e03abc4a21019",
          "body": "On fresh servers with empty npm cache, 120s timeout is insufficient for\ndownloading all dependencies. Bump to 300s and switch stdio from pipe\nto inherit so users see real-time npm progress.\n\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: increase npm install timeout and show progress (#522)",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-05-04T17:29:09Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3a807de533db0b33c0a1b13d471d180c5dd93bd9",
          "body": "Co-authored-by: howard_mini <howard@howard-minideMac-mini.local>",
          "is_bot": false,
          "headline": "fix(caddy): forward stripped route prefix (#521)",
          "author_name": "Jinglever",
          "author_login": "jinglever",
          "committed_at": "2026-05-04T16:40:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5f257eebc10952b7701e7aaad4fe88583ae9886a",
          "body": "* fix(c4): treat codex exit as lifecycle control\n\n* docs(create-skill): clarify YAML frontmatter safety",
          "is_bot": false,
          "headline": "fix(c4): treat Codex /exit as lifecycle control (#517)",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-04-28T04:58:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "330dd9eebd717b6d1a9bda13e01aec19fee006f4",
          "body": "PATH grows from ~17 unique entries to 189+ through a 4-layer\ncompounding cycle:\n\n1. ecosystem.config.cjs builds ENHANCED_PATH by concatenating\n   SYSTEM_PATH + process.env.PATH without dedup. Each PM2 restart\n   re-evaluates this file, and process.env.PATH already contains\n   the previous ENHANCED_P\n[…]\nM_PATH persistence, and tmux\nPATH pass-through. Preserves entry order (first occurrence wins).\n\nCo-authored-by: emma-zylos <emma-zylos@coco.xyz>\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: deduplicate PATH to prevent bloat across restarts (#499)",
          "author_name": "Daniel Zhou",
          "author_login": "danielzhou82",
          "committed_at": "2026-04-17T03:29:11Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2167fbeab96379160a5c29f4b5c3fc515210279f",
          "body": "* feat: add claude web tool watchdog\n\n* fix: harden tool event stream recovery and remove dead api activity reader\n\n* fix(security): patch path-to-regexp ReDoS in web-console\n\n* fix: harden claude watchdog foreground detection\n\n* fix: dedupe duplicate claude tool lifecycle events\n\n* fix: ignore subagent hook events in watchdog stream",
          "is_bot": false,
          "headline": "Add Claude web tool watchdog and harden tool event recovery (#500)",
          "author_name": "Athan",
          "author_login": "athanbase",
          "committed_at": "2026-04-16T11:02:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a6014bd0fd1b47fa8cf336373c17f0c62c94cc86",
          "body": "* docs: add Node.js dependency note to README\n\nHighlights that npm packages are tied to the system Node.js version.\nIf users upgrade Node.js (e.g. via nvm), globally installed packages\nincluding Zylos may disappear. Added to both EN and zh-CN READMEs.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthro\n[…]\n <noreply@anthropic.com>\n\n* docs: revert nvm to v0.40.3 to match install.sh\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: add Node.js dependency note to README (#495)",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-04-13T15:30:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8a2a293670d3eaec3c0eda88a22acc3a528c512a",
          "body": "Bump version to 0.4.13 and document C4 Claude input-box fallback\ndetection plus send-retry reduction from PR #493.\n\nCo-authored-by: Zylos <zylos@zylos.ai>\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: prepare release v0.4.13 (#494)",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-04-11T16:42:27Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "57afc1132371275745af207925250084651f9998",
          "body": "* fix(c4): add claude input fallback and reduce retry count\n\n* refactor(c4): use prompt-right 10-char window for claude fallback\n\n* refactor(c4): make claude fallback function explicit\n\n---------\n\nCo-authored-by: Zylos <zylos@zylos.ai>",
          "is_bot": false,
          "headline": "fix(c4): add Claude input fallback and reduce send retries (#493)",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-04-11T16:24:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "33cb1e2a01e134b1ac904369b9a724d2365ba3f2",
          "body": "* chore: prepare release v0.4.12\n\n* docs: expand v0.4.12 changelog scope\n\n* docs: rewrite 0.4.12 changelog as synthesized summary\n\nReplace per-commit changelog entries with a consolidated summary\nthat describes the net functional changes between v0.4.11 and v0.4.12.\nAdd upgrade-strongly-recommended notice.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Zylos <zylos@zylos.ai>\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: prepare release v0.4.12 (#491)",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-04-08T14:40:03Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9fb43962e02093b8efe087a3b356e4e01c664068",
          "body": "* fix: fallback tmpdir for copyTree self-copy backups\n\n* fix: fallback tmpdir for diff3 merge workspace\n\n---------\n\nCo-authored-by: Zylos <zylos@zylos.ai>",
          "is_bot": false,
          "headline": "fix: fallback tmpdir for copyTree self-copy backups (#490)",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-04-08T14:14:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "605595928b73d9dc49d73d24bd583efca10fa2d9",
          "body": "Co-authored-by: Zylos <zylos@zylos.ai>",
          "is_bot": false,
          "headline": "fix: fallback tmpdir for self-upgrade backup path (#489)",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-04-08T12:27:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "32a1191e2fc84c9194a0ca807375fff9d3c7c619",
          "body": "Co-authored-by: Zylos <zylos@zylos.ai>",
          "is_bot": false,
          "headline": "fix: fallback tmpdir handling in download helpers (#488)",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-04-08T12:19:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7651bf61506a81924e4a0b1a21d86ad1ff706d1f",
          "body": "…#487)\n\n* fix: add safety checks to upgrade --temp-dir to prevent directory deletion\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>\n\n* fix: const -> let for tempDirWasProvided to support fallback reassignment\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>\n\n* fix: resolve symlinks\n[…]\nmessage\n\n* docs: update getAllowedTmpRoots comment\n\n---------\n\nCo-authored-by: Zylos10 <zylos10@zylos.ai>\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>\nCo-authored-by: Zylos <zylos@zylos.ai>",
          "is_bot": false,
          "headline": "fix: upgrade --temp-dir safety checks to prevent directory deletion (…",
          "author_name": "voya",
          "author_login": "voyax",
          "committed_at": "2026-04-08T08:50:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1345d45ae7e978b360694eedfa32d2836dc2aa18",
          "body": "Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: add PR #479 to CHANGELOG for v0.4.11 (#480)",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-04-02T12:40:24Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "71e383501964a13d36a9767b977316ec1e9a1c72",
          "body": "…479)\n\nThe 30-min periodic probe bypassed the heartbeatEnabled config flag,\nsending heartbeat checks even when heartbeat was disabled by default.\nNow gated by engine.heartbeatEnabled like primary heartbeat polling.\n\nAlso fixes outdated comment (\"3-min\" → \"30-min\") and probe reason\nstring (\"periodic_3min\" → \"periodic_30min\").\n\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(activity-monitor): gate periodic probe behind heartbeatEnabled (#…",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-04-02T12:31:15Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "30e205d3926e3362bb6506211ea2d9d90e00dafb",
          "body": "* chore: bump version to 0.4.11 and update changelog\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>\n\n* chore: update release process and sync package-lock.json\n\n- Add package-lock.json step to release process in CLAUDE.md\n- Remove superseded version convention\n- Sync package-lock.json with\n[…]\nply@anthropic.com>\n\n* docs: update CHANGELOG for block-queue-until-idle fix\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Release v0.4.11 (#478)",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-04-02T11:47:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "fd03fe998aa2872b59bb0356a1926a16c4490087",
          "body": "…y paths (#477)\n\nheartbeatEnabled=false was a full kill switch that blocked ALL heartbeat\nprocessing in processHeartbeat(), including recovery probes, rate_limited\ncooldown handling, signal acceleration, and down-check. This meant that\ndisabling periodic heartbeat polling also disabled all health re\n[…]\n All other paths (pending result processing, rate_limited→recovering,\nsignal acceleration, recovering backoff, down-check) remain fully active.\n\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix heartbeatEnabled scope: only disable primary polling, not recover…",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-04-02T09:38:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "45685c1f4f76ffeff75bfcf805c101db5f1b1e41",
          "body": "feat: disable autoMemoryEnabled and autoDreamEnabled by default",
          "is_bot": false,
          "headline": "Merge pull request #476 from zylos-ai/feat/disable-auto-memory-dream",
          "author_name": "voya",
          "author_login": "voyax",
          "committed_at": "2026-04-01T18:29:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4aecdb90b29e10b4211e19c63157cfe9aa6fd254",
          "body": "Zylos has its own memory system — Claude's built-in auto-memory and\nauto-dream should be off by default to avoid conflicts. Uses the same\nbackfill pattern as model: set on init/upgrade if absent, preserve if\nuser already configured.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: disable autoMemoryEnabled and autoDreamEnabled by default",
          "author_name": "zylos-01",
          "author_login": null,
          "committed_at": "2026-04-01T18:21:25Z",
          "body_truncated": false,
          "is_coding_agent": true
        }
      ],
      "releases_count": 50,
      "commits_last_year": 588,
      "latest_release_at": "2026-07-14T14:42:51Z",
      "latest_release_tag": "v0.6.0",
      "releases_from_tags": false,
      "days_since_last_push": 2,
      "active_weeks_last_year": 24,
      "days_since_latest_release": 8,
      "mean_days_between_releases": 12
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 87,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "web-console",
          "exists": true,
          "license": "BSD-3-Clause",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": null,
          "registry_url": "https://www.npmjs.com/package/web-console",
          "is_deprecated": false,
          "latest_version": "0.0.0",
          "repository_url": null,
          "versions_count": 1,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 65,
          "first_published_at": "2015-08-10T21:10:20.756000Z",
          "latest_published_at": "2015-08-10T21:10:20.756000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 3998
        }
      ]
    },
    "popularity": {
      "forks": 119,
      "stars": 1136,
      "watchers": 66,
      "fork_history": {
        "days": [
          {
            "date": "2026-02-11",
            "count": 3
          },
          {
            "date": "2026-02-12",
            "count": 1
          },
          {
            "date": "2026-02-13",
            "count": 1
          },
          {
            "date": "2026-02-14",
            "count": 3
          },
          {
            "date": "2026-02-15",
            "count": 1
          },
          {
            "date": "2026-02-16",
            "count": 2
          },
          {
            "date": "2026-02-17",
            "count": 2
          },
          {
            "date": "2026-02-18",
            "count": 2
          },
          {
            "date": "2026-02-19",
            "count": 4
          },
          {
            "date": "2026-02-20",
            "count": 2
          },
          {
            "date": "2026-02-21",
            "count": 2
          },
          {
            "date": "2026-02-23",
            "count": 4
          },
          {
            "date": "2026-02-24",
            "count": 2
          },
          {
            "date": "2026-02-25",
            "count": 1
          },
          {
            "date": "2026-02-26",
            "count": 4
          },
          {
            "date": "2026-02-28",
            "count": 1
          },
          {
            "date": "2026-03-01",
            "count": 2
          },
          {
            "date": "2026-03-02",
            "count": 1
          },
          {
            "date": "2026-03-04",
            "count": 1
          },
          {
            "date": "2026-03-06",
            "count": 2
          },
          {
            "date": "2026-03-07",
            "count": 1
          },
          {
            "date": "2026-03-08",
            "count": 2
          },
          {
            "date": "2026-03-09",
            "count": 2
          },
          {
            "date": "2026-03-10",
            "count": 1
          },
          {
            "date": "2026-03-12",
            "count": 3
          },
          {
            "date": "2026-03-13",
            "count": 1
          },
          {
            "date": "2026-03-14",
            "count": 1
          },
          {
            "date": "2026-03-15",
            "count": 3
          },
          {
            "date": "2026-03-16",
            "count": 3
          },
          {
            "date": "2026-03-18",
            "count": 2
          },
          {
            "date": "2026-03-20",
            "count": 3
          },
          {
            "date": "2026-03-21",
            "count": 1
          },
          {
            "date": "2026-03-22",
            "count": 1
          },
          {
            "date": "2026-03-23",
            "count": 1
          },
          {
            "date": "2026-03-24",
            "count": 3
          },
          {
            "date": "2026-03-25",
            "count": 2
          },
          {
            "date": "2026-03-26",
            "count": 2
          },
          {
            "date": "2026-03-27",
            "count": 1
          },
          {
            "date": "2026-03-28",
            "count": 1
          },
          {
            "date": "2026-03-29",
            "count": 1
          },
          {
            "date": "2026-03-30",
            "count": 3
          },
          {
            "date": "2026-03-31",
            "count": 2
          },
          {
            "date": "2026-04-01",
            "count": 6
          },
          {
            "date": "2026-04-02",
            "count": 3
          },
          {
            "date": "2026-04-03",
            "count": 1
          },
          {
            "date": "2026-04-04",
            "count": 3
          },
          {
            "date": "2026-04-05",
            "count": 2
          },
          {
            "date": "2026-04-06",
            "count": 2
          },
          {
            "date": "2026-04-08",
            "count": 2
          },
          {
            "date": "2026-04-09",
            "count": 2
          },
          {
            "date": "2026-04-10",
            "count": 1
          },
          {
            "date": "2026-04-12",
            "count": 2
          },
          {
            "date": "2026-04-14",
            "count": 2
          },
          {
            "date": "2026-04-15",
            "count": 2
          },
          {
            "date": "2026-04-17",
            "count": 1
          },
          {
            "date": "2026-04-18",
            "count": 1
          },
          {
            "date": "2026-04-19",
            "count": 2
          },
          {
            "date": "2026-05-08",
            "count": 2
          },
          {
            "date": "2026-05-22",
            "count": 1
          },
          {
            "date": "2026-05-28",
            "count": 1
          },
          {
            "date": "2026-06-20",
            "count": 1
          },
          {
            "date": "2026-07-18",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 119,
        "total_forks": 119
      },
      "star_history": null,
      "open_issues_and_prs": 137
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [],
      "largest_source_bytes": 124245,
      "source_files_sampled": 229,
      "oversized_source_files": 4,
      "agent_instruction_files": [
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 6158
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [
          {
            "name": "js-yaml",
            "direct": true,
            "version": "3.14.2",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-52cp-r559-cp3m",
              "GHSA-h67p-54hq-rp68"
            ],
            "fixed_version": "4.3.0",
            "advisory_count": 2,
            "oldest_advisory_days": 37
          },
          {
            "name": "js-yaml",
            "direct": true,
            "version": "4.1.1",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-52cp-r559-cp3m",
              "GHSA-h67p-54hq-rp68"
            ],
            "fixed_version": "4.3.0",
            "advisory_count": 2,
            "oldest_advisory_days": 37
          },
          {
            "name": "multer",
            "direct": true,
            "version": "2.1.1",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-3p4h-7m6x-2hcm",
              "GHSA-72gw-mp4g-v24j"
            ],
            "fixed_version": "3.0.0-alpha.2",
            "advisory_count": 2,
            "oldest_advisory_days": 35
          },
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "1.1.13",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-3jxr-9vmj-r5cp"
            ],
            "fixed_version": "5.0.7",
            "advisory_count": 1,
            "oldest_advisory_days": 1
          },
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "2.0.3",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-3jxr-9vmj-r5cp"
            ],
            "fixed_version": "5.0.7",
            "advisory_count": 1,
            "oldest_advisory_days": 1
          },
          {
            "name": "@babel/core",
            "direct": false,
            "version": "7.29.0",
            "severity": "low",
            "ecosystem": "npm",
            "cvss_score": 3.2,
            "advisory_ids": [
              "GHSA-4x5r-pxfx-6jf8"
            ],
            "fixed_version": "8.0.0-rc.6",
            "advisory_count": 1,
            "oldest_advisory_days": 37
          },
          {
            "name": "body-parser",
            "direct": false,
            "version": "1.20.4",
            "severity": "low",
            "ecosystem": "npm",
            "cvss_score": 3.7,
            "advisory_ids": [
              "GHSA-v422-hmwv-36x6"
            ],
            "fixed_version": "2.3.0",
            "advisory_count": 1,
            "oldest_advisory_days": 1
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "low": 2,
          "high": 5
        },
        "advisory_count": 10,
        "affected_count": 7,
        "assessed_count": 413,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 3
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "dotenv",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^16.4.7"
        },
        {
          "name": "js-yaml",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.1.1"
        },
        {
          "name": "smol-toml",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.6.1"
        },
        {
          "name": "dotenv",
          "manifest": "skills/activity-monitor/package.json",
          "ecosystem": "npm",
          "version_constraint": "^16.6.1"
        },
        {
          "name": "better-sqlite3",
          "manifest": "skills/comm-bridge/package.json",
          "ecosystem": "npm",
          "version_constraint": "^12.6.2"
        },
        {
          "name": "better-sqlite3",
          "manifest": "skills/scheduler/package.json",
          "ecosystem": "npm",
          "version_constraint": "^12.6.2"
        },
        {
          "name": "chrono-node",
          "manifest": "skills/scheduler/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.7.7"
        },
        {
          "name": "cron-parser",
          "manifest": "skills/scheduler/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.9.0"
        },
        {
          "name": "dotenv",
          "manifest": "skills/scheduler/package.json",
          "ecosystem": "npm",
          "version_constraint": "^16.6.1"
        },
        {
          "name": "better-sqlite3",
          "manifest": "skills/web-console/package.json",
          "ecosystem": "npm",
          "version_constraint": "^12.6.2"
        },
        {
          "name": "dotenv",
          "manifest": "skills/web-console/package.json",
          "ecosystem": "npm",
          "version_constraint": "^16.6.1"
        },
        {
          "name": "express",
          "manifest": "skills/web-console/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.18.2"
        },
        {
          "name": "multer",
          "manifest": "skills/web-console/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.1.1"
        },
        {
          "name": "ws",
          "manifest": "skills/web-console/package.json",
          "ecosystem": "npm",
          "version_constraint": "^8.20.1"
        },
        {
          "name": "dotenv",
          "manifest": "skills/zylos-memory/package.json",
          "ecosystem": "npm",
          "version_constraint": "^16.6.1"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "better-sqlite3",
            "direct": true,
            "version": "12.6.2",
            "ecosystem": "npm"
          },
          {
            "name": "chrono-node",
            "direct": true,
            "version": "2.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "cron-parser",
            "direct": true,
            "version": "4.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "dotenv",
            "direct": true,
            "version": "16.6.1",
            "ecosystem": "npm"
          },
          {
            "name": "express",
            "direct": true,
            "version": "4.22.1",
            "ecosystem": "npm"
          },
          {
            "name": "js-yaml",
            "direct": true,
            "version": "3.14.2",
            "ecosystem": "npm"
          },
          {
            "name": "js-yaml",
            "direct": true,
            "version": "4.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "multer",
            "direct": true,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "smol-toml",
            "direct": true,
            "version": "1.6.1",
            "ecosystem": "npm"
          },
          {
            "name": "ws",
            "direct": true,
            "version": "8.21.0",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/code-frame",
            "direct": false,
            "version": "7.29.0",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/compat-data",
            "direct": false,
            "version": "7.29.0",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/core",
            "direct": false,
            "version": "7.29.0",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/generator",
            "direct": false,
            "version": "7.29.1",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-compilation-targets",
            "direct": false,
            "version": "7.28.6",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-globals",
            "direct": false,
            "version": "7.28.0",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-module-imports",
            "direct": false,
            "version": "7.28.6",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-module-transforms",
            "direct": false,
            "version": "7.28.6",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-plugin-utils",
            "direct": false,
            "version": "7.28.6",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-string-parser",
            "direct": false,
            "version": "7.27.1",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-validator-identifier",
            "direct": false,
            "version": "7.28.5",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-validator-option",
            "direct": false,
            "version": "7.27.1",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helpers",
            "direct": false,
            "version": "7.29.2",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/parser",
            "direct": false,
            "version": "7.29.2",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-async-generators",
            "direct": false,
            "version": "7.8.4",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-bigint",
            "direct": false,
            "version": "7.8.3",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-class-properties",
            "direct": false,
            "version": "7.12.13",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-class-static-block",
            "direct": false,
            "version": "7.14.5",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-import-attributes",
            "direct": false,
            "version": "7.28.6",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-import-meta",
            "direct": false,
            "version": "7.10.4",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-json-strings",
            "direct": false,
            "version": "7.8.3",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-jsx",
            "direct": false,
            "version": "7.28.6",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-logical-assignment-operators",
            "direct": false,
            "version": "7.10.4",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-nullish-coalescing-operator",
            "direct": false,
            "version": "7.8.3",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-numeric-separator",
            "direct": false,
            "version": "7.10.4",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-object-rest-spread",
            "direct": false,
            "version": "7.8.3",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-optional-catch-binding",
            "direct": false,
            "version": "7.8.3",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-optional-chaining",
            "direct": false,
            "version": "7.8.3",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-private-property-in-object",
            "direct": false,
            "version": "7.14.5",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-top-level-await",
            "direct": false,
            "version": "7.14.5",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-typescript",
            "direct": false,
            "version": "7.28.6",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/template",
            "direct": false,
            "version": "7.28.6",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/traverse",
            "direct": false,
            "version": "7.29.0",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/types",
            "direct": false,
            "version": "7.29.0",
            "ecosystem": "npm"
          },
          {
            "name": "@bcoe/v8-coverage",
            "direct": false,
            "version": "0.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "@emnapi/core",
            "direct": false,
            "version": "1.9.1",
            "ecosystem": "npm"
          },
          {
            "name": "@emnapi/runtime",
            "direct": false,
            "version": "1.9.1",
            "ecosystem": "npm"
          },
          {
            "name": "@emnapi/wasi-threads",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@isaacs/cliui",
            "direct": false,
            "version": "8.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@istanbuljs/load-nyc-config",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@istanbuljs/schema",
            "direct": false,
            "version": "0.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/console",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/core",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/diff-sequences",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/environment",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/expect",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/expect-utils",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/fake-timers",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/get-type",
            "direct": false,
            "version": "30.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/globals",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/pattern",
            "direct": false,
            "version": "30.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/reporters",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/schemas",
            "direct": false,
            "version": "30.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/snapshot-utils",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/source-map",
            "direct": false,
            "version": "30.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/test-result",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/test-sequencer",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/transform",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/types",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/gen-mapping",
            "direct": false,
            "version": "0.3.13",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/remapping",
            "direct": false,
            "version": "2.3.5",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/resolve-uri",
            "direct": false,
            "version": "3.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/sourcemap-codec",
            "direct": false,
            "version": "1.5.5",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/trace-mapping",
            "direct": false,
            "version": "0.3.31",
            "ecosystem": "npm"
          },
          {
            "name": "@napi-rs/wasm-runtime",
            "direct": false,
            "version": "0.2.12",
            "ecosystem": "npm"
          },
          {
            "name": "@pkgjs/parseargs",
            "direct": false,
            "version": "0.11.0",
            "ecosystem": "npm"
          },
          {
            "name": "@pkgr/core",
            "direct": false,
            "version": "0.2.9",
            "ecosystem": "npm"
          },
          {
            "name": "@sinclair/typebox",
            "direct": false,
            "version": "0.34.48",
            "ecosystem": "npm"
          },
          {
            "name": "@sinonjs/commons",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "@sinonjs/fake-timers",
            "direct": false,
            "version": "15.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "@tybys/wasm-util",
            "direct": false,
            "version": "0.10.1",
            "ecosystem": "npm"
          },
          {
            "name": "@types/babel__core",
            "direct": false,
            "version": "7.20.5",
            "ecosystem": "npm"
          },
          {
            "name": "@types/babel__generator",
            "direct": false,
            "version": "7.27.0",
            "ecosystem": "npm"
          },
          {
            "name": "@types/babel__template",
            "direct": false,
            "version": "7.4.4",
            "ecosystem": "npm"
          },
          {
            "name": "@types/babel__traverse",
            "direct": false,
            "version": "7.28.0",
            "ecosystem": "npm"
          },
          {
            "name": "@types/istanbul-lib-coverage",
            "direct": false,
            "version": "2.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "@types/istanbul-lib-report",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@types/istanbul-reports",
            "direct": false,
            "version": "3.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "@types/node",
            "direct": false,
            "version": "25.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "@types/stack-utils",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@types/yargs",
            "direct": false,
            "version": "17.0.35",
            "ecosystem": "npm"
          },
          {
            "name": "@types/yargs-parser",
            "direct": false,
            "version": "21.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@ungap/structured-clone",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@unrs/resolver-binding-android-arm-eabi",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "@unrs/resolver-binding-android-arm64",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "@unrs/resolver-binding-darwin-arm64",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "@unrs/resolver-binding-darwin-x64",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "@unrs/resolver-binding-freebsd-x64",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "@unrs/resolver-binding-linux-arm-gnueabihf",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "@unrs/resolver-binding-linux-arm-musleabihf",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "@unrs/resolver-binding-linux-arm64-gnu",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "@unrs/resolver-binding-linux-arm64-musl",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "@unrs/resolver-binding-linux-ppc64-gnu",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "@unrs/resolver-binding-linux-riscv64-gnu",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "@unrs/resolver-binding-linux-riscv64-musl",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "@unrs/resolver-binding-linux-s390x-gnu",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "@unrs/resolver-binding-linux-x64-gnu",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "@unrs/resolver-binding-linux-x64-musl",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "@unrs/resolver-binding-wasm32-wasi",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "@unrs/resolver-binding-win32-arm64-msvc",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "@unrs/resolver-binding-win32-ia32-msvc",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "@unrs/resolver-binding-win32-x64-msvc",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "accepts",
            "direct": false,
            "version": "1.3.8",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-escapes",
            "direct": false,
            "version": "4.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-regex",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-regex",
            "direct": false,
            "version": "6.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-styles",
            "direct": false,
            "version": "4.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-styles",
            "direct": false,
            "version": "5.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-styles",
            "direct": false,
            "version": "6.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "anymatch",
            "direct": false,
            "version": "3.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "append-field",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "argparse",
            "direct": false,
            "version": "1.0.10",
            "ecosystem": "npm"
          },
          {
            "name": "argparse",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "array-flatten",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "babel-jest",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "babel-plugin-istanbul",
            "direct": false,
            "version": "7.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "babel-plugin-jest-hoist",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "babel-preset-current-node-syntax",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "babel-preset-jest",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "balanced-match",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "base64-js",
            "direct": false,
            "version": "1.5.1",
            "ecosystem": "npm"
          },
          {
            "name": "baseline-browser-mapping",
            "direct": false,
            "version": "2.10.11",
            "ecosystem": "npm"
          },
          {
            "name": "bindings",
            "direct": false,
            "version": "1.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "bl",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "body-parser",
            "direct": false,
            "version": "1.20.4",
            "ecosystem": "npm"
          },
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "1.1.13",
            "ecosystem": "npm"
          },
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "browserslist",
            "direct": false,
            "version": "4.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "bser",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "buffer",
            "direct": false,
            "version": "5.7.1",
            "ecosystem": "npm"
          },
          {
            "name": "buffer-from",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "busboy",
            "direct": false,
            "version": "1.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "bytes",
            "direct": false,
            "version": "3.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "call-bind-apply-helpers",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "call-bound",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "callsites",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "camelcase",
            "direct": false,
            "version": "5.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "camelcase",
            "direct": false,
            "version": "6.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "caniuse-lite",
            "direct": false,
            "version": "1.0.30001781",
            "ecosystem": "npm"
          },
          {
            "name": "chalk",
            "direct": false,
            "version": "4.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "char-regex",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "chownr",
            "direct": false,
            "version": "1.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "ci-info",
            "direct": false,
            "version": "4.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "cjs-module-lexer",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "cliui",
            "direct": false,
            "version": "8.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "co",
            "direct": false,
            "version": "4.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "collect-v8-coverage",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "color-convert",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "color-name",
            "direct": false,
            "version": "1.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "concat-map",
            "direct": false,
            "version": "0.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "concat-stream",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "content-disposition",
            "direct": false,
            "version": "0.5.4",
            "ecosystem": "npm"
          },
          {
            "name": "content-type",
            "direct": false,
            "version": "1.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "convert-source-map",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "cookie",
            "direct": false,
            "version": "0.7.2",
            "ecosystem": "npm"
          },
          {
            "name": "cookie-signature",
            "direct": false,
            "version": "1.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "cross-spawn",
            "direct": false,
            "version": "7.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "debug",
            "direct": false,
            "version": "2.6.9",
            "ecosystem": "npm"
          },
          {
            "name": "debug",
            "direct": false,
            "version": "4.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "decompress-response",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "dedent",
            "direct": false,
            "version": "1.7.2",
            "ecosystem": "npm"
          },
          {
            "name": "deep-extend",
            "direct": false,
            "version": "0.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "deepmerge",
            "direct": false,
            "version": "4.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "depd",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "destroy",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "detect-libc",
            "direct": false,
            "version": "2.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "detect-newline",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "dunder-proto",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "eastasianwidth",
            "direct": false,
            "version": "0.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "ee-first",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "electron-to-chromium",
            "direct": false,
            "version": "1.5.328",
            "ecosystem": "npm"
          },
          {
            "name": "emittery",
            "direct": false,
            "version": "0.13.1",
            "ecosystem": "npm"
          },
          {
            "name": "emoji-regex",
            "direct": false,
            "version": "8.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "emoji-regex",
            "direct": false,
            "version": "9.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "encodeurl",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "end-of-stream",
            "direct": false,
            "version": "1.4.5",
            "ecosystem": "npm"
          },
          {
            "name": "error-ex",
            "direct": false,
            "version": "1.3.4",
            "ecosystem": "npm"
          },
          {
            "name": "es-define-property",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "es-errors",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "es-object-atoms",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "escalade",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "escape-html",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "escape-string-regexp",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "esprima",
            "direct": false,
            "version": "4.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "etag",
            "direct": false,
            "version": "1.8.1",
            "ecosystem": "npm"
          },
          {
            "name": "execa",
            "direct": false,
            "version": "5.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "exit-x",
            "direct": false,
            "version": "0.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "expand-template",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "expect",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "fast-json-stable-stringify",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "fb-watchman",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "file-uri-to-path",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "finalhandler",
            "direct": false,
            "version": "1.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "find-up",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "foreground-child",
            "direct": false,
            "version": "3.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "forwarded",
            "direct": false,
            "version": "0.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "fresh",
            "direct": false,
            "version": "0.5.2",
            "ecosystem": "npm"
          },
          {
            "name": "fs-constants",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "fs.realpath",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "fsevents",
            "direct": false,
            "version": "2.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "function-bind",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "gensync",
            "direct": false,
            "version": "1.0.0-beta.2",
            "ecosystem": "npm"
          },
          {
            "name": "get-caller-file",
            "direct": false,
            "version": "2.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "get-intrinsic",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "get-package-type",
            "direct": false,
            "version": "0.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "get-proto",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "get-stream",
            "direct": false,
            "version": "6.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "github-from-package",
            "direct": false,
            "version": "0.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "glob",
            "direct": false,
            "version": "10.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "glob",
            "direct": false,
            "version": "7.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "gopd",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "graceful-fs",
            "direct": false,
            "version": "4.2.11",
            "ecosystem": "npm"
          },
          {
            "name": "has-flag",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "has-symbols",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "hasown",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "html-escaper",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "http-errors",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "human-signals",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "iconv-lite",
            "direct": false,
            "version": "0.4.24",
            "ecosystem": "npm"
          },
          {
            "name": "ieee754",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "import-local",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "imurmurhash",
            "direct": false,
            "version": "0.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "inflight",
            "direct": false,
            "version": "1.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "inherits",
            "direct": false,
            "version": "2.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "ini",
            "direct": false,
            "version": "1.3.8",
            "ecosystem": "npm"
          },
          {
            "name": "ipaddr.js",
            "direct": false,
            "version": "1.9.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-arrayish",
            "direct": false,
            "version": "0.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-fullwidth-code-point",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-generator-fn",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-stream",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "isexe",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-lib-coverage",
            "direct": false,
            "version": "3.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-lib-instrument",
            "direct": false,
            "version": "6.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-lib-report",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-lib-source-maps",
            "direct": false,
            "version": "5.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-reports",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "jackspeak",
            "direct": false,
            "version": "3.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "jest",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-changed-files",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-circus",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-cli",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-config",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-diff",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-docblock",
            "direct": false,
            "version": "30.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-each",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-environment-node",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-haste-map",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-leak-detector",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-matcher-utils",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-message-util",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-mock",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-pnp-resolver",
            "direct": false,
            "version": "1.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "jest-regex-util",
            "direct": false,
            "version": "30.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "jest-resolve",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-resolve-dependencies",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-runner",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-runtime",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-snapshot",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-util",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-validate",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-watcher",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-worker",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "js-tokens",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "jsesc",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "json-parse-even-better-errors",
            "direct": false,
            "version": "2.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "json5",
            "direct": false,
            "version": "2.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "leven",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "lines-and-columns",
            "direct": false,
            "version": "1.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "locate-path",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "lru-cache",
            "direct": false,
            "version": "10.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "lru-cache",
            "direct": false,
            "version": "5.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "luxon",
            "direct": false,
            "version": "3.7.2",
            "ecosystem": "npm"
          },
          {
            "name": "make-dir",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "makeerror",
            "direct": false,
            "version": "1.0.12",
            "ecosystem": "npm"
          },
          {
            "name": "math-intrinsics",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "media-typer",
            "direct": false,
            "version": "0.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "merge-descriptors",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "merge-stream",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "methods",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "mime",
            "direct": false,
            "version": "1.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "mime-db",
            "direct": false,
            "version": "1.52.0",
            "ecosystem": "npm"
          },
          {
            "name": "mime-types",
            "direct": false,
            "version": "2.1.35",
            "ecosystem": "npm"
          },
          {
            "name": "mimic-fn",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "mimic-response",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "minimatch",
            "direct": false,
            "version": "3.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "minimatch",
            "direct": false,
            "version": "9.0.9",
            "ecosystem": "npm"
          },
          {
            "name": "minimist",
            "direct": false,
            "version": "1.2.8",
            "ecosystem": "npm"
          },
          {
            "name": "minipass",
            "direct": false,
            "version": "7.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "mkdirp-classic",
            "direct": false,
            "version": "0.5.3",
            "ecosystem": "npm"
          },
          {
            "name": "ms",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "ms",
            "direct": false,
            "version": "2.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "napi-build-utils",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "napi-postinstall",
            "direct": false,
            "version": "0.3.4",
            "ecosystem": "npm"
          },
          {
            "name": "natural-compare",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "negotiator",
            "direct": false,
            "version": "0.6.3",
            "ecosystem": "npm"
          },
          {
            "name": "node-abi",
            "direct": false,
            "version": "3.87.0",
            "ecosystem": "npm"
          },
          {
            "name": "node-int64",
            "direct": false,
            "version": "0.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "node-releases",
            "direct": false,
            "version": "2.0.36",
            "ecosystem": "npm"
          },
          {
            "name": "normalize-path",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "npm-run-path",
            "direct": false,
            "version": "4.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "object-inspect",
            "direct": false,
            "version": "1.13.4",
            "ecosystem": "npm"
          },
          {
            "name": "on-finished",
            "direct": false,
            "version": "2.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "once",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "onetime",
            "direct": false,
            "version": "5.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "p-limit",
            "direct": false,
            "version": "2.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "p-limit",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "p-locate",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "p-try",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "package-json-from-dist",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "parse-json",
            "direct": false,
            "version": "5.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "parseurl",
            "direct": false,
            "version": "1.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "path-exists",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "path-is-absolute",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "path-key",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "path-scurry",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "path-to-regexp",
            "direct": false,
            "version": "0.1.13",
            "ecosystem": "npm"
          },
          {
            "name": "picocolors",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "picomatch",
            "direct": false,
            "version": "2.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "picomatch",
            "direct": false,
            "version": "4.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "pirates",
            "direct": false,
            "version": "4.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "pkg-dir",
            "direct": false,
            "version": "4.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "prebuild-install",
            "direct": false,
            "version": "7.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "pretty-format",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "proxy-addr",
            "direct": false,
            "version": "2.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "pump",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "pure-rand",
            "direct": false,
            "version": "7.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "qs",
            "direct": false,
            "version": "6.15.2",
            "ecosystem": "npm"
          },
          {
            "name": "range-parser",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "raw-body",
            "direct": false,
            "version": "2.5.3",
            "ecosystem": "npm"
          },
          {
            "name": "rc",
            "direct": false,
            "version": "1.2.8",
            "ecosystem": "npm"
          },
          {
            "name": "react-is",
            "direct": false,
            "version": "18.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "readable-stream",
            "direct": false,
            "version": "3.6.2",
            "ecosystem": "npm"
          },
          {
            "name": "require-directory",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "resolve-cwd",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "resolve-from",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "safe-buffer",
            "direct": false,
            "version": "5.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "safer-buffer",
            "direct": false,
            "version": "2.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "semver",
            "direct": false,
            "version": "6.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "semver",
            "direct": false,
            "version": "7.7.3",
            "ecosystem": "npm"
          },
          {
            "name": "semver",
            "direct": false,
            "version": "7.7.4",
            "ecosystem": "npm"
          },
          {
            "name": "send",
            "direct": false,
            "version": "0.19.2",
            "ecosystem": "npm"
          },
          {
            "name": "serve-static",
            "direct": false,
            "version": "1.16.3",
            "ecosystem": "npm"
          },
          {
            "name": "setprototypeof",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "shebang-command",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "shebang-regex",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "side-channel",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "side-channel-list",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "side-channel-map",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "side-channel-weakmap",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "signal-exit",
            "direct": false,
            "version": "3.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "signal-exit",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "simple-concat",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "simple-get",
            "direct": false,
            "version": "4.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "slash",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "source-map",
            "direct": false,
            "version": "0.6.1",
            "ecosystem": "npm"
          },
          {
            "name": "source-map-support",
            "direct": false,
            "version": "0.5.13",
            "ecosystem": "npm"
          },
          {
            "name": "sprintf-js",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "stack-utils",
            "direct": false,
            "version": "2.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "statuses",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "streamsearch",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "string-length",
            "direct": false,
            "version": "4.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "string-width",
            "direct": false,
            "version": "4.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "string-width",
            "direct": false,
            "version": "5.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "string_decoder",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "strip-ansi",
            "direct": false,
            "version": "6.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "strip-ansi",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "strip-bom",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "strip-final-newline",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "strip-json-comments",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "strip-json-comments",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "supports-color",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "supports-color",
            "direct": false,
            "version": "8.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "synckit",
            "direct": false,
            "version": "0.11.12",
            "ecosystem": "npm"
          },
          {
            "name": "tar-fs",
            "direct": false,
            "version": "2.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "tar-stream",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "test-exclude",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "tmpl",
            "direct": false,
            "version": "1.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "toidentifier",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "tslib",
            "direct": false,
            "version": "2.8.1",
            "ecosystem": "npm"
          },
          {
            "name": "tunnel-agent",
            "direct": false,
            "version": "0.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "type-detect",
            "direct": false,
            "version": "4.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "type-fest",
            "direct": false,
            "version": "0.21.3",
            "ecosystem": "npm"
          },
          {
            "name": "type-is",
            "direct": false,
            "version": "1.6.18",
            "ecosystem": "npm"
          },
          {
            "name": "typedarray",
            "direct": false,
            "version": "0.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "undici-types",
            "direct": false,
            "version": "7.18.2",
            "ecosystem": "npm"
          },
          {
            "name": "unpipe",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "unrs-resolver",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "update-browserslist-db",
            "direct": false,
            "version": "1.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "util-deprecate",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "utils-merge",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "v8-to-istanbul",
            "direct": false,
            "version": "9.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "vary",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "walker",
            "direct": false,
            "version": "1.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "which",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "wrap-ansi",
            "direct": false,
            "version": "7.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "wrap-ansi",
            "direct": false,
            "version": "8.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "wrappy",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "write-file-atomic",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "y18n",
            "direct": false,
            "version": "5.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "yallist",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "yargs",
            "direct": false,
            "version": "17.7.2",
            "ecosystem": "npm"
          },
          {
            "name": "yargs-parser",
            "direct": false,
            "version": "21.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "yocto-queue",
            "direct": false,
            "version": "0.1.0",
            "ecosystem": "npm"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 413,
        "direct_count": 10,
        "indirect_count": 403
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 34,
        "merged_prs": 374,
        "open_issues": 103,
        "closed_ratio": 0.591,
        "closed_issues": 149,
        "closed_unmerged_prs": 41
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "voyax",
          "commits": 293,
          "avatar_url": "https://avatars.githubusercontent.com/u/13559404?v=4"
        },
        {
          "type": "User",
          "login": "zylos-luna",
          "commits": 163,
          "avatar_url": "https://avatars.githubusercontent.com/u/258754527?v=4"
        },
        {
          "type": "User",
          "login": "jinglever",
          "commits": 19,
          "avatar_url": "https://avatars.githubusercontent.com/u/267884994?v=4"
        },
        {
          "type": "User",
          "login": "zylos-luna-coco",
          "commits": 17,
          "avatar_url": "https://avatars.githubusercontent.com/u/300354114?v=4"
        },
        {
          "type": "User",
          "login": "zz-howard",
          "commits": 10,
          "avatar_url": "https://avatars.githubusercontent.com/u/4019224?v=4"
        },
        {
          "type": "User",
          "login": "leslielin2025",
          "commits": 9,
          "avatar_url": "https://avatars.githubusercontent.com/u/225646034?v=4"
        },
        {
          "type": "User",
          "login": "FelixLin6",
          "commits": 5,
          "avatar_url": "https://avatars.githubusercontent.com/u/68569236?v=4"
        },
        {
          "type": "User",
          "login": "kevinho",
          "commits": 5,
          "avatar_url": "https://avatars.githubusercontent.com/u/546824?v=4"
        },
        {
          "type": "User",
          "login": "eric-sss89",
          "commits": 5,
          "avatar_url": "https://avatars.githubusercontent.com/u/12973536?v=4"
        },
        {
          "type": "User",
          "login": "jessie-coco",
          "commits": 4,
          "avatar_url": "https://avatars.githubusercontent.com/u/259836333?v=4"
        }
      ],
      "contributors_sampled": 19,
      "top_contributor_share": 0.538
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "docker-publish.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 6,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 0,
            "reason": "0 out of 30 merged PRs checked by a CI test -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 10,
            "reason": "all changesets reviewed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 3,
            "reason": "project has 1 contributing companies or organizations -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 9,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 3,
            "reason": "7 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "7a034ca2e55457bf114d4973b7df04ca207371eb",
        "ran_at": "2026-07-22T18:54:49Z",
        "aggregate_score": 6.1,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-15T01:56:11Z",
      "oldest_open_prs": [
        {
          "number": 144,
          "created_at": "2026-02-23T05:38:53Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 146,
          "created_at": "2026-02-23T13:43:32Z",
          "last_comment_at": "2026-02-26T07:51:47Z",
          "last_comment_author": "zylos-luna"
        },
        {
          "number": 152,
          "created_at": "2026-02-25T10:41:03Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 277,
          "created_at": "2026-03-08T11:49:59Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 373,
          "created_at": "2026-03-20T23:07:42Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 389,
          "created_at": "2026-03-24T14:49:36Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 390,
          "created_at": "2026-03-25T06:02:28Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 420,
          "created_at": "2026-03-26T08:09:38Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 468,
          "created_at": "2026-04-01T08:11:39Z",
          "last_comment_at": "2026-04-01T19:20:24Z",
          "last_comment_author": "zylos-luna"
        },
        {
          "number": 501,
          "created_at": "2026-04-17T01:47:01Z",
          "last_comment_at": "2026-04-28T13:37:49Z",
          "last_comment_author": "leslielin2025"
        },
        {
          "number": 503,
          "created_at": "2026-04-19T05:14:48Z",
          "last_comment_at": "2026-04-19T15:45:18Z",
          "last_comment_author": "zylos-luna"
        },
        {
          "number": 505,
          "created_at": "2026-04-20T00:04:20Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 507,
          "created_at": "2026-04-20T10:45:47Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 509,
          "created_at": "2026-04-21T07:35:28Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 510,
          "created_at": "2026-04-21T13:38:34Z",
          "last_comment_at": "2026-04-27T18:07:10Z",
          "last_comment_author": "jinglever"
        },
        {
          "number": 513,
          "created_at": "2026-04-24T10:07:10Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 518,
          "created_at": "2026-04-28T13:37:38Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 530,
          "created_at": "2026-05-06T02:23:16Z",
          "last_comment_at": "2026-05-06T07:09:34Z",
          "last_comment_author": "zylos-luna"
        },
        {
          "number": 544,
          "created_at": "2026-05-06T14:33:41Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 566,
          "created_at": "2026-05-08T06:09:25Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-15T01:55:00Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 42,
          "created_at": "2026-02-07T15:56:28Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 139,
          "created_at": "2026-02-22T07:16:02Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 169,
          "created_at": "2026-02-26T15:00:50Z",
          "last_comment_at": "2026-03-19T18:15:02Z",
          "last_comment_author": "voyax"
        },
        {
          "number": 189,
          "created_at": "2026-02-28T02:43:38Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 223,
          "created_at": "2026-03-04T08:01:24Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 237,
          "created_at": "2026-03-05T03:53:26Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 243,
          "created_at": "2026-03-05T11:37:58Z",
          "last_comment_at": "2026-03-19T18:14:59Z",
          "last_comment_author": "voyax"
        },
        {
          "number": 245,
          "created_at": "2026-03-05T11:51:35Z",
          "last_comment_at": "2026-03-19T18:15:05Z",
          "last_comment_author": "voyax"
        },
        {
          "number": 246,
          "created_at": "2026-03-05T11:54:10Z",
          "last_comment_at": "2026-03-23T17:04:12Z",
          "last_comment_author": "m13v"
        },
        {
          "number": 250,
          "created_at": "2026-03-06T03:39:09Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 260,
          "created_at": "2026-03-06T16:08:27Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 262,
          "created_at": "2026-03-07T17:09:29Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 267,
          "created_at": "2026-03-08T09:12:40Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 268,
          "created_at": "2026-03-08T09:12:42Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 271,
          "created_at": "2026-03-08T09:12:49Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 272,
          "created_at": "2026-03-08T09:12:51Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 297,
          "created_at": "2026-03-10T15:48:51Z",
          "last_comment_at": "2026-03-19T18:15:01Z",
          "last_comment_author": "voyax"
        },
        {
          "number": 300,
          "created_at": "2026-03-11T03:34:28Z",
          "last_comment_at": "2026-03-11T03:35:49Z",
          "last_comment_author": "jessie-coco"
        },
        {
          "number": 305,
          "created_at": "2026-03-11T06:57:30Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 320,
          "created_at": "2026-03-12T18:08:34Z",
          "last_comment_at": "2026-03-19T18:15:03Z",
          "last_comment_author": "voyax"
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/zylos-ai/zylos-core",
    "host": "github.com",
    "name": "zylos-core",
    "owner": "zylos-ai"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 68,
      "inputs": {
        "security": 62,
        "vitality": 89,
        "community": 70,
        "governance": 55,
        "engineering": 65
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 89,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 81,
            "inputs": {
              "commits_last_year": 588,
              "human_commit_share": 1,
              "days_since_last_push": 2,
              "active_weeks_last_year": 24
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 2 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 2
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "24/52 weeks with commits",
                "points": 16.6,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 24
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "588 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 588
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 50,
              "latest_release_tag": "v0.6.0",
              "releases_from_tags": false,
              "days_since_latest_release": 8,
              "mean_days_between_releases": 12
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "50 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 50
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 8 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 8
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~12 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 12
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "good",
        "name": "Community & Adoption",
        "value": 70,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "good",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 77,
            "inputs": {
              "forks": 119,
              "stars": 1136,
              "watchers": 66,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "1,136 stars",
                "points": 49.6,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 1136
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "119 forks",
                "points": 17.3,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 119
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "66 watchers",
                "points": 10.1,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 66
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "at_risk",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 30,
            "inputs": {
              "packages": [
                "web-console"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 65
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "65 downloads/month across npm",
                "points": 24.3,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 65,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 55,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "at_risk",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 36,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 19,
              "top_contributor_share": 0.538
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 54% of commits",
                "points": 10.4,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 54
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "19 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 19
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 77,
            "inputs": {
              "merged_prs": 374,
              "open_issues": 103,
              "closed_issues": 149,
              "issue_closed_ratio": 0.591,
              "closed_unmerged_prs": 41
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "59% of issues closed",
                "points": 27.6,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 59
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "374/415 decided PRs merged",
                "points": 34.5,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 374,
                      "decided": 415
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "all changesets reviewed",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 57,
            "inputs": {
              "followers": 115,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "zylos-ai",
              "public_repos": 36,
              "account_age_days": 191
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "115 followers of zylos-ai",
                "points": 14.8,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 115,
                      "login": "zylos-ai"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "36 public repos, account ~0 yr old",
                "points": 12.5,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 36
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "moderate",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 53,
            "inputs": {
              "packages": [
                "web-console"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 3998
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 3998 days ago",
                "points": 4,
                "status": "partial",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 3998
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "1 published versions",
                "points": 4,
                "status": "partial",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 65,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "at_risk",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 48,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "1 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "0 out of 30 merged PRs checked by a CI test -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "topics": [
                "ai",
                "ai-worker",
                "own-your-data",
                "personal-ai-assistant",
                "self-evolving",
                "team-collaboration"
              ],
              "has_wiki": false,
              "homepage": "https://zylos.ai",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://zylos.ai",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "6 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 6
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 62,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 61,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 6.1
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "0 out of 30 merged PRs checked by a CI test -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "all changesets reviewed",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 6.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "7 existing vulnerabilities detected",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "moderate",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories. Remaining weights renormalized. Matched 413 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 413
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 67,
            "inputs": {
              "source": "osv",
              "advisories": 10,
              "affected_packages": 7,
              "assessed_packages": 413,
              "unassessed_packages": 0,
              "affected_by_severity": "high 5, low 2",
              "direct_affected_packages": 3
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "3 affected: js-yaml 3.14.2 (high 7.5), js-yaml 4.1.1 (high 7.5), multer 2.1.1 (high 7.5)",
                "points": 10.2,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 3,
                      "packages": "js-yaml 3.14.2 (high 7.5), js-yaml 4.1.1 (high 7.5), multer 2.1.1 (high 7.5)"
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory has been public longer than 90 days",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "advisories_none_stale",
                    "params": {
                      "days": 90
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 413,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 3
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 56,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.99,
              "agent_instruction_files": [
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 6158
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "99 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 99,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "at_risk",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 42,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "package-lock.json"
              ],
              "has_dockerfile": true,
              "typed_language": false,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0.62,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "62 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 62,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "moderate",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 54,
            "inputs": {
              "primary_language": "JavaScript",
              "largest_source_bytes": 124245,
              "source_files_sampled": 229,
              "oversized_source_files": 4
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "JavaScript without a type-check config",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_typecheck_config_language",
                    "params": {
                      "language": "JavaScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "4/229 source files over 60KB",
                "points": 54,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 229,
                      "oversized": 4
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "Could not fetch npm package 'zylos' from its registry",
    "Could not fetch npm package 'zylos-scheduler-v2' from its registry",
    "Could not fetch npm package 'comm-bridge' from its registry",
    "Could not fetch npm package 'zylos-memory' from its registry"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-22T18:55:14.976430Z",
  "schema_version": "0.26.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/z/zylos-ai/zylos-core.svg",
  "full_name": "zylos-ai/zylos-core",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.26.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsnpm.