Публічний реєстр
Звіт про здоров'я програмного забезпеченнясхема 0.26.0 · метрики 1.13.0 · 2026-07-22 18:48 UTC

234150476 / cac-windows

Shell · JavaScriptMIT★ 0 зірок⑂ 0 форківз лип. 2026 р.Переглянути на GitHub ↗

234150476/cac-windows має індекс здоров’я 38 зі 100, що відповідає смузі «У зоні ризику». Найвищий показник — Sustainability & Governance (44/100), найнижчий — AI Readiness (29/100). Останнє оновлення було 5 днів тому. Більшість нещодавньої роботи виконує один учасник.

38
загалом / 100
У зоні ризику

Індекс здоров'я програмного забезпечення

Метрики згруповано у зважені категорії на шкалі 1–100. Загальна оцінка починається як їхнє середнє; коли публічні дані активують Політику юрисдикцій високого ризику, рейтинг коригується й отримує верхню межу 49 («Під ризиком»). Готовність до ШІ не входить до індексу.

38
Відмінний85-100Зразковий; відповідає практично всім перевіреним критеріям
Добрий70-84Здоровий; незначні прогалини
Помірний50-69Прийнятний, але з помітними прогалинами; рекомендовано перевірку
У зоні ризику30-49Суттєві слабкі місця; впровадження потребує обережності
Критичний1-29Серйозні проблеми (покинутий, єдиний мейнтейнер, без базової гігієни)
ЖиттєздатністьСпільнота тавпровадженняСталість таврядуванняІнженернаякістьБезпекаГотовність доШІ

Профіль оцінок

Кожна вісь — окрема категорія. Форма важить більше, ніж середнє: здоровий об'єкт заповнює всю фігуру, тоді як профіль із піками та провалами означає, що сила в одному вимірі маскує ризик в іншому.

Власність

234150476Особистий обліковий запис
38 підписників49 публічних репозиторіївз лют. 2015 р.

Цей репозиторій належить особистому обліковому запису. Проєкт з єдиним власником несе більший ризик безперервності, ніж підтримуваний організацією.

Пакетні екосистеми

РеєстрПакетВерсіяЗавантажень / місВерсіїОстання публікаціяТеги
npmcac-windows1.0.224 474235 днів томуclaudeclaude-codeanthropicprivacyproxytelemetryfingerprintwindowspowershelltimezonecloakcli

Метрики за категоріями

Життєздатність

Чи живий проєкт — чи пишеться код і чи виходять релізи?

35У зоні ризику · 22% загального індексу
Як обчислюється оцінка
36/36Свіжість push — останній push 5 дн. тому
4.2/36Ритм комітів — 6/52 тижнів із комітами
18/18Обсяг комітів — 196 комітів за останній рік
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Використані вхідні дані
commits_last_year196
human_commit_share1
days_since_last_push5
active_weeks_last_year6
Як обчислюється оцінка
0/27Випускає релізи — релізів не опубліковано
0/36Свіжість релізів — релізів немає
0/27Ритм релізів — релізів немає
0/10OpenSSF Scorecard: Signed-Releases — немає даних
Використані вхідні дані
releases_count0
Виключено з оцінювання (немає даних або не застосовно): OpenSSF Scorecard: Signed-Releases. Залишкові ваги перенормовано.

Спільнота та впровадження

Чи має проєкт користувачів, завантаження, увагу та влаштовані умови для контриб’юторів?

33У зоні ризику · 18% загального індексу
Як обчислюється оцінка
0/60Зірки — 0 зірок
0/25Форки — 0 форків
0/15Спостерігачі — 0 спостерігачів
Використані вхідні дані
forks0
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Як обчислюється оцінка
22.5/22.5README
22.5/22.5Ліцензія — визнана ліцензія (MIT)
0/18Настанови CONTRIBUTING
0/13.5Кодекс поведінки
0/7.2Шаблон issue
0/6.3Шаблон PR
Використані вхідні дані
has_readmeтак
has_licenseтак
has_contributingні
has_issue_templateні
has_code_of_conductні
has_pull_request_templateні
Як обчислюється оцінка
48.7/80Щомісячні завантаження — 4 474 завантажень/місяць у npm
0/20Залежні пакети в реєстрі — ця екосистема цього не повідомляє
Використані вхідні дані
packagescac-windows
dependents
ecosystemsnpm
total_downloads
monthly_downloads4 474
Виключено з оцінювання (немає даних або не застосовно): Залежні пакети в реєстрі. Залишкові ваги перенормовано.

Сталість та врядування

Чи переживе проєкт своїх людей — бас-фактор, реактивність, хто за ним стоїть і як супроводжуються пакети?

44У зоні ризику · 24% загального індексу
Як обчислюється оцінка
9/54Бас-фактор — на 1 контриб’ютор(ів) припадає половина всіх комітів
8.6/22.5Розподіл комітів — головний контриб’ютор — автор 62% комітів
9.5/13.5Широта контриб’юторів — 7 контриб’юторів
6/10OpenSSF Scorecard: Contributors — project has 2 contributing companies or organizations -- score normalized to 6
Використані вхідні дані
bus_factor1
contributors_sampled7
top_contributor_share0,62
Як обчислюється оцінка
0/46.8Вирішення issue — немає issue або даних
0/38.3Прийняття PR — немає вирішених pull request-ів або даних
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Використані вхідні дані
merged_prs0
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs0
Виключено з оцінювання (немає даних або не застосовно): Вирішення issue, Прийняття PR. Залишкові ваги перенормовано.
Як обчислюється оцінка
10/30Підтримка власника — особистий (користувацький) обліковий запис
0/20Верифікований домен — не застосовно до користувацьких облікових записів
11.4/25Охоплення власника — 38 підписників у 234150476
24.4/25Послужний список — 49 публічних репозиторіїв, вік облікового запису ~11 р.
Використані вхідні дані
followers38
owner_typeUser
is_verified
owner_login234150476
public_repos49
account_age_days4 162
Виключено з оцінювання (немає даних або не застосовно): Верифікований домен. Залишкові ваги перенормовано.

Супровід пакетів

100Відмінний
Як обчислюється оцінка
25/25Опубліковано й доступно — 1 пакет(ів) у npm
35/35Свіжість публікацій — остання публікація 5 дн. тому
20/20Історія версій — 23 опублікованих версій
20/20Не застарілий — активний, не deprecated і не yanked
Використані вхідні дані
packagescac-windows
ecosystemsnpm
any_deprecatedні
min_days_since_publish5

Інженерна якість

Чи наявні базові інженерні практики та документація?

44У зоні ризику · 20% загального індексу

Інженерні практики

30У зоні ризику
Як обчислюється оцінка
24/24Процеси CI — 4 процес(ів) CI
0/24Наявні тести
0/16Конфігурація лінтера
0/9.6Pre-commit-хуки
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — немає даних
Використані вхідні дані
has_ciтак
has_testsні
has_editorconfigні
has_linter_configні
has_precommit_configні
Виключено з оцінювання (немає даних або не застосовно): OpenSSF Scorecard: CI-Tests. Залишкові ваги перенормовано.

Документація

65Помірний
Як обчислюється оцінка
30/30README
25/25Каталог документації
0/15Сайт документації / домашня сторінка
0/10Опис репозиторію
0/10Теми
10/10Wiki
Використані вхідні дані
topics
has_wikiтак
homepage
has_readmeтак
has_docs_dirтак
has_descriptionні

Безпека

Чи міцні видимі практики безпеки й ланцюга постачання, без непослабленої пов’язаності з юрисдикціями високого ризику?

32У зоні ризику · 16% загального індексу

Стан безпеки

32У зоні ризику
Як обчислюється оцінка
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — немає даних
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
1.5/2.5Contributors — project has 2 contributing companies or organizations -- score normalized to 6
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Ліцензія — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
0/5Packaging — немає даних
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — no SAST tool detected
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — немає даних
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
Використані вхідні дані
sourceopenssf_scorecard
checks_evaluated15
scorecard_versionv5.5.0
checks_inconclusive3
scorecard_aggregate3,2
Виключено з оцінювання (немає даних або не застосовно): ci_tests, packaging, signed_releases. Залишкові ваги перенормовано.

Готовність до ШІ

Наскільки репозиторій оснащений для розробки та супроводу за участі ШІ-агентів? Незалежний, експериментальний бейдж — вага 0.0, тож він подається окремо і не впливає на загальний індекс здоров'я.

29Критичний · 0% загального індексу
Як обчислюється оцінка
0/45Інструкції для агентів — немає CLAUDE.md / AGENTS.md / правил редактора
0/15Машиночитана документація (llms.txt)
40/40Читабельна історія комітів — намір зазначено у 99 з 100 людських комітів (структурований заголовок або пояснювальний текст)
Використані вхідні дані
has_llms_txtні
legible_history_share0,99
agent_instruction_files
agent_instruction_max_bytes
Як обчислюється оцінка
0/18Розгортання однією командою
0/22Автоматизовані тести
0/11Конфігурація лінтера / форматера
0/11Статична перевірка типів
10/10Відтворюване середовище — Dockerfile
0/10Підтверджена практика роботи з агентами — серед останніх 100 комітів немає створених агентом
0/8Автоматизоване супроводження — автоматичних оновлень залежностей не виявлено
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Використані вхідні дані
has_nixні
has_testsні
lockfiles
has_dockerfileтак
typed_languageні
bootstrap_files
has_devcontainerні
has_linter_configні
typecheck_configs
agent_commit_share0
toolchain_manifests
dependency_bot_commit_share0
Як обчислюється оцінка
0/45Типізований код — Shell без конфігурації перевірки типів
55/55Керовані розміри файлів — 0/15 файлів вихідного коду понад 60 КБ
Використані вхідні дані
primary_languageShell
largest_source_bytes13 930
source_files_sampled15
oversized_source_files0

Ключові факти

0зірок GitHub
7контриб'юторів
196комітів за останні 12 місяців
5днів від останнього пушу
0релізів
1бас-фактор
0відкритих issue
npmпакетних екосистем

Попередження щодо збору даних

  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository
  • deps.dev does not index npm:cac-windows@1.0.22; advisories assessed against the repository dependency graph instead

Докладніше

OpenSSF Scorecard 3.2 / 10
3.2сукупно

Незалежна, не прив'язана до інструментів оцінка безпеки від відкритого проєкту OpenSSF Scorecard. Кожна перевірка винагороджує практику безпеки, а не інструмент конкретного постачальника. Перевірки, які Scorecard не зміг визначити, позначено н/д і виключено з оцінки безпеки (вони ніколи не зараховуються як нуль).Scorecard v5.5.0 · 2026-07-22 18:48 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
н/дCI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
6Contributorsproject has 2 contributing companies or organizations -- score normalized to 6
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
н/дPackaginginternal error: Client.Actions.ListWorkflowRunsByFileName: internal error: ListWorkflowRunsByFileName: GET https://api.github.com/repos/234150476/cac-windows/actions/workflows/docker.yml/runs?status=success: 404 Not Found []
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTno SAST tool detected
0Security-Policysecurity policy file not detected
н/дSigned-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
10Vulnerabilities0 existing vulnerabilities detected
Усі залежності не зібрано

Не вдалося зібрати розв'язаний набір залежностей для цього звіту: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Звіт у форматі JSON машиночитний
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 599,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "Shell": 319824,
        "Python": 21234,
        "Batchfile": 205,
        "Dockerfile": 2803,
        "JavaScript": 77908,
        "PowerShell": 38907
      },
      "pushed_at": "2026-07-17T14:14:50Z",
      "created_at": "2026-07-14T05:29:31Z",
      "owner_type": "User",
      "updated_at": "2026-07-17T14:16:23Z",
      "description": null,
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "master",
      "license_spdx_raw": "MIT",
      "primary_language": "Shell",
      "significant_languages": [
        "Shell",
        "JavaScript"
      ]
    },
    "owner": {
      "blog": null,
      "name": null,
      "type": "User",
      "login": "234150476",
      "company": null,
      "location": null,
      "followers": 38,
      "avatar_url": "https://avatars.githubusercontent.com/u/11246667?v=4",
      "created_at": "2015-02-28T16:16:04Z",
      "is_verified": null,
      "public_repos": 49,
      "account_age_days": 4162
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [],
      "recent_commits": [
        {
          "oid": "aad238d3a6e3badb409888970b6904ff978efa06",
          "body": null,
          "is_bot": false,
          "headline": "release: v1.0.22",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-17T14:14:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d632ed80bca038613f7174d07edcf274fbe39764",
          "body": null,
          "is_bot": false,
          "headline": "fix: cleanup preserves sessions, history and config",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-17T14:14:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "158fc577f503979f8d34d0078d844fcf25d4fec7",
          "body": null,
          "is_bot": false,
          "headline": "release: v1.0.21",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-17T14:07:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2eb15d068aef3fc5a84a84e898a9dd9d7805d3ac",
          "body": null,
          "is_bot": false,
          "headline": "simplify: cac cleanup runs all steps directly, no menu",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-17T14:07:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4148e8e047a16c2cd7e43c8bddf7b1d04b323371",
          "body": null,
          "is_bot": false,
          "headline": "release: v1.0.20",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-17T14:04:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1a3c3f2a590035a2a996fd96a1b398d18a459b79",
          "body": null,
          "is_bot": false,
          "headline": "fix: use ConvertFrom-Json -AsHashtable to handle case-conflicting keys",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-17T14:04:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7a70808f9961068f32b897ee94fc068641c45fd1",
          "body": null,
          "is_bot": false,
          "headline": "release: v1.0.19",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-17T13:02:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "50d8de8b0a7a6c47722963e7899a02723a5f73c8",
          "body": "Windows PowerShell version of the cleanup guide. Supports 6 levels:\n1. Reset device identity (userID/anonymousId/statsig)\n2. Clear telemetry & analytics\n3. Clear sessions & history\n4. Clear OAuth account linkage\n5. Full reset (nuclear, with config backup)\n6. All of 1-4 (preserves config)\n\nUsage: cac cleanup",
          "is_bot": false,
          "headline": "feat: add cac cleanup command for tracking data removal",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-17T13:02:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c4f61bf0d11a20ee293535388a5c918c38bc098b",
          "body": null,
          "is_bot": false,
          "headline": "release: v1.0.18",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-15T17:53:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "41a79f9b4918e2fb8c0190bcd92d68013f7d86d5",
          "body": "Previously only patched cli.js, so switching to 2.1.202 left\nclaude.exe unpatched. Now patches both formats automatically.",
          "is_bot": false,
          "headline": "fix: patch-cli.js handles both cli.js and SEA binary",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-15T17:53:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aa50795947fffc9c3f207a29cb8b88fa3fcd68a5",
          "body": null,
          "is_bot": false,
          "headline": "release: v1.0.17",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-15T17:30:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "814b56d6801a9cd7cde1b7399e3ffd802a6681d3",
          "body": null,
          "is_bot": false,
          "headline": "docs: update quickstart with complete setup flow",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-15T17:22:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2943598817a406bd03bec398872fcf605d8c790d",
          "body": null,
          "is_bot": false,
          "headline": "release: v1.0.16",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-15T16:37:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "184c5996bace76cf18aa4dec464fb361ecc22ea8",
          "body": "These were in src/ but excluded from root by .gitignore, so npm\npackage didn't contain them. Now copied to root and un-ignored.",
          "is_bot": false,
          "headline": "fix: include fingerprint-hook.js and relay.js in package",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-15T16:37:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bca8ea2fdda7c01c521df2e799ab87d106643d83",
          "body": null,
          "is_bot": false,
          "headline": "release: v1.0.15",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-15T16:25:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "95a437018fa721c3b7378ac4465a577d3ebedfd7",
          "body": null,
          "is_bot": false,
          "headline": "fix: patch-cli.js use argv[2] not argv[1] for ccDir argument",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-15T16:25:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7de83533f7fd388f094a15672dd9f3d1fdedd5c7",
          "body": null,
          "is_bot": false,
          "headline": "release: v1.0.14",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-15T16:22:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d96cee6c3d65d303c45f4fd7c049a9b49ae581df",
          "body": null,
          "is_bot": false,
          "headline": "fix: use fixed npm path for patch-cli.js instead of MyInvocation",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-15T16:22:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d4bb7262cb76859b60b43ba831c7bb756d054abd",
          "body": null,
          "is_bot": false,
          "headline": "release: v1.0.13",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-15T16:19:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "abc4da7de3b5afe075b37ab4c92c2971dc5ea073",
          "body": "Inline Node code in PowerShell here-strings had escaping issues\n(double-quoted @\"...\"@ expands $variables, backticks parsed wrong).\nExtracted to scripts/patch-cli.js — called by file, no escaping.\nAlso updated peerDependencies to accept both 2.1.77 and 2.1.202.",
          "is_bot": false,
          "headline": "fix: use standalone patch-cli.js for version switch patching",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-15T16:19:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "513d98f4ce598c3e2ffba11cf79d4c9c73deb1fd",
          "body": null,
          "is_bot": false,
          "headline": "release: v1.0.12",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-15T15:51:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7f5177b9a88670301fdaf45811412a4731c26c07",
          "body": "cac env set version reinstalls Claude Code which overwrites patched\ncli.js. Now automatically re-applies TZ and session compat patches\nafter npm install completes.",
          "is_bot": false,
          "headline": "fix: auto-reapply patches after version switch",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-15T15:51:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5b2da2e42b773c98e46da90be05f89c9cedf979c",
          "body": null,
          "is_bot": false,
          "headline": "release: v1.0.11",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-15T15:42:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b3edd82f27ae6540dae550a5ad25abe923f436d6",
          "body": "- postinstall patches null check for originalFile.split() crash\n  when resuming newer sessions on older Claude Code versions\n- README documents version switching (cac env set version 2.1.77)\n  and Pro 1M context workaround\n- TZ patch now documented for both cli.js and SEA binary",
          "is_bot": false,
          "headline": "feat: session compatibility patch + version switching docs",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-15T15:42:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dae1225f89d563e79f7bd1bc30acaeb8a4b78d81",
          "body": null,
          "is_bot": false,
          "headline": "release: v1.0.10",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-15T15:05:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e653158ae729ba236a63bd03ae275b84f5c273a8",
          "body": "Postinstall now detects date function by pattern matching across\nversions — TD6() in cli.js and byo() in SEA binary. Uses text\nreplacement for .js files and byte-level patching for binaries.\nNo longer force-installs a specific version.",
          "is_bot": false,
          "headline": "feat: TZ patch supports both cli.js (2.1.77) and SEA binary (2.1.202)",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-15T15:05:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e678cc62cc34aac0acd6cf5d205ed20f7154d2f9",
          "body": null,
          "is_bot": false,
          "headline": "release: v1.0.9",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-15T14:55:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6055755a907c5633f94241a5a1f52df5c2d34645",
          "body": "PATH scanning was unreliable — it picked up bash shim scripts (npm/claude)\nthat can't be executed in PowerShell. Now goes straight to the npm\ninstall directory: checks bin/claude.exe, bin/claude, then cli.js.\nWorks for both SEA binary (>=2.1.200) and plain Node (<=2.1.77).",
          "is_bot": false,
          "headline": "fix: Find-RealClaude directly checks npm install dir instead of PATH",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-15T14:55:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "578f5474f15c3e4137ef05cbeea02197af863f85",
          "body": null,
          "is_bot": false,
          "headline": "release: v1.0.8",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-15T14:18:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b7b7ddda9f1d56f68fbd5bca12fd5c587aba4874",
          "body": "Installs the specified version, runs install.cjs if needed,\nand re-runs cac setup to update the real_claude path.\nUsage: cac env set version 2.1.77",
          "is_bot": false,
          "headline": "feat: add `cac env set version` to switch Claude Code versions",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-15T14:18:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fdf408a727dc600e197e461d3a0ec58316db9cac",
          "body": null,
          "is_bot": false,
          "headline": "release: v1.0.7",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-15T14:12:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2a1e9e3c1a5a7b314c025285f40676f0d94fcd16",
          "body": "- Find-RealClaude now searches for cli.js as fallback (pre-SEA versions)\n- Wrapper detects .js entry and runs via node instead of direct exec\n- postinstall no longer force-overwrites user's Claude Code version;\n  only auto-installs when Claude Code is missing entirely\n- Older versions (e.g. 2.1.77) benefit from NODE_OPTIONS injection\n  since they run as plain Node.js, not SEA binary",
          "is_bot": false,
          "headline": "feat: support older Claude Code versions using cli.js entry point",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-15T14:12:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4d4efd05f3dff5edd5347f1a9fffd28e6eba0b28",
          "body": null,
          "is_bot": false,
          "headline": "release: v1.0.6",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-14T18:21:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1e3605320d737de6940c6fddbb882e8cb955de85",
          "body": "Postinstall now handles everything automatically:\n- Claude Code not installed → installs pinned v2.1.202\n- Wrong version → reinstalls pinned version\n- install.cjs blocked by allow-scripts → runs it\n- TZ patch not applied → applies it\n\nUsers only need: npm i -g cac-windows",
          "is_bot": false,
          "headline": "feat: auto-install correct Claude Code version during postinstall",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-14T18:21:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "533fabfa7cc0f6068f3880493643f0ccd31165f9",
          "body": null,
          "is_bot": false,
          "headline": "release: v1.0.5",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-14T18:12:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c2907a1d07ae01e29754ae12bc80bdc22f4acbf2",
          "body": "Newer npm versions block postinstall scripts via allow-scripts policy,\nso claude.exe may not exist after npm install. Detect this and run\ninstall.cjs automatically during cac-windows postinstall.",
          "is_bot": false,
          "headline": "fix: auto-run Claude Code install.cjs when blocked by allow-scripts",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-14T18:12:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "333ca1554bb1dbf86c9e0c5f3edffa4173c7ce36",
          "body": null,
          "is_bot": false,
          "headline": "release: v1.0.4",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-14T18:08:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ab88e04ddc039e6d91de78e10182c4d3e0b49f60",
          "body": "The byo() binary signature changes across Claude Code versions.\nPin to 2.1.202 (verified) and warn users when signature mismatches\ninstead of silently skipping the patch.",
          "is_bot": false,
          "headline": "fix: pin Claude Code 2.1.202 for TZ patch compatibility",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-14T18:08:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "508bac2c972de80aaf50535c6fbc1cd08df4cb9a",
          "body": null,
          "is_bot": false,
          "headline": "release: v1.0.3",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-14T17:51:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b9757d444a3fbd2f829bb12ca9d6785fc3199ca3",
          "body": "Some npm installs produce `claude` without .exe extension. Now checks\nboth claude.exe and claude, plus a direct fallback to the known npm\ninstall path under AppData\\Roaming\\npm.",
          "is_bot": false,
          "headline": "fix: Find-RealClaude supports extensionless SEA binary",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-14T17:51:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "60df0124c73b9dc41144c1c9065bc075125ad02a",
          "body": null,
          "is_bot": false,
          "headline": "release: v1.0.2",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-14T17:24:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "00d4dc79a066526e4a030397d7eb4bc677adf899",
          "body": "Shims were still referencing node_modules\\claude-cac which doesn't\nexist after the package rename. Updated to node_modules\\cac-windows.",
          "is_bot": false,
          "headline": "fix: shim paths use correct package name cac-windows",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-14T17:24:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7fc7bc95b4620ee6f75169ce053219d15929364e",
          "body": null,
          "is_bot": false,
          "headline": "release: v1.0.1",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-14T17:16:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "18b7c5399489eb34bccebd73701f4dca0ed34c6c",
          "body": "The generated cac.ps1 shim hardcoded `pwsh`, which fails on systems\nwith only Windows PowerShell 5.1. Now detects pwsh availability and\nfalls back to powershell.exe automatically.",
          "is_bot": false,
          "headline": "fix: ps1 shim falls back to powershell.exe when pwsh is not installed",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-14T17:14:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b005ef4e30c158bfbf68b3795c67eebcb5bbe8b1",
          "body": "- Complete installation and usage guide in Chinese\n- Command reference with all subcommands\n- TZ timezone patch explanation\n- Telemetry modes and identity spoofing coverage table\n- Update package.json: rename to cac-windows, v1.0.0, new repo URL, win32 only",
          "is_bot": false,
          "headline": "docs: rewrite README for Windows standalone project",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-14T09:41:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7c037d4ef2be1ba3aba5a770a53df70d017e7f20",
          "body": "Changes:\n- cac.ps1: add env create, env set (tz/lang/proxy/telemetry/persona), env rm\n- cac.ps1: full PowerShell claude.ps1 wrapper (sets env vars directly, not via cmd.exe)\n- cac.ps1: fix wrapper set /p CRLF bug (switch to for /f usebackq)\n- cac.ps1: fix wrapper proxy file-not-found error when no p\n[…]\n call cac.ps1\n- postinstall.js: skip bash commands on Windows\n- postinstall.js: auto-patch claude.exe byo() to respect TZ env var\n- postinstall.js: Windows-specific install message with cac setup step",
          "is_bot": false,
          "headline": "feat(windows): full Windows PowerShell support + TZ timezone patch",
          "author_name": "234150476",
          "author_login": "234150476",
          "committed_at": "2026-07-14T09:31:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b1c8f42b5b861d1edf443ac763dca0d1b195db28",
          "body": null,
          "is_bot": false,
          "headline": "docs: add v1.5.7 changelog entry (clone agents fix) (#74)",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-04-27T14:17:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "966303dfbdbaa5cc878bdd3d94d4811c1ad139e7",
          "body": "* fix: include agents in clone_dirs for env create\n\n~/.claude/agents was missing from the clone list, so newly created\nenvironments via --clone never inherited subagent configs. Add it\nalongside commands/hooks/skills/plugins. Bump to 1.5.7.\n\n* chore: bump package.json to 1.5.7",
          "is_bot": false,
          "headline": "fix: include agents in clone_dirs (v1.5.7) (#73)",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-04-27T13:39:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "00d2796d20efcd1a70284b158a36abf9293c1796",
          "body": null,
          "is_bot": false,
          "headline": "fix: use remote DNS for SOCKS5 curl probes",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-04-27T04:06:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fa44cca4f9e4cf9c5b4a9da41edcdf48d276064b",
          "body": null,
          "is_bot": false,
          "headline": "build: regenerate cac after timer fix",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-04-22T08:55:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "61171520bdd674960c8b31e5a66258c5e3ecc116",
          "body": "Extract _time_now() helper that validates date +%s%N output with regex\ninstead of string length, falling back to seconds-only on platforms\nwhere %N is literal (e.g. macOS). Prevents arithmetic errors when\n_TIMER_START contains non-numeric suffixes.",
          "is_bot": false,
          "headline": "fix: robust nanosecond timer parsing for non-GNU date",
          "author_name": "xuzhizhen",
          "author_login": null,
          "committed_at": "2026-04-22T08:55:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b2ea6b8378e132940ffa6660052db497b1d5d970",
          "body": null,
          "is_bot": false,
          "headline": "fix: make generated hostnames platform-aware",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-04-22T08:37:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b5883c27a97631dafeb1d71499276d9f60d8472c",
          "body": null,
          "is_bot": false,
          "headline": "fix: document clone flags in env help",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-04-22T08:19:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ad5c25591c15ac4c92efbef0964196e857bf9437",
          "body": null,
          "is_bot": false,
          "headline": "fix: support fish shell PATH integration",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-04-22T06:36:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8d8603aba8f8beb3e5e23b686b37b0ee9aea3b7d",
          "body": null,
          "is_bot": false,
          "headline": "ci: allow tag publish when version already matches",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-04-22T04:48:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "16cfd723210f4835f1b94f11e512952414b5a7e6",
          "body": null,
          "is_bot": false,
          "headline": "release: v1.5.5",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-04-22T04:45:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8c34ebffa4dbce340c76729f3622da294aaaea28",
          "body": null,
          "is_bot": false,
          "headline": "release: v1.5.5-beta.2",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-04-22T04:38:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cedad62b9819721e94b74f35dd30b03b65a17ec9",
          "body": null,
          "is_bot": false,
          "headline": "merge: sync remote master before beta release push",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-04-22T04:31:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "902728b59661a00593bb5b6a2cd60c5ee837e841",
          "body": null,
          "is_bot": false,
          "headline": "release: v1.5.5-beta.1",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-04-22T04:30:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ddc59f5ed864c02f9498d4b6fd67e0692e784a02",
          "body": null,
          "is_bot": false,
          "headline": "ci: add Feishu webhook notification workflow",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-04-04T15:36:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "07ccc5f58a5dccfac0e8ddb192e3bfec4237634b",
          "body": "* fix: disable Claude auto-updater in all cac-managed environments\n\nClaude's auto-updater runs mid-session and re-execs a new binary directly,\nbypassing the cac wrapper (no fingerprint hook, no timezone spoofing, no\ndns-guard). Claude Code migrated the disable mechanism from .claude.json\nto settings\n[…]\nsure_initialized: patch all existing envs on every cac invocation (idempotent)\n\n* perf: skip python3 fork in autoupdater patch loop if already patched\n\n* chore: bump version to 1.5.4, update changelog",
          "is_bot": false,
          "headline": "fix: disable Claude auto-updater in all cac-managed environments (#62)",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-04-02T12:43:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "36504490ab97f4d6b7efc846b34288e732f11c40",
          "body": null,
          "is_bot": false,
          "headline": "release: v1.5.3 (re-release of v1.5.2, npm version conflict)",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-04-01T09:22:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "99c97820a6f3e88d0ca417ca86dda48264885fb6",
          "body": "…positive\n\n* fix: prevent sudo-caused file ownership corruption breaking normal-user claude\n\nRunning `sudo cac` could rewrite ~/.cac/ files as root, causing the claude\nwrapper to silently exit (set -e + unreadable root-owned JS files).\n\n- cmd_setup.sh: add warning when running as root; protect cp co\n[…]\ne wins),\n  never report mismatch error\n\n* release: v1.5.2\n\n- Bump version from 1.5.2-beta.3 to 1.5.2\n- Update changelog (EN + ZH) with both fixes\n- Correct v1.5.0 user_id entry to reflect new behavior",
          "is_bot": false,
          "headline": "fix: sudo-caused file ownership corruption and userID mismatch false …",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-04-01T09:14:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6623a1833d4c436d59e2e3c62555050c7cbecca8",
          "body": null,
          "is_bot": false,
          "headline": "docs: move 注意事项/Notes section to top, right after intro",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-03-31T15:47:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0af8d0f96acde4a00fd8ce40fc4088c77b1edfba",
          "body": "docs: ban risk FAQ + README warning",
          "is_bot": false,
          "headline": "Merge pull request #57 from nmhjklnm/docs/ban-risk-faq",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-03-31T15:43:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "392079f7e5b884a66bb732709ac9767ef05eff1e",
          "body": null,
          "is_bot": false,
          "headline": "docs: fix ban risk warning to be general, not specific to quick bans",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-03-31T15:42:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2ab9bdd8027947d86c49dcc6d631e2bf221a5851",
          "body": "Add a warning to README (both CN and EN) clarifying that cac protects\nthe device fingerprint layer only and cannot prevent account-layer bans\n(OAuth account, payment method, IP reputation, server-side decisions).\n\nAdd bilingual FAQ guide (docs/guides/ban-risk.mdx + zh/) covering:\n- What cac protects vs. what it cannot protect\n- Why \"banned in 15 minutes\" is an account-layer issue\n- Self-diagnostic checklist\n- Multi-device shared environment risks\n- Tips for reducing account-layer risk",
          "is_bot": false,
          "headline": "docs: add ban risk FAQ and README warning",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-03-31T15:38:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3ad3a7165df7871148d4ac55b01011d67846be9d",
          "body": "- hostname: replace host-xxxxx pattern with realistic macOS format (Names-MacBook-Pro.local)\n- persona: unset conflicting detectTerminal() vars before injection to prevent host env override\n- rh: intercept fs.readFileSync on .git/config to cover CC 2.1.88 direct-read path\n- statsig: remove dead code (_update_statsig, _new_sid, stable_id) — CC migrated to GrowthBook\n- USER/LOGNAME: export spoofed username so process.env.USER matches os.userInfo() patch",
          "is_bot": false,
          "headline": "fix: fingerprint accuracy improvements — 1.5.2-beta.1",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-03-31T13:09:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "911ffe117150db75b3d18a66f17d7ca46daa723d",
          "body": "- fix: relay watchdog connectivity check (process alive but port unresponsive)\n- feat: cac stop / cac env stop — pause cac, claude runs natively\n- docs: changelog for v1.5.1",
          "is_bot": false,
          "headline": "release: v1.5.1",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-03-31T07:51:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "12cd3dc26c2a84f224ccececd053bf67f311d700",
          "body": "…1-beta.2\n\n- watchdog now checks TCP reachability in addition to process liveness:\n  if relay process is alive but port unresponsive, kill and restart\n- add `cac env stop` / `cac stop`: pauses cac, claude runs natively\n  without any injection; `cac <name>` resumes",
          "is_bot": false,
          "headline": "feat: relay watchdog connectivity check + cac env stop command — 1.5.…",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-03-31T07:31:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "401eaca2deaf4bb86a2e332812841d19b1766a70",
          "body": "Regression from fa9d23b: watchdog added in a0a0d6b was removed along\nwith EXIT trap, leaving relay with no auto-recovery on crash mid-session\n(Connection Refused until session restart).\n\nFix: re-add watchdog as env-level singleton (relay.watchdog.pid), shared\nacross all sessions. Restarts relay on same port within 5s of crash.\nExits when relay is intentionally stopped. _relay_stop kills watchdog\nimmediately on env switch.",
          "is_bot": false,
          "headline": "fix: restore relay watchdog as env-level singleton — 1.5.1-beta.1",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-03-31T07:04:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e1f63fd376ff2d8bef447f3dba8ab542f21ebbd6",
          "body": "Regression introduced in fa9d23b: the watchdog added in a0a0d6b was\nremoved along with the EXIT trap, leaving no recovery when relay crashes\nmid-session (Connection Refused with no auto-restart).\n\nFix: re-add watchdog as an environment-level singleton (relay.watchdog.pid),\nshared across all sessions\n[…]\ny crash and restarts on\nthe same port within 5s. Exits automatically when relay is intentionally\nstopped (relay.proxy removed). _relay_stop kills watchdog immediately for\nclean teardown on env switch.",
          "is_bot": false,
          "headline": "fix: restore relay watchdog as env-level singleton",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-03-31T07:00:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d3c6ebff1fceefb64afb3aa9150f471970571d52",
          "body": "…text\n\n- Expand changelog entries to explain why persona presets exist (Claude detects terminal environment/deployment context)\n- Update docs/commands/env.mdx with complete persona and telemetry documentation\n- Add telemetry and persona subsections with examples to set command\n- Update README comman\n[…]\nng flagged as non-personal-developer environment. Telemetry modes provide granular control: stealth (blocks 1p_events but allows feature flags), paranoid (maximum blocking), transparent (no blocking).",
          "is_bot": false,
          "headline": "docs: clarify persona and telemetry modes — add context, update help …",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-03-30T10:54:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "39d009a3af5122ac9de4855f9654d72ef24c2a0a",
          "body": null,
          "is_bot": false,
          "headline": "feat: anti-fingerprint v2 overhaul",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-03-30T10:41:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3a1e7861d7ab0486d1cff0b5fad052a0e914c516",
          "body": "…mmits, not just telemetry",
          "is_bot": false,
          "headline": "fix: remove GIT_AUTHOR_EMAIL from wrapper — was affecting real git co…",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-03-30T09:37:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2f5750ccff16659ecf9a068be7f1575298ae1176",
          "body": "…ildProcess, hoist TERM, store persona IDs",
          "is_bot": false,
          "headline": "refactor: cleanup from simplify review — dedupe fakeResult/makeFakeCh…",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-03-30T09:31:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9901b86e8bb2095c6c1489bea7848115887f2c52",
          "body": "…to one line",
          "is_bot": false,
          "headline": "refactor: consolidate cac env check output — identity items merged in…",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-03-30T09:20:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a9a732431c9561d9ecf506e761c40a5afa110bed",
          "body": "Implements all actionable suggestions from issue #47:\n\n- P0: Repository hash (rh) spoofing via child_process interception\n- P1: Git email spoofing (wrapper + process-level)\n- P1: Telemetry strategy redesign (stealth/paranoid/transparent)\n- P1: Docker/server persona presets (--persona flag)\n- P1: Tru\n[…]\n preemptive handling\n- P2: Billing header disabled (CLAUDE_CODE_ATTRIBUTION_HEADER=0)\n- P2: Datadog domain added to DNS block list\n- P2: metadata.user_id consistency check in cac env check\n\nCloses #47",
          "is_bot": false,
          "headline": "feat: anti-fingerprint overhaul based on v2.1.86 reverse engineering",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-03-30T02:18:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1a9ef8037a67539b5c5814d8c15379fdc940e4e5",
          "body": null,
          "is_bot": false,
          "headline": "docs: add v1.4.4 changelog entry",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-03-29T07:07:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c4bdb9d1c6d127ddfcb113a67b1481f25f86e8ca",
          "body": null,
          "is_bot": false,
          "headline": "fix: revert bad array syntax ${#problems[@]:-0} — invalid in bash",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-03-28T16:40:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6e994912f057b9a8b2070c44e4f889a1a99744e5",
          "body": "CLAUDE.md may contain sensitive project-specific instructions.\nUse CLAUDE.local.md instead, which is gitignored.",
          "is_bot": false,
          "headline": "chore: move CLAUDE.md to CLAUDE.local.md (untracked)",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-03-28T16:34:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d3f1045e12e55e631e5c5d289360b5668c647a3d",
          "body": "Systematic audit found 10 places where commands could fail silently,\ncausing the script to exit with no error message:\n\n- cmd_env.sh: grep in subshell on proxy URL detection\n- cmd_relay.sh: unguarded kill race condition in _relay_stop\n- cmd_check.sh: empty array reference on bash 3.2 (set -u)\n- util\n[…]\nn3 aborts env creation silently\n- cmd_setup.sh: broken symlink crashes _ensure_initialized\n- cmd_docker.sh: invalid network interface crashes setup\n- mtls.sh: openssl pipeline failure on unusual certs",
          "is_bot": false,
          "headline": "fix: eliminate silent failures under set -euo pipefail",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-03-28T16:31:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5ab70aaf49674aa1640235cbf0b016467da6e108",
          "body": "cac env check crashed at the concurrent session check when no claude\nprocess was running, skipping all subsequent checks (proxy, exit IP,\nTUN conflict). Same root cause as the wrapper pgrep bug.",
          "is_bot": false,
          "headline": "fix: pgrep pipefail bug in cmd_check.sh (same as wrapper fix)",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-03-28T16:24:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3822ac5a80425b8a6fe9b9556a7313ca3ac24acb",
          "body": "Root cause: wrapper _cleanup_all killed the shared relay on every\nsession exit. Any short-lived claude -p invocation (e.g. from a\nFeishu auto-reply pipeline) killed the relay, breaking all other\nactive sessions with Connection Refused.\n\nFix:\n- Remove _cleanup_all, trap, and watchdog from wrapper\n- R\n[…]\nronment-level lifecycle)\n- Add relay.proxy file to detect proxy mismatch on startup\n- postinstall.js patches old wrappers (removes trap line)\n- _relay_start/_relay_stop manage relay.proxy consistently",
          "is_bot": false,
          "headline": "fix: relay lifecycle — persist across sessions, detect proxy mismatch",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-03-28T16:02:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e1b27d68229a2547e263dc9ff00f4ae767d7410f",
          "body": null,
          "is_bot": false,
          "headline": "docs: add Telegram community badge to README",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-03-27T09:31:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "75f9ef0eacc4a6f113f6b28c133a5a932c4c6119",
          "body": null,
          "is_bot": false,
          "headline": "docs: add v1.4.3 changelog entry",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-03-27T09:29:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3258ca98524c701a87e70b423afb98f698ce1abe",
          "body": "postinstall.js now directly patches ~/.cac/bin/claude if it has the\npipefail/pgrep bug (wrapper exits silently before launching claude).\n\nAlso adds _require_setup to _env_cmd_ls so `cac env ls` triggers\n_ensure_initialized and regenerates wrapper on version mismatch.",
          "is_bot": false,
          "headline": "fix: auto-patch wrapper pgrep bug on npm upgrade",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-03-27T09:19:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1932a5fab23774a14200dd5e08038aba3e00bd88",
          "body": "- Extract cac-dns-guard.js as standalone file during build\n- postinstall copies dns-guard, relay, fingerprint-hook to ~/.cac/\n- Pure Node.js — no bash/zsh dependency, works on all platforms\n- Users get bug fixes immediately on npm install, no manual cac command needed",
          "is_bot": false,
          "headline": "fix: postinstall auto-syncs runtime JS via pure Node.js copy",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-03-27T08:55:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "35eec739f0b375d9f6296920ede17a698787389d",
          "body": "This reverts commit 287be75bedef3d154a2f0aee022b3145edab0e1f.",
          "is_bot": false,
          "headline": "Revert \"chore: release v1.4.1 — sync cmd_check pgrep fix + version bump\"",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-03-27T08:39:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c37f81d3ea8e14861849f38e9cb55c33617c5e30",
          "body": "npm install now runs cac -v which triggers _ensure_initialized,\nauto-regenerating wrapper + runtime JS files. Users no longer need\nto manually run a cac command after upgrading to pick up bug fixes.\n\nAlso updates postinstall message to current command structure.",
          "is_bot": false,
          "headline": "fix: postinstall triggers wrapper regeneration on upgrade",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-03-27T08:35:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "287be75bedef3d154a2f0aee022b3145edab0e1f",
          "body": "- cmd_check: same pgrep||0 fallback as wrapper (pipefail + set -e)\n- bump CAC_VERSION and package.json to 1.4.1; rebuild cac\n\nMade-with: Cursor",
          "is_bot": false,
          "headline": "chore: release v1.4.1 — sync cmd_check pgrep fix + version bump",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-03-27T08:33:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f04631903eaef378c0720d62ba73d6b396bc9d89",
          "body": "Two bugs in the wrapper caused claude to silently fail to launch:\n\n1. pgrep -x \"claude\" returns 1 when no match — with pipefail + set -e\n   the script exits before reaching exec claude\n2. Non-zero claude exit code under set -e skips _ec=$? assignment —\n   set -u then aborts on unbound _ec variable\n\nFix: add || _claude_count=0 fallback, wrap claude exec in set +e block.",
          "is_bot": false,
          "headline": "fix: wrapper crash under set -euo pipefail",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-03-27T08:28:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0f6989db5e9fef395cac57baaa3ae94bbfff7ada",
          "body": null,
          "is_bot": false,
          "headline": "fix: rewrite docs.json tabs to Mintlify v2 format (tab inside languages)",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-03-27T06:29:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "03af931e564bb3236835587046ef9f43f412e5ea",
          "body": null,
          "is_bot": false,
          "headline": "fix: add url field to Mintlify tabs config for navigation",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-03-27T06:21:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "65c596b976edb1b925d3336aa52d5961da73439a",
          "body": "- New guide: \"Config inheritance with --clone\" (EN + ZH)\n- Update cac env create docs: add --clone, --no-link, --telemetry flags\n- Add guide to navigation in docs.json",
          "is_bot": false,
          "headline": "docs: add --clone guide + update env command reference",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-03-27T06:11:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fbd142ae959b3455f74633050fc6f0442f156a95",
          "body": null,
          "is_bot": false,
          "headline": "docs: complete v1.4.0 changelog — add missing items from all commits",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-03-27T06:02:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a0a0d6b7cd038a6b204a548d009e5e455939124a",
          "body": "- uncaughtException/unhandledRejection handlers: never crash from single connection error\n- upstream heartbeat every 30s: detect and log proxy connectivity changes\n- idle timeout 120s → 30min: streaming responses no longer killed prematurely\n- data activity resets idle timer: active streams stay ali\n[…]\nstart on transient errors (EADDRINUSE exits for watchdog)\n- wrapper watchdog: auto-restarts relay within 10s if process crashes\n- fail-closed: dead relay → HTTPS_PROXY points to dead port → no IP leak",
          "is_bot": false,
          "headline": "feat: relay hardening — heartbeat, crash recovery, streaming timeout",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-03-27T06:02:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ae2d5b0ae787aef75e2c86584aace4b141b0337a",
          "body": "…ncel)\n\ndns-guard.js replaced globalThis.fetch with node-fetch, whose Response.body\nis a Node.js Readable stream lacking ReadableStream.cancel(). Claude Code\nruns on Bun and expects native fetch — every streaming response triggered\n\"body.cancel is not a function\".\n\nAlso removes deprecated `cmd_setup()` and cleans up stale \"run cac setup\"\nerror messages.",
          "is_bot": false,
          "headline": "fix: remove node-fetch replacement that breaks Bun streaming (body.ca…",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-03-27T06:02:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b7c640a0ea49cc4e2c4822c8a931c60e58849575",
          "body": "…lone --no-link",
          "is_bot": false,
          "headline": "feat: CAC Meta Prompt — skip injection on --clone link, append on --c…",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-03-27T06:02:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f56c89997c3a037369d2711adca4d3cf46e439e9",
          "body": null,
          "is_bot": false,
          "headline": "fix: pgrep -x to match claude binary only, not MCP subprocesses",
          "author_name": "Yang YiHe",
          "author_login": "nmhjklnm",
          "committed_at": "2026-03-27T06:02:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 0,
      "commits_last_year": 196,
      "latest_release_at": null,
      "latest_release_tag": null,
      "releases_from_tags": false,
      "days_since_last_push": 5,
      "active_weeks_last_year": 6,
      "days_since_latest_release": null,
      "mean_days_between_releases": null
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": false,
      "has_contributing": false,
      "health_percentage": 28,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "cac-windows",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "claude",
            "claude-code",
            "anthropic",
            "privacy",
            "proxy",
            "telemetry",
            "fingerprint",
            "windows",
            "powershell",
            "timezone",
            "cloak",
            "cli"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/cac-windows",
          "is_deprecated": false,
          "latest_version": "1.0.22",
          "repository_url": "https://github.com/234150476/cac-windows",
          "versions_count": 23,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 4474,
          "first_published_at": "2026-07-14T10:07:51.090000Z",
          "latest_published_at": "2026-07-17T14:14:53.968000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0
      },
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [],
      "largest_source_bytes": 13930,
      "source_files_sampled": 15,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 0,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "nmhjklnm",
          "commits": 101,
          "avatar_url": "https://avatars.githubusercontent.com/u/108562510?v=4"
        },
        {
          "type": "User",
          "login": "234150476",
          "commits": 46,
          "avatar_url": "https://avatars.githubusercontent.com/u/11246667?v=4"
        },
        {
          "type": "User",
          "login": "SakuraPuare",
          "commits": 5,
          "avatar_url": "https://avatars.githubusercontent.com/u/52142762?v=4"
        },
        {
          "type": "User",
          "login": "luoxiaohei2584",
          "commits": 5,
          "avatar_url": "https://avatars.githubusercontent.com/u/199768911?v=4"
        },
        {
          "type": "User",
          "login": "ShiLong-CN",
          "commits": 4,
          "avatar_url": "https://avatars.githubusercontent.com/u/222668115?v=4"
        },
        {
          "type": "User",
          "login": "guoyongchang",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/10484506?v=4"
        },
        {
          "type": "User",
          "login": "Tinghecui",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/54262737?v=4"
        }
      ],
      "contributors_sampled": 7,
      "top_contributor_share": 0.62
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": false,
      "ci_workflows": [
        "ci.yml",
        "docker.yml",
        "feishu-notify.yml",
        "npm-publish.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 6,
            "reason": "project has 2 contributing companies or organizations -- score normalized to 6",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "internal error: Client.Actions.ListWorkflowRunsByFileName: internal error: ListWorkflowRunsByFileName: GET https://api.github.com/repos/234150476/cac-windows/actions/workflows/docker.yml/runs?status=success: 404 Not Found []",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "aad238d3a6e3badb409888970b6904ff978efa06",
        "ran_at": "2026-07-22T18:48:46Z",
        "aggregate_score": 3.2,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-17T14:15:07Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": null,
      "ci_last_conclusion": "FAILURE",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/234150476/cac-windows",
    "host": "github.com",
    "name": "cac-windows",
    "owner": "234150476"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "at_risk",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 38,
      "inputs": {
        "security": 32,
        "vitality": 35,
        "community": 33,
        "governance": 44,
        "engineering": 44
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "at_risk",
        "name": "Vitality",
        "value": 35,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 58,
            "inputs": {
              "commits_last_year": 196,
              "human_commit_share": 1,
              "days_since_last_push": 5,
              "active_weeks_last_year": 6
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "6/52 weeks with commits",
                "points": 4.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 6
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "196 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 196
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "critical",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "releases_count": 0
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "no releases published",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_releases_published",
                    "params": {}
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "no releases",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_releases",
                    "params": {}
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "no releases",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_releases",
                    "params": {}
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 33,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 61,
            "inputs": {
              "packages": [
                "cac-windows"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 4474
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "4,474 downloads/month across npm",
                "points": 48.7,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 4474,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 44,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "at_risk",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 33,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 7,
              "top_contributor_share": 0.62
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 62% of commits",
                "points": 8.6,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 62
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "7 contributors",
                "points": 9.5,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "critical",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution, PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution",
                    "pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "merged_prs": 0,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "no decided pull requests or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_decided_prs_or_data",
                    "params": {}
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 57,
            "inputs": {
              "followers": 38,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "234150476",
              "public_repos": 49,
              "account_age_days": 4162
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "38 followers of 234150476",
                "points": 11.4,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 38,
                      "login": "234150476"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "49 public repos, account ~11 yr old",
                "points": 24.4,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 49
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 11
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "cac-windows"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 5
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 5 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "23 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 23
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "at_risk",
        "name": "Engineering Quality",
        "value": 44,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "at_risk",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 30,
            "inputs": {
              "has_ci": true,
              "has_tests": false,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "4 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 65,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 32,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests, Packaging, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests",
                    "packaging",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 32,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 15,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 3,
              "scorecard_aggregate": 3.2
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "internal error: Client.Actions.ListWorkflowRunsByFileName: internal error: ListWorkflowRunsByFileName: GET https://api.github.com/repos/234150476/cac-windows/actions/workflows/docker.yml/runs?status=success: 404 Not Found []",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 3
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "critical",
        "name": "AI Readiness",
        "value": 29,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.99,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "99 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 99,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "critical",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "has_nix": false,
              "has_tests": false,
              "lockfiles": [],
              "has_dockerfile": true,
              "typed_language": false,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "moderate",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 55,
            "inputs": {
              "primary_language": "Shell",
              "largest_source_bytes": 13930,
              "source_files_sampled": 15,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Shell without a type-check config",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_typecheck_config_language",
                    "params": {
                      "language": "Shell"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/15 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 15,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
    "deps.dev does not index npm:cac-windows@1.0.22; advisories assessed against the repository dependency graph instead"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-22T18:48:53.345693Z",
  "schema_version": "0.26.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/2/234150476/cac-windows.svg",
  "full_name": "234150476/cac-windows",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Оцінки — це сигнали, а не гарантії. Вони відображають публічно видимі практики на GitHub — це не аудит коду й не гарантія безпеки.

Відсутні дані виключаються, а ваги перенормовуються — нуль за відсутність ніколи не ставиться. Методологія версіонована й відкрита: метрики v1.13.0, схема v0.26.0 — повна методологія · вікі метрик.

Як окремий результат виглядає на тлі всього реєстру: сукупна статистикаnpm.