Звіт у форматі JSON машиночитний
{
"data": {
"repo": {
"topics": [],
"is_fork": false,
"size_kb": 7498,
"has_wiki": true,
"homepage": null,
"languages": {
"Just": 1122,
"Rust": 6577477,
"Shell": 189890,
"Python": 12830
},
"pushed_at": "2026-07-25T11:55:46Z",
"created_at": "2026-05-26T00:18:24Z",
"owner_type": "Organization",
"updated_at": "2026-07-25T11:39:35Z",
"description": "Repo Allowlist for Rust",
"is_archived": false,
"is_disabled": false,
"license_spdx": "Apache-2.0",
"default_branch": "main",
"license_spdx_raw": "Apache-2.0",
"primary_language": "Rust",
"significant_languages": [
"Rust"
]
},
"owner": {
"blog": "effortlesssteven.com",
"name": "EffortlessMetrics",
"type": "Organization",
"login": "EffortlessMetrics",
"company": null,
"location": "Canada",
"followers": 7,
"avatar_url": "https://avatars.githubusercontent.com/u/164865351?v=4",
"created_at": "2024-03-25T09:34:01Z",
"is_verified": null,
"public_repos": 75,
"account_age_days": 852
},
"license": {
"state": "standard",
"spdx_id": "Apache-2.0",
"raw_spdx": "Apache-2.0",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v0.1.11",
"kind": "patch",
"published_at": "2026-07-18T00:52:46Z"
},
{
"tag": "v0.1.10",
"kind": "patch",
"published_at": "2026-07-09T00:19:59Z"
},
{
"tag": "v0.1.9",
"kind": "patch",
"published_at": "2026-06-16T04:04:39Z"
},
{
"tag": "v0.1.8",
"kind": "patch",
"published_at": "2026-06-12T21:40:24Z"
},
{
"tag": "v0.1.7",
"kind": "patch",
"published_at": "2026-06-12T20:35:17Z"
}
],
"recent_commits": [
{
"oid": "3366897b078191bee344d03af2d27bf635e322fd",
"body": "…#2804)\n\n* fix(scanner): surface tree-sitter parse errors in scan completeness\n\nTrack files_with_parse_errors in RustScanResult and fail closed in check --mode no-new when partial parses are present, matching the files_skipped precedent (#2658).\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* st\n[…]\n only; stderr warnings break the quiet artifact-output contract in audit integration tests.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "fix(scanner): surface tree-sitter parse errors in scan completeness (…",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-25T11:39:31Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "886e268f6f5e140cd816f4ffd8c1f79ebb17591e",
"body": "* deps: bump fs4 from 0.13.1 to 1.1.0\n\nBumps [fs4](https://github.com/al8n/fs4) from 0.13.1 to 1.1.0.\n- [Release notes](https://github.com/al8n/fs4/releases)\n- [Changelog](https://github.com/al8n/fs4/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/al8n/fs4/commits/1.1.0)\n\n---\nupdated-dependen\n[…]\nbot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Steven Zimmerman, CPA <15812269+EffortlessSteven@users.noreply.github.com>",
"is_bot": true,
"headline": "deps: bump fs4 from 0.13.1 to 1.1.0 (#2769)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-25T11:36:51Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4d820b2414f4fb37548cd9b2c61403e3e80ac99d",
"body": "* feat(migrate): add bespoke-ledger importer adapter (xtask/ripr)\n\nIntroduce a read-only xtask-ripr bespoke ledger dialect importer and wire\nmigrate --from to detect dialect=xtask-ripr before legacy dispatch.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* style: apply rustfmt for bespoke importer lane\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "feat(migrate): bespoke-ledger importer adapter (xtask/ripr) (#2803)",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-25T10:51:51Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "2ac2b669d5a2e4efd7d38bdcab2ffc8da9494eb6",
"body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 5 to 7.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Commits](https://github.com/actions/checkout/compare/v5...v7)\n\n---\nupdated-dependencies:\n- dependency-name: actions/checkout\n dependency-version: '7'\n depen\n[…]\nirect:production\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "ci: bump actions/checkout from 5 to 7 (#2767)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-25T09:37:14Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "780d6a0bdbe6b1b64a6c8ea508640f69fe71a9d4",
"body": "Bumps [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance) from 96b4a1ef7235a096b17240c259729fdd70c83d45 to e8998f949152b193b063cb0ec769d69d929409be.\n- [Release notes](https://github.com/actions/attest-build-provenance/releases)\n- [Changelog](https://github.com/actio\n[…]\n63cb0ec769d69d929409be\n dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "ci: bump actions/attest-build-provenance (#2766)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-25T09:34:11Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fea3c82cac4015c1713db7d785194b36f73f2726",
"body": "Bumps [Swatinem/rust-cache](https://github.com/swatinem/rust-cache) from 42dc69e1aa15d09112580998cf2ef0119e2e91ae to e18b497796c12c097a38f9edb9d0641fb99eee32.\n- [Release notes](https://github.com/swatinem/rust-cache/releases)\n- [Changelog](https://github.com/Swatinem/rust-cache/blob/master/CHANGELOG\n[…]\n38f9edb9d0641fb99eee32\n dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "ci: bump Swatinem/rust-cache (#2765)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-25T09:30:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7032bd0f0b690ce956077a6273ce04ca62da6ca2",
"body": "Bumps [EmbarkStudios/cargo-deny-action](https://github.com/embarkstudios/cargo-deny-action) from c3bbe7e4e3f7baeee1a3dd9aec0a3b2aded580fb to 3c6349835b2b7b196a839186cb8b78e02f7b5f25.\n- [Release notes](https://github.com/embarkstudios/cargo-deny-action/releases)\n- [Commits](https://github.com/embarks\n[…]\n839186cb8b78e02f7b5f25\n dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "ci: bump EmbarkStudios/cargo-deny-action (#2764)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-25T09:25:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fdb165f56a8ba40ff27de95c741f3b6ea791183d",
"body": "Bumps [codecov/codecov-action](https://github.com/codecov/codecov-action) from 4650159d642e33fdc30954ca22638caf0df6cac8 to 18283e04ce6e62d37312384ff67231eb8fd56d24.\n- [Release notes](https://github.com/codecov/codecov-action/releases)\n- [Changelog](https://github.com/codecov/codecov-action/blob/main\n[…]\n12384ff67231eb8fd56d24\n dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "ci: bump codecov/codecov-action (#2763)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-25T09:20:57Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c885ff732e2749027cd2b9dd8543b35307786892",
"body": "Bumps [EffortlessMetrics/ub-review](https://github.com/effortlessmetrics/ub-review) from f0620c358f4a9032d3f832fda92488fd198ab6e9 to a1e64c65e39aadf341f4e5cb14094b9a87f592ad.\n- [Release notes](https://github.com/effortlessmetrics/ub-review/releases)\n- [Changelog](https://github.com/EffortlessMetrics\n[…]\nf4e5cb14094b9a87f592ad\n dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "ci: bump EffortlessMetrics/ub-review (#2762)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-25T09:12:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b2106a2232cc7f7be062003784eb438d9c7b86a2",
"body": "Bumps [tree-sitter](https://github.com/tree-sitter/tree-sitter) from 0.25.10 to 0.26.11.\n- [Release notes](https://github.com/tree-sitter/tree-sitter/releases)\n- [Commits](https://github.com/tree-sitter/tree-sitter/compare/v0.25.10...v0.26.11)\n\n---\nupdated-dependencies:\n- dependency-name: tree-sitte\n[…]\nirect:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "deps: bump tree-sitter from 0.25.10 to 0.26.11 (#2770)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-25T09:08:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c18f384b48da5f22af8f8f86c77dc7def0d9620d",
"body": "…-test\n\ntest: add tool command integration test (#2795)",
"is_bot": false,
"headline": "Merge pull request #2798 from EffortlessMetrics/test/tool-integration…",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-25T08:59:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a0d582eeacb52991c49044b7a5242bbc8399d687",
"body": "Bumps [sha2](https://github.com/RustCrypto/hashes) from 0.10.9 to 0.11.0.\n- [Commits](https://github.com/RustCrypto/hashes/compare/sha2-v0.10.9...sha2-v0.11.0)\n\n---\nupdated-dependencies:\n- dependency-name: sha2\n dependency-version: 0.11.0\n dependency-type: direct:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "deps: bump sha2 from 0.10.9 to 0.11.0",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-25T08:41:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2b6f60b9c12f9531f3ebd6d5194a91b0b8304681",
"body": null,
"is_bot": false,
"headline": "test: restore Command import in tool_output",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-25T08:29:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d8890d7f0a5a0b07b2dc93f318ef98c47a2ea521",
"body": "Bumps [sha2](https://github.com/RustCrypto/hashes) from 0.10.9 to 0.11.0.\n- [Commits](https://github.com/RustCrypto/hashes/compare/sha2-v0.10.9...sha2-v0.11.0)\n\n---\nupdated-dependencies:\n- dependency-name: sha2\n dependency-version: 0.11.0\n dependency-type: direct:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "deps: bump sha2 from 0.10.9 to 0.11.0",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-25T08:23:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "07888aded693d59d4e46c2b01cc7d1e61e8f039e",
"body": "Bumps the patch-updates group with 4 updates in the / directory: [serde](https://github.com/serde-rs/serde), [serde_json](https://github.com/serde-rs/json), [toml](https://github.com/toml-rs/toml) and [clap](https://github.com/clap-rs/clap).\n\n\nUpdates `serde` from 1.0.228 to 1.0.229\n- [Release notes\n[…]\nncy-version: 1.1.3+spec-1.1.0\n dependency-type: direct:production\n update-type: version-update:semver-patch\n dependency-group: patch-updates\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "deps: bump the patch-updates group across 1 directory with 4 updates",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-25T08:23:40Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c1832bc3992190340d338971765ec61bdb9c94ae",
"body": "Avoid compiling the shared support module in the tool_output integration test crate, which triggered clippy dead-code failures under -D warnings.",
"is_bot": false,
"headline": "test: inline cargo_allow_command helper in tool_output",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-25T08:14:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f2279331382d7e67839fd33a64cfb50a73660d00",
"body": "The `tool` subcommand had zero binary-level integration coverage despite\nhaving 10 unit tests. Its identity, digest, and capability-generation\noutput is security-relevant (used by pre-commit verification).\n\nAdd crates/cargo-allow/tests/tool_output.rs with two integration tests:\n- tool_identity_json_\n[…]\ns\n cargo-allow and the schema_id\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2659 pass); cargo-allow check --mode\nno-new (status: passed).",
"is_bot": false,
"headline": "test: add tool command integration test (#2795)",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-25T07:57:26Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "63829a7e77a666d7cc5723146c53c695bdb96799",
"body": "…-0.11.0\n\ndeps: bump sha2 from 0.10.9 to 0.11.0",
"is_bot": false,
"headline": "Merge pull request #2771 from EffortlessMetrics/dependabot/cargo/sha2…",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-25T07:48:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7f003984049f4e2e876de045edae1f4c35f5d2e4",
"body": "…h-updates-2b5d80e5f5\n\ndeps: bump the patch-updates group across 1 directory with 4 updates",
"is_bot": false,
"headline": "Merge pull request #2768 from EffortlessMetrics/dependabot/cargo/patc…",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-25T07:30:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "80ead5a1beb02a6f7671233e924018eea49441d7",
"body": "… output (#2785) (#2793)\n\ncargo-allow prints a 600+ char claim boundary on every human-format run\nwith no way to suppress it short of --format json. CI logs are polluted.\n\nAdd a global --quiet/-q flag that:\n- Suppresses CLAIM_BOUNDARY_TEXT in check/audit human output\n- Suppresses CLAIM_BOUNDARY_TEXT\n[…]\n through every command signature.\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2657 pass); cargo-allow check --mode\nno-new (status: passed).",
"is_bot": false,
"headline": "feat(ux): add --quiet/-q flag to suppress claim boundary and advisory…",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-25T05:28:47Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ad86d12c72a36bd03c1b474aca56aebeb79c65d2",
"body": "Bumps the patch-updates group with 4 updates in the / directory: [serde](https://github.com/serde-rs/serde), [serde_json](https://github.com/serde-rs/json), [toml](https://github.com/toml-rs/toml) and [clap](https://github.com/clap-rs/clap).\n\n\nUpdates `serde` from 1.0.228 to 1.0.229\n- [Release notes\n[…]\nncy-version: 1.1.3+spec-1.1.0\n dependency-type: direct:production\n update-type: version-update:semver-patch\n dependency-group: patch-updates\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "deps: bump the patch-updates group across 1 directory with 4 updates",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-25T05:24:03Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "104c0e850300230239dd4345ebeff1a756994d1d",
"body": "…(#2792)\n\ncargo-allow shipped with Cargo default release profile (no LTO, no strip,\nopt-level=3, full debug paths). For a CPU-bound CLI tool this left\nmeasurable binary size and runtime performance on the floor.\n\nAdd:\n- lto = 'thin' — cross-crate inlining without fat-LTO build cost\n- strip = true — \n[…]\nry\n- codegen-units = 1 — better optimization at cost of slower compile\n\nThese settings apply to all workspace binaries (cargo-allow, cargo-intent,\ncargo-proof).\n\nBuild-only change; no production code.",
"is_bot": false,
"headline": "perf: add [profile.release] with LTO, strip, codegen-units=1 (#2789) …",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-25T05:21:10Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6ab820bed5c4cd55324f709a847ae88f3f59cc17",
"body": "…rectly (#2777, #2778) (#2783)\n\nTwo init.rs bugs:\n\n#2777: The non-force path used exists() + AtomicReplace, leaving a TOCTOU\nwindow between the existence check and the unconditional rename. An external\nprocess that creates the file in the window would be silently overwritten\nwithout --force. Fixed b\n[…]\nnd using the correct action word.\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2656 pass); cargo-allow check --mode\nno-new (status: passed).",
"is_bot": false,
"headline": "fix(init): use CreateNewOnly for non-force path; report overwrite cor…",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-25T04:31:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5280a9a7bf8bf11860de65ea78071f249841a11d",
"body": "…ctions (#2776) (#2782)\n\nThe wildcard branch of source_tree_path_matches_filter checked\nsource_tree_scope_has_wildcard(&item_path) — the file being filtered.\nReal file paths never contain wildcards, so the branch was dead code.\nA glob pattern in the filter_path (e.g. --path 'src/**/*.rs') never\nmatc\n[…]\no fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (616 pass + 1 pre-existing flaky Windows\ntemp-dir doctor test); cargo-allow check --mode no-new (status: passed).",
"is_bot": false,
"headline": "fix(core): source_tree_path_matches_filter supports glob in both dire…",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-25T04:24:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c54ab10ac31463199ca0476d818666458e327524",
"body": "* docs: add SECURITY.md for vulnerability reporting (#1884)\n\ncargo-allow is a supply-chain governance tool with no SECURITY.md —\nexternal users and security researchers had no private reporting path.\n\nAdd SECURITY.md with:\n- Private reporting via email and GitHub Security Advisories\n- Response timel\n[…]\nitives, upstream dependency CVEs)\n- Hardening measures inventory (cargo-deny, Dependabot, SHA-pinned\n actions, OIDC Trusted Publishing, keyless attestation, Windows CI)\n\n* policy: receipt SECURITY.md",
"is_bot": false,
"headline": "docs: add SECURITY.md for vulnerability reporting (#1884) (#2775)",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-25T03:17:43Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1634f535d3a2c82adf3c713a2ca2a9de7ce199fd",
"body": "…1949) (#2774)\n\nThe issue reported that evidence references to directory targets were\ntreated as valid. Investigation found the bug was already fixed: the\nevidence_reference_diagnostic function catches directories at the\nmetadata level (Ok(_) => InvalidLocalPath 'exists but is not a file')\nbefore th\n[…]\nactor\ncannot silently regress it.\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2656 pass); cargo-allow check --mode\nno-new (status: passed).",
"is_bot": false,
"headline": "test(evidence): pin directory-target rejection as InvalidLocalPath (#…",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-25T02:57:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "92c5c71f4098d3b2ce2bfe428dd1c73c65f24f83",
"body": "…773)\n\nThe legacy unsafe-allowlist parser captured scope, justification, and\naudit_url fields but the converter silently dropped them because the\nLegacyUnsafeRule type had no fields for them and the converter had no\npreservation path. Compliance reviews lost provenance on migration.\n\nAdd scope, just\n[…]\non: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (615 pass + 1 pre-existing flaky init\ntest on Windows); cargo-allow check --mode no-new (status: passed).",
"is_bot": false,
"headline": "fix(migrate): preserve unsafe provenance fields via links (#1865) (#2…",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-25T00:17:22Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "53cb843b6ddf7629824ccc503d38ac52e41f2bcd",
"body": "…1870) (#2772)\n\nnormalize_legacy_expires only mapped 'permanent' → 'never'. Legacy\nledgers using RFC3339 timestamps with timezones (2025-12-01T00:00:00Z vs\n2025-12-01T00:00:00-05:00) produced non-deterministic, non-comparable\nLifecycle values — breaking reproducible-migration guarantees.\n\nAdd canoni\n[…]\n plus the plain-date passthrough.\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2654 pass); cargo-allow check --mode\nno-new (status: passed).",
"is_bot": false,
"headline": "fix(migrate): canonicalize legacy expires timestamps to YYYY-MM-DD (#…",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-25T00:10:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2cff1f439aafb0fb817c381526396181c68169e2",
"body": "Remove RTK from the live agent contract and reusable PR and plan templates. Keep historical evidence and runtime compatibility behavior unchanged.",
"is_bot": false,
"headline": "chore: remove RTK command wrapper guidance (#2761)",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T23:27:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c9bc1d519eb6ae5be164b6139fe19e6cfdce2cd3",
"body": "Bumps [sha2](https://github.com/RustCrypto/hashes) from 0.10.9 to 0.11.0.\n- [Commits](https://github.com/RustCrypto/hashes/compare/sha2-v0.10.9...sha2-v0.11.0)\n\n---\nupdated-dependencies:\n- dependency-name: sha2\n dependency-version: 0.11.0\n dependency-type: direct:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "deps: bump sha2 from 0.10.9 to 0.11.0",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-24T23:00:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2dc7c28d60351cec88e2a02097753ad2f091a8ff",
"body": "* ci: add Dependabot for Rust deps and GitHub Actions (#1898)\n\ncargo-allow had no automated dependency update path. Combined with the\ncargo-deny supply-chain audit (#1897), Dependabot ensures advisories are\nboth caught (deny) and patched (Dependabot PRs).\n\nConfiguration:\n- cargo ecosystem: weekly, M\n[…]\nen PRs max, patch updates grouped\n- github-actions ecosystem: weekly, Monday, 5 open PRs max\n\nCI-only; no production code changes.\n\n* policy: receipt .github/dependabot.yml\n\n* chore: trigger CI re-run",
"is_bot": false,
"headline": "ci: add Dependabot for Rust deps and GitHub Actions (#1898) (#2758)",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T22:58:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "66ebd703a631a84292815e8da934c895d710a409",
"body": "cargo-allow had no test coverage reporting and no automated way to track\ncoverage regressions. As a governance tool, coverage visibility matters.\n\nAdd a coverage job to ci.yml that runs cargo-tarpaulin on the full\nworkspace and uploads the Cobertura XML to Codecov. The job is separate\nfrom the main test job so tarpaulin's instrumentation overhead doesn't\nslow down PR feedback. fail_ci_if_error: false so coverage upload\nfailures don't block merges.\n\nCI-only; no production code changes.",
"is_bot": false,
"headline": "ci: add cargo-tarpaulin coverage reporting to Codecov (#1902) (#2760)",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T22:32:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "70abd9d51f34222152ae7af26426f18ae74e75d5",
"body": "The release install-smoke job ran on ubuntu-latest only, so the published\nbinary was never tested on Windows — the repo's primary dev OS. A Windows\nbinary could ship broken without any CI signal.\n\nMatrix the install-smoke job across ubuntu-latest and windows-latest with\nfail-fast: false. Added expli\n[…]\nds the OS.\n\nThe smoke script (scripts/release-install-smoke.sh) already uses bash and\ncargo install, which work on Windows via Git Bash. No script changes needed.\n\nCI-only; no production code changes.",
"is_bot": false,
"headline": "ci: matrix release install-smoke across ubuntu+windows (#1904) (#2759)",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T22:26:59Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "dfb47b5f1247680dfec0ee9e8ee5b47b1859d6f6",
"body": "Enable repo-wide delegate_spec_system cutover, replace CI embedded audit with cutover receipt, and document honest fail-closed posture until cargo-intent audit vertical ships.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "feat(#2568): retire embedded spec-system CI audit path (#2757)",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T20:50:50Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "dac02808a09a61e80b76aa8a15db7f286d4a0445",
"body": "Wave 6 closeout: validate packaging, boundaries, support postures, forbidden production deps, dogfood/simplification prerequisites, and rollback documentation without authorizing physical repository extraction.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "feat(#2559): add extraction readiness checklist receipt (#2756)",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T20:32:58Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "b287fabba89946dbda97319d2d2e6392e7589776",
"body": "* feat(#2208): add simplification inventory and remove io shim\n\nClassify extraction abstractions with mandatory labels, fold cargo-allow io helpers into command_support, and add audit script plus closeout.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* fix(#2208): update move ledger after io sh\n[…]\n: Cursor <cursoragent@cursor.com>\n\n* fix(#2208): move re-exports before io_tests for clippy\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "feat(#2208): add simplification inventory and remove io shim (#2755)",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T20:22:29Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "65df48a2c6080eb34ea4a1b8090e959597ade616",
"body": "* feat(#2558): add three-product dogfood pipeline smoke\n\nRun one real source change through cargo-intent, bridged proof planning, stubbed RIPR/Hawk evidence, gates, and reconciliation with honest claim boundary; wire CI and closeout.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* fix(#2558): re\n[…]\nCursor <cursoragent@cursor.com>\n\n* fix(#2558): align stub fixture needles with parity files\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "feat(#2558): add three-product dogfood pipeline smoke (#2754)",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T19:55:30Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "505502bdd0b1c13bfc40bb107a6d3dcd6749079f",
"body": "* feat(#2605): add exact-candidate interop smoke A-E\n\nRun packaged three-product interop journeys outside the monorepo with installed candidate binaries, negative scenario controls, CI wiring, and offline receipt characterization.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* fix(#2605): corre\n[…]\ncursoragent@cursor.com>\n\n* fix(#2605): accept findings exit from cargo-intent change status\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "feat(#2605): add exact-candidate interop smoke A-E (#2753)",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T18:59:16Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "8c49efeaed59d6812eec55d11e59191be475c3ee",
"body": "Introduce proof.hawk.v1 provider with analysis receipt validation, finding mapping, source-anchor resolution, and receipt currentness so Hawk liveness stays provider-owned while cargo-proof consumes snapshots.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "feat(#2555): add proof-adapter-hawk analysis adapter (#2752)",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T17:59:47Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "3fd7fb3b2b9ecdf619ad7bed3726adf7092ebc91",
"body": "Land RiprGripReceiptV1 validation, receipt currentness, requirement-grip comparison, and ProofProviderV1 wiring without RIPR or intent crate imports. Authored evidence purpose remains cargo-intent owned.",
"is_bot": false,
"headline": "feat(#2556): add proof-adapter-ripr grip adapter (#2751)",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T17:42:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d28ac4b28515d4f60a9aaafd5ebbb6a3e0e37cd1",
"body": "* feat(#2567/#2554): add proof-adapter-cargo-allow provider\n\nLand snapshot-bound read-only cargo-allow provider contract, public process discovery, dry-run argv compilation via proof-adapter-command, and ProofProviderV1 wiring without cargo-allow private imports.\n\n* fix(#2567): satisfy source-tree c\n[…]\nllow from package smoke\n\nUnpublished adapter depends on proof-adapter-command; keep it out of workspace package verification until #2604 publish posture.\n\n* fix(#2567): satisfy clippy on adapter crate",
"is_bot": false,
"headline": "feat(#2567/#2554): add proof-adapter-cargo-allow provider (#2750)",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T17:21:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6d5537123d98fc7908c12d05ebf9752a7686c51d",
"body": "* feat(#2589-B): add thin cargo-proof CLI\n\nIntroduce cargo-proof product shell with identity, render, exit mapping, plan and dry-run commands wired to proof-engine, plus six-crate proof-candidate install smoke.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* fix(#2589-B): allow-dirty package in proof-candidate-smoke\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "feat(#2589-B): add thin cargo-proof CLI (#2749)",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T16:02:35Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "bf7ec4e014662e04b4b234ca1bd1236dc74517d5",
"body": "* feat(#2589-A): scaffold proof-engine crate\n\nIntroduce provider registry, captured receipts, obligation planning, currentness, dry-run, explicit execution gates, cache, contradiction detection, and phase-gate evaluation.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* fix(#2589-A): align proof-\n[…]\ning\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* chore: cargo fmt proof-engine tests\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "feat(#2589-A): scaffold proof-engine crate (#2748)",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T15:34:37Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "4d446a9ca82f23f20c3f8f31b8fa2948d5df16e9",
"body": "Introduce reviewed command registry, structured argv compilation, dry-run reports, and receipt interpretation with prose-to-shell rejection.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "feat(#2603-B): scaffold proof-adapter-command crate (#2747)",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T15:07:52Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "f95ce9a06e7d600ad5f6c1e8bb64582cbbb080f0",
"body": "* feat(#2603-A): scaffold proof-provider-api crate\n\nAdd provider API trait, fake provider, conformance harness, and parity/ledger registration.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* fix(#2603-A): satisfy package smoke and crate doc boundary\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* fix(#2603-A): allow proof-provider-api manifest and fixture README\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "feat(#2603-A): scaffold proof-provider-api crate (#2746)",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T14:43:58Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "edcf65627ee8d2c625e02b81e485031b781343ab",
"body": "* feat(#2588-B): add proof-protocol plan and receipt DTOs\n\nLand provider-neutral plan, capability, receipt, contradiction, and phase-gate transport with parity fixtures, ledger entries, and shims.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* chore(#2588-B): refresh lockfile for proof-protocol deps\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "feat(#2588-B): add proof-protocol plan and receipt DTOs (#2745)",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T14:20:56Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "549149ae17df7ff2989cf0d6d599fdc40585df36",
"body": "Combine translation and recompile contract into a settlement plan with await-apply, await-recompile-proof, and await-currentness-refresh residual obligations.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "feat(#2613-F): add intent-edit settlement plan (#2744)",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T14:02:46Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "4fe64f6733dc3574ae02255255fd81e2dd5c8cd0",
"body": "* feat(#2613-E): compile recompile contract via intent-engine\n\nBind intent-edit translation output to intent-engine phase-obligation transport with parity fixture, ledger, and shim registration.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* fix(#2613-E): use transport DTOs without intent-engin\n[…]\ncally and validate round-trip in dev tests. Fix parity path recursion and clippy dead-code.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "feat(#2613-E): compile recompile contract via intent-engine (#2743)",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T13:52:28Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "c9d0408c94d1793becf5d2e1d7c2fdce01eea473",
"body": "…t-translation\n\nfeat(#2613-D): translate intent-edit plans to repo-edit",
"is_bot": false,
"headline": "Merge pull request #2742 from EffortlessMetrics/cursor/2613d-repo-edi…",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T13:26:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "394efbcabd143366754e7c0e706974fe243cf45c",
"body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "fix(#2613-D): remove duplicate move-ledger key",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T13:14:26Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "76c888fb4507e028f6683b65c5716ba4b4c42070",
"body": "Add repo-edit translation DTOs that map validated edit plans and approval envelopes into SingleTargetApplyMode requests without executing apply.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "feat(#2613-D): translate intent-edit plans to repo-edit",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T13:02:53Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "6fe67305273776ac77a84d056493e2a8b64d9913",
"body": "…approval\n\nfeat(#2613-C): add dialect adapters and approval/currentness",
"is_bot": false,
"headline": "Merge pull request #2741 from EffortlessMetrics/cursor/2613c-dialect-…",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T13:00:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f1cf1e64f9c55857c0909b2fbaaf566a1dc4bd34",
"body": "Land intent-edit dialect selector normalization and approval/currentness fail-closed envelopes with parity/ledger registration; repo-edit translation deferred to #2613-D.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "feat(#2613-C): add dialect adapters and approval/currentness",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T12:48:12Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "5d7217d1499f2f3d999067c917025dcc4883c30a",
"body": "…otocol-scaffold\n\nfeat(#2588-A): scaffold proof-protocol crate and boundary",
"is_bot": false,
"headline": "Merge pull request #2740 from EffortlessMetrics/cursor/2588a-proof-pr…",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T12:44:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "63c597d4e52076c72be1c07ba48c89c2707c8f51",
"body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "fix(#2588-A): satisfy source-tree boundary rustdoc check",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T12:33:13Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "43d8f30cdd3d8c5242c7a3cf528e46d2f1654113",
"body": "Introduce proof-protocol with parity/ledger registration, ADR-0002 forbidden-edge tests, and policy surfaces without wiring cargo-allow to proof-protocol.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "feat(#2588-A): scaffold proof-protocol crate and boundary",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T12:19:10Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "9caa9d8d35933b434fe14709c29c4991c7783ad4",
"body": "feat(#2613-B): add intent-edit plan and find-before-create",
"is_bot": false,
"headline": "Merge pull request #2739 from EffortlessMetrics/cursor/2613b-edit-plan",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T12:16:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3d40197e20a92f2ea54836431e1a67c24142f0b6",
"body": "Land edit-plan transport with stable action IDs, find-before-create validation, parity fixture, and ledger registration without repo-edit translation yet.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "feat(#2613-B): add intent-edit plan and find-before-create",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T12:03:28Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "5e356dd094bf18a1ff22cd56f1e804b8c6dd331e",
"body": "…dit-scaffold\n\nfeat(#2613-A): scaffold intent-edit crate and boundary topology",
"is_bot": false,
"headline": "Merge pull request #2738 from EffortlessMetrics/cursor/2613a-intent-e…",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T12:00:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "be58541ad771687522bfe8009ed785a3181d2bfc",
"body": "Add IntentEdit to extraction parity stages, fix allow classification for intent-edit docs, and keep scaffold deps on repo-edit only so workspace packaging stays green.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "fix(#2613-A): register IntentEdit stage and package-safe deps",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T11:48:09Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "64f3659e4b930ae19960084ab15eb005148642f2",
"body": "Introduce intent-edit with parity/ledger registration, ADR-0002 forbidden-edge tests, and policy surfaces without wiring cargo-allow to intent-edit.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "feat(#2613-A): scaffold intent-edit crate and boundary topology",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T11:30:36Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "12c80d559f6caa9be89eb14fefeabf1e9f9bc646",
"body": "propose --write uses CreateNewOnly or ReplaceWithBackup with fail-closed repository containment.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "feat(#2602-J): migrate propose through repo-edit apply (#2737)",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T11:24:07Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "579f0e0a540369cdded6cd00c873b5443f649258",
"body": "* feat(#2602-I): migrate migrate through repo-edit apply\n\nmigrate --update and --out forward policy writes through SingleTargetApplyMode with repository-contained --out targets.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* fix(#2602-I): hybrid apply for in-repo migrate --out\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "feat(#2602-I): migrate migrate through repo-edit apply (#2736)",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T11:04:24Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "13beac9eb3e4b34c0998bfd36cc0c42fa4999aba",
"body": "* feat(#2602-H): migrate add through repo-edit apply\n\nadd --update/--write and add --from-plan forward policy writes through SingleTargetApplyMode with backup semantics preserved.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* fix(#2602-H): canonicalize portable mutation targets on Windows\n\nCo-\n[…]\nsor <cursoragent@cursor.com>\n\n* fix(#2602-H): best-effort canonical paths for apply targets\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "feat(#2602-H): migrate add through repo-edit apply (#2735)",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T10:47:33Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "d5b4701b4b42718108b4c12e8995f34c183c76e8",
"body": "Replace force_create_new with AtomicReplace, CreateNewOnly, and ReplaceWithBackup modes preserving --force .toml.bak behavior.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "feat(#2602-G): add SingleTargetApplyMode backup semantics (#2734)",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T10:16:51Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "821c243e2de10933fa4e05b781ff8cde0d572fa1",
"body": "Prune --write rewrites policy via apply_single_target with containment and mutation-lock unchanged.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "feat(#2602-F): migrate prune through repo-edit apply (#2733)",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T09:57:13Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "cbc8c7d10c910b996202c77ff087c1e729f50f84",
"body": "Refresh --write rewrites policy via apply_single_target with containment and mutation-lock unchanged.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "feat(#2602-E): migrate refresh through repo-edit apply (#2732)",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T09:41:55Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "0f2c25cd6b4a23c344de5a5cc1fb9a26f6c38919",
"body": "* feat(#2602-D): migrate init through repo-edit apply\n\nRoute cargo-allow init policy writes through repo-edit::single_target_apply with parity fixture, shim registry, and init test alignment.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* fix(#2602-D): align init parent error test with apply path\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "feat(#2602-D): migrate init through repo-edit apply (#2731)",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T09:22:01Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "47739d1097c56def4ae7bd5d76522c1da1a98e65",
"body": "* feat(#2602-C): add generic single-target apply receipts\n\nIntroduce repo-edit apply receipt envelope, digest helpers, and single_target_apply with containment-checked portable receipts and parity fixtures.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* fix(#2602-C): receipt parity allow entry and clippy\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "feat(#2602-C): generic single-target apply receipts in repo-edit (#2730)",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T09:04:45Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "2a6fada9edf91f72c874140581f08d4329a7c4fc",
"body": "* feat(#2602-B): extract single-target atomic write to repo-edit\n\nMove write_file and write_file_no_overwrite into repo-edit::atomic_write with cargo-allow ModuleFacade shims, parity fixtures, and focused regression tests.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* fix(#2602-B): receipt par\n[…]\nv1.toml so diff/shallow-diff characterization passes, and apply rustfmt to repo-edit tests.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "feat(#2602-B): extract single-target atomic write to repo-edit (#2729)",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T08:39:56Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "2b24e7cddc958e1e8eed6a320c2ae081f979ec98",
"body": "* feat(#2602-A): scaffold repo-edit lock and containment\n\nExtract mutation_lock and assert_path_within_root into repo-edit with cargo-allow ModuleFacade shims, parity fixtures, and stage receipt. Documents #2568 residual spec-system CI audit path.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n* \n[…]\n<cursoragent@cursor.com>\n\n* fix(#2602-A): document repo-edit source-tree boundary in lib.rs\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "feat(#2602-A): scaffold repo-edit lock and containment (#2728)",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T07:59:44Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "78780b30a50c23ede3ac05e65175ca4e105a3627",
"body": "* refactor(#2568): remove embedded precommit evaluator\n\nStaged precommit now delegates to cargo-intent or fails with provider_unavailable; embedded spec_system_workspace evaluation path removed from spec_precommit. Updates conformance tests, stage receipts, and parity claim boundaries.\n\nCo-authored-\n[…]\nrsor.com>\n\n* fix(#2568): use NotApplicable for empty delegated precommit; repair allow.toml\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "refactor(#2568): remove embedded precommit evaluator (#2727)",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T06:58:24Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "129dc18d001cd35793b9ca81d70b06ab2f36d02e",
"body": "…(#2726)\n\nWhen delegate_spec_system is enabled, legacy spec-system commands and the embedded precommit evaluator reject instead of falling back; staged precommit still delegates only via delegate_staged_precommit. Adds cutover fixtures, parity/shim claim updates, and reachability receipt evidence for #2568.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "feat(#2601-C): fail closed embedded spec-system authority at cutover …",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T06:22:59Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "2632bca73d66efcc69cb195136a959330ba2395b",
"body": "…recommit-delegate\n\nfeat(#2601-B): delegate staged precommit to cargo-intent",
"is_bot": false,
"headline": "Merge pull request #2722 from EffortlessMetrics/cursor/2601b-staged-p…",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T06:04:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cd321b9518f70f63276ab51eaf6f5cb6d1f47292",
"body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "ci(#2601-B): build cargo-intent before delegation e2e tests",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T05:47:26Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "f1b90f250f953f42332ee7da169dabee3cd44e8b",
"body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "style: rustfmt intent_delegate and release_prep_tests",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T05:44:10Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "0496822b31f32d31ea667e0bd7f36cd90fbf8719",
"body": "When intent-delegation config enables delegate_staged_precommit, cargo-allow\ninvokes cargo-intent via subprocess and validates repo.analysis-receipt.v1\nthrough repo-protocol only, without an intent-protocol dependency.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "feat(#2601-B): delegate staged precommit to cargo-intent",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T05:41:01Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "6ab43a8043d1a4d78ebfa70a7eca0ae37de4ae7f",
"body": "…#2724)\n\n* ci: add cargo-deny supply-chain audit and CODEOWNERS (#1897, #1899)\n\ncargo-allow is a governance tool but had no cargo-deny supply-chain audit\nand no CODEOWNERS file.\n\nAdd a cargo-deny CI job running cargo deny check advisories bans licenses\nsources on ubuntu-latest with a deny.toml confi\n[…]\npping each crate/directory to its owner for automatic\nreview requests.\n\nChild of #1786. CI-only; no production code changes.\n\n* fix(ci): correct cargo-deny-action SHA; receipt deny.toml and CODEOWNERS",
"is_bot": false,
"headline": "ci: add cargo-deny supply-chain audit and CODEOWNERS (#1897, #1899) (…",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T04:42:59Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "457d9303ff3d4fd280d8e9f1fac8b029d2a17548",
"body": "…725)\n\nParse errors from legacy migration said 'missing field owner' with no\nindication of which legacy ledger file produced the error. On a repo with\nmultiple ripr ledger files, the operator had to grep by hand.\n\nWrap load_legacy_or_canonical (single-file path) and load_lane_config\n(batch path) wit\n[…]\nallowlist`): missing field owner'\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2510 pass); cargo-allow check --mode\nno-new (status: passed).",
"is_bot": false,
"headline": "fix(migrate): parse errors include source legacy filename (#1868) (#2…",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T04:10:37Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ea457e25acd2cd1334c82b593715df982162b310",
"body": "…(#1861) (#2723)\n\nimport_legacy_policy_dir concatenated lane outputs without checking global\nID uniqueness before validate_policy. When two lanes produced entries with\nthe same ID (e.g. both had id = allow-1), validate_policy caught the\nduplicate and aborted the entire migration — no partial result,\n[…]\nboth survive with namespaced IDs.\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2510 pass); cargo-allow check --mode\nno-new (status: passed).",
"is_bot": false,
"headline": "fix(migrate): namespace cross-lane ID collisions instead of aborting …",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T03:24:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d83cacdc9a55fd94eaaad1cbbc1a2aa3cc601068",
"body": "cmd_migrate only called validate_policy, skipping the source-tree evidence\nreference validation that add and refresh enforce. A migration could write\nentries with evidence pointing at non-existent or out-of-tree files to the\nlive ledger.\n\nAdd validate_evidence_references_for_source_tree to the --upd\n[…]\nlidator has the source-tree root.\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2509 pass); cargo-allow check --mode\nno-new (status: passed).",
"is_bot": false,
"headline": "fix(cli): migrate --update validates evidence references (#1871) (#2717)",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T02:21:11Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ebf60ede167ae2a9172d365ae21522d48482d7f4",
"body": "…721)\n\nimport_legacy_policy_dir iterated only known lane descriptors and silently\nskipped any .toml files in the directory that didn't match. A user\nmigrating a ripr ledger with a custom section (e.g. [vendor] or [sbom])\nsaw 'migration complete' and silently lost that section.\n\nDetect unrecognized .\n[…]\noad_repo_policy_migration_config.\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2509 pass); cargo-allow check --mode\nno-new (status: passed).",
"is_bot": false,
"headline": "fix(migrate): warn on unrecognized legacy directory files (#1867) (#2…",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T02:15:12Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fd9006094f564edc7ca6f7f4567c1a0f66ebe833",
"body": "…2696)\n\nlocation_drift fired on any 1-line delta, so every receipt drifted the\nmoment any code above an entry changed. This flooded the advisory channel\nand eroded reviewer trust — the exact opposite of what drift detection\nshould do.\n\nAdd DRIFT_LINE_TOLERANCE (default 3): line-only shifts within th\n[…]\nsage_fires_on_column_only_change.\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2509 pass); cargo-allow check --mode\nno-new (status: passed).",
"is_bot": false,
"headline": "fix(match): location_drift tolerance for small line shifts (#1808) (#…",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T01:27:40Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "be4ea6daed243f3462a5801beed91d7add169396",
"body": "…handling (#1858) (#2695)\n\nevidence_repair_queues was conditionally omitted when empty in three\ndifferent ways across three artifacts:\n- report_json.rs: skipped the entire array when empty (early return)\n- receipt.rs: only inserted the key when queues was non-empty\n- doctor.rs: unrelated conditional\n[…]\npt_error, diff) with the new key.\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2505 pass); cargo-allow check --mode\nno-new (status: passed).",
"is_bot": false,
"headline": "fix(report): always emit evidence_repair_queues for consistent empty-…",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T00:55:11Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c9b877b47a7a5a22fd57f7d210a79b64620c0f26",
"body": "…ds (#1877) (#2694)\n\nis_generated_path used file_name.contains(\".generated.\") and\nfile_name.ends_with(\".generated\") which matched compound words like\nreport-pre-generated.json where generated is part of a larger word, not a\nfile extension marker.\n\nReplace with has_generated_extension which splits on\n[…]\nes and three true-positive cases.\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2506 pass); cargo-allow check --mode\nno-new (status: passed).",
"is_bot": false,
"headline": "fix(scanner): .generated heuristic no longer misfires on compound wor…",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-24T00:44:13Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8a18189a0374755097fdc28267c861683c151288",
"body": "…strings (#2659) (#2672)\n\nextract_lints tracked paren depth correctly but the final .split(',')\nwas a flat split that did not skip commas inside string literals. A\nreason like reason = \"see policy: a, b\" produced a spurious extra\nlint entry with a corrupt identity from the comma-separated fragment.\n\n[…]\nped quotes inside reason strings.\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2500 pass); cargo-allow check --mode\nno-new (status: passed).",
"is_bot": false,
"headline": "fix(scanner): extract_lints no longer splits on commas inside reason …",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-23T23:13:46Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1c96a3a8666f575fed17e2f734f37af7704b8a92",
"body": "…capes (#1839) (#2671)\n\nvalidate_import_roots_config only checked duplicate id and duplicate path.\nThe entry.path was later joined via root.join(&entry.path) at discover.rs\nwith no source-tree-relative validation — the same bug class the federation\nlayer calls out in its #2011 comment. An absolute p\n[…]\nccepts_source_tree_relative_path.\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2502 pass); cargo-allow check --mode\nno-new (status: passed).",
"is_bot": false,
"headline": "fix(policy): validate import-root paths for traversal and absolute es…",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-23T23:06:57Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "df3abb8fdf2e0c9ddd57bfaed98ad75b1c8366d3",
"body": "classification is a free-form string, but baseline_debt is the only value\nwith structural lifecycle semantics (requires expires + created, caps at\n120 days, blocks in Strict/Release). A typo like baseline-debt or\nBaselineDebt silently bypassed all three enforcements.\n\nAdd looks_like_baseline_debt_ty\n[…]\ng passes, unrelated values pass).\n\nValidation: cargo fmt --check; cargo clippy --workspace --all-targets;\ncargo test --workspace --locked (2501 pass); cargo-allow check --mode\nno-new (status: passed).",
"is_bot": false,
"headline": "fix(policy): reject baseline_debt classification typos (#2661) (#2670)",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-23T23:06:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7c8b30b9ded33e5c1206bce90736515d34dfcdd8",
"body": "…rovider-discovery\n\nfeat(#2601-A): cargo-intent provider discovery",
"is_bot": false,
"headline": "Merge pull request #2669 from EffortlessMetrics/cursor/2601a-intent-p…",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-23T22:03:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8c2e7e80606d2aa7facee01404322fa6eea9d18d",
"body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "fix(#2601-A): wire provider discovery into doctor for clippy",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-23T21:58:19Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "3c670a0a0986bacc31e112a569495e7fd044d250",
"body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "chore: rustfmt intent_provider",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-23T21:51:56Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "fc4a9f106538ad2ec0d6958c8d55e78847e55c7a",
"body": "Discover cargo-intent via explicit override, compatibility config, then PATH while rejecting workspace target and crates paths.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "feat(#2601-A): cargo-intent provider discovery",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-23T21:46:10Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "c5883f0625fa301c0ccba470d571b4897e795f3e",
"body": "…nstall-smoke\n\nfeat(#2599-C): intent-candidate isolated install smoke",
"is_bot": false,
"headline": "Merge pull request #2657 from EffortlessMetrics/cursor/2599c-intent-i…",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-23T21:42:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fba19d8db50feff8853eba2bc4b086deacb8cdda",
"body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "fix(#2599-C): scope install isolation to cargo-intent closure",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-23T21:33:24Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "605dbb0965fad7184e4402e006536880ba5c8bab",
"body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "fix(#2599-C): avoid patch writer clobbering crate loop var",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-23T21:28:23Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "df54785d10e56e4993b00252de541bd5cf41b152",
"body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "fix(#2599-C): read packaged crates from isolated target dir",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-23T21:24:18Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "616d2b0b98a4235093e70be20d223380a4363f31",
"body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "fix(#2599-C): incremental patch without --locked",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-23T21:18:39Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "ef7b3f238ab389899a25cad30d5f109fa39834de",
"body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "fix(#2599-C): package intent deps without patch lock drift",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-23T21:11:53Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "048e79fd53979cbce6551db42e04c76b493a618d",
"body": "Prove the seven-crate intent stack packages and installs outside the workspace without proof/test invocation or workspace target/debug leakage.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "feat(#2599-C): intent-candidate isolated install smoke",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-23T21:00:23Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "d839ea6d62f1470612f924ca243e0496e20a5c98",
"body": "* feat(#2599-B): change status staged precommit vertical\n\nWire cargo intent change status --staged --phase precommit through repo-snapshot, intent-engine phase obligations, and intent-protocol transport with render/exit mapping. No cargo-allow production dependency on intent crates.\n\nCo-authored-by:\n[…]\n\n\n* fix(#2599-B): restore parity registry field and exclude cargo-intent from package smoke\n\nCo-authored-by: Cursor <cursoragent@cursor.com>\n\n---------\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "feat(#2599-B): change status staged precommit vertical (#2656)",
"author_name": "Steven Zimmerman, CPA",
"author_login": "EffortlessSteven",
"committed_at": "2026-07-23T20:53:31Z",
"body_truncated": true,
"is_coding_agent": true
}
],
"releases_count": 5,
"commits_last_year": 2295,
"latest_release_at": "2026-07-18T00:52:46Z",
"latest_release_tag": "v0.1.11",
"releases_from_tags": false,
"days_since_last_push": 0,
"active_weeks_last_year": 9,
"days_since_latest_release": 7,
"mean_days_between_releases": 8.8
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": true,
"health_percentage": 100,
"has_issue_template": false,
"has_code_of_conduct": true,
"has_pull_request_template": true
},
"ecosystem": {
"packages": [
{
"name": "allow-core",
"exists": true,
"license": "MIT OR Apache-2.0",
"keywords": [
"audit",
"governance",
"policy",
"rust",
"scanner",
"development-tools"
],
"ecosystem": "crates",
"matches_repo": true,
"registry_url": "https://crates.io/crates/allow-core",
"is_deprecated": false,
"latest_version": "0.1.11",
"repository_url": "https://github.com/EffortlessMetrics/cargo-allow",
"versions_count": 12,
"total_downloads": 6064,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": 2021,
"first_published_at": "2026-05-27T03:18:05.875614Z",
"latest_published_at": "2026-07-18T00:50:11.488335Z",
"latest_version_yanked": false,
"days_since_latest_publish": 7
},
{
"name": "allow-diff",
"exists": true,
"license": "MIT OR Apache-2.0",
"keywords": [
"audit",
"governance",
"policy",
"rust",
"scanner",
"development-tools"
],
"ecosystem": "crates",
"matches_repo": true,
"registry_url": "https://crates.io/crates/allow-diff",
"is_deprecated": false,
"latest_version": "0.1.11",
"repository_url": "https://github.com/EffortlessMetrics/cargo-allow",
"versions_count": 12,
"total_downloads": 5656,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": 1885,
"first_published_at": "2026-05-27T03:47:57.520975Z",
"latest_published_at": "2026-07-18T00:51:02.330957Z",
"latest_version_yanked": false,
"days_since_latest_publish": 7
},
{
"name": "allow-rust",
"exists": true,
"license": "MIT OR Apache-2.0",
"keywords": [
"audit",
"governance",
"policy",
"rust",
"scanner",
"development-tools"
],
"ecosystem": "crates",
"matches_repo": true,
"registry_url": "https://crates.io/crates/allow-rust",
"is_deprecated": false,
"latest_version": "0.1.11",
"repository_url": "https://github.com/EffortlessMetrics/cargo-allow",
"versions_count": 12,
"total_downloads": 5702,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": 1901,
"first_published_at": "2026-05-27T03:18:39.115606Z",
"latest_published_at": "2026-07-18T00:50:40.210362Z",
"latest_version_yanked": false,
"days_since_latest_publish": 7
},
{
"name": "allow-files",
"exists": true,
"license": "MIT OR Apache-2.0",
"keywords": [
"audit",
"governance",
"policy",
"rust",
"scanner",
"development-tools"
],
"ecosystem": "crates",
"matches_repo": true,
"registry_url": "https://crates.io/crates/allow-files",
"is_deprecated": false,
"latest_version": "0.1.11",
"repository_url": "https://github.com/EffortlessMetrics/cargo-allow",
"versions_count": 12,
"total_downloads": 5698,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": 1899,
"first_published_at": "2026-05-27T03:18:34.007252Z",
"latest_published_at": "2026-07-18T00:50:30.152040Z",
"latest_version_yanked": false,
"days_since_latest_publish": 7
},
{
"name": "allow-match",
"exists": true,
"license": "MIT OR Apache-2.0",
"keywords": [
"audit",
"governance",
"policy",
"rust",
"scanner",
"development-tools"
],
"ecosystem": "crates",
"matches_repo": true,
"registry_url": "https://crates.io/crates/allow-match",
"is_deprecated": false,
"latest_version": "0.1.11",
"repository_url": "https://github.com/EffortlessMetrics/cargo-allow",
"versions_count": 12,
"total_downloads": 5669,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": 1890,
"first_published_at": "2026-05-27T03:27:40.457493Z",
"latest_published_at": "2026-07-18T00:50:43.257274Z",
"latest_version_yanked": false,
"days_since_latest_publish": 7
},
{
"name": "cargo-allow",
"exists": true,
"license": "MIT OR Apache-2.0",
"keywords": [
"audit",
"governance",
"policy",
"rust",
"scanner",
"command-line-utilities",
"development-tools"
],
"ecosystem": "crates",
"matches_repo": true,
"registry_url": "https://crates.io/crates/cargo-allow",
"is_deprecated": false,
"latest_version": "0.1.11",
"repository_url": "https://github.com/EffortlessMetrics/cargo-allow",
"versions_count": 12,
"total_downloads": 5608,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": 1869,
"first_published_at": "2026-05-27T04:07:37.858491Z",
"latest_published_at": "2026-07-18T00:51:22.688717Z",
"latest_version_yanked": false,
"days_since_latest_publish": 7
}
]
},
"popularity": {
"forks": 2,
"stars": 0,
"watchers": 0,
"fork_history": {
"days": [
{
"date": "2026-07-23",
"count": 2
}
],
"complete": true,
"collected": 2,
"total_forks": 2
},
"star_history": {
"days": [],
"complete": true,
"collected": 0,
"total_stars": 0,
"collected_at": null
},
"open_issues_and_prs": 407
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [
"examples"
],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": false,
"bootstrap_files": [
"justfile"
],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [],
"toolchain_manifests": [
"Cargo.toml",
"crates/allow-core/Cargo.toml",
"crates/allow-diff/Cargo.toml",
"crates/allow-files/Cargo.toml",
"crates/allow-inventory/Cargo.toml",
"crates/allow-match/Cargo.toml",
"crates/allow-policy-legacy/Cargo.toml",
"crates/allow-policy/Cargo.toml",
"crates/allow-report/Cargo.toml",
"crates/allow-rust/Cargo.toml",
"crates/cargo-allow/Cargo.toml",
"crates/cargo-intent/Cargo.toml",
"crates/cargo-proof/Cargo.toml",
"crates/intent-edit/Cargo.toml",
"crates/intent-engine/Cargo.toml",
"crates/intent-model/Cargo.toml",
"crates/intent-protocol/Cargo.toml",
"crates/proof-adapter-cargo-allow/Cargo.toml",
"crates/proof-adapter-command/Cargo.toml",
"crates/proof-adapter-hawk/Cargo.toml",
"crates/proof-adapter-ripr/Cargo.toml",
"crates/proof-engine/Cargo.toml",
"crates/proof-protocol/Cargo.toml",
"crates/proof-provider-api/Cargo.toml",
"crates/repo-edit/Cargo.toml",
"crates/repo-protocol/Cargo.toml",
"crates/repo-snapshot/Cargo.toml",
"crates/rust-source-index/Cargo.toml"
],
"largest_source_bytes": 229120,
"source_files_sampled": 1010,
"oversized_source_files": 4,
"agent_instruction_files": [
"AGENTS.md"
],
"agent_instruction_max_bytes": 5031
},
"dependencies": {
"manifests": [
"Cargo.toml"
],
"advisories": {
"error": null,
"scope": null,
"source": null,
"findings": [],
"collected": false,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 0,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"crates"
],
"dependencies": [
{
"name": "sha2",
"manifest": "crates/allow-core/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "allow-core",
"manifest": "crates/allow-diff/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "allow-files",
"manifest": "crates/allow-diff/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "allow-policy-legacy",
"manifest": "crates/allow-diff/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "allow-policy",
"manifest": "crates/allow-diff/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "allow-rust",
"manifest": "crates/allow-diff/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "sha2",
"manifest": "crates/allow-diff/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "allow-core",
"manifest": "crates/allow-files/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "allow-core",
"manifest": "crates/allow-inventory/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "allow-core",
"manifest": "crates/allow-match/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "allow-core",
"manifest": "crates/allow-policy-legacy/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "allow-policy",
"manifest": "crates/allow-policy-legacy/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "toml",
"manifest": "crates/allow-policy-legacy/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "allow-core",
"manifest": "crates/allow-policy/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "serde",
"manifest": "crates/allow-policy/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "toml",
"manifest": "crates/allow-policy/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "allow-core",
"manifest": "crates/allow-report/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "allow-policy-legacy",
"manifest": "crates/allow-report/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "serde",
"manifest": "crates/allow-report/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "serde_json",
"manifest": "crates/allow-report/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "allow-core",
"manifest": "crates/allow-rust/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "toml",
"manifest": "crates/allow-rust/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "tree-sitter",
"manifest": "crates/allow-rust/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "tree-sitter-rust",
"manifest": "crates/allow-rust/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "allow-core",
"manifest": "crates/cargo-allow/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "allow-policy",
"manifest": "crates/cargo-allow/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "allow-inventory",
"manifest": "crates/cargo-allow/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "allow-files",
"manifest": "crates/cargo-allow/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "allow-rust",
"manifest": "crates/cargo-allow/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "allow-match",
"manifest": "crates/cargo-allow/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "allow-report",
"manifest": "crates/cargo-allow/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "allow-diff",
"manifest": "crates/cargo-allow/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "allow-policy-legacy",
"manifest": "crates/cargo-allow/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "repo-protocol",
"manifest": "crates/cargo-allow/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "repo-edit",
"manifest": "crates/cargo-allow/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "clap",
"manifest": "crates/cargo-allow/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "toml",
"manifest": "crates/cargo-allow/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "serde",
"manifest": "crates/cargo-allow/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "serde_json",
"manifest": "crates/cargo-allow/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "clap",
"manifest": "crates/cargo-intent/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "intent-engine",
"manifest": "crates/cargo-intent/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "intent-protocol",
"manifest": "crates/cargo-intent/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "repo-protocol",
"manifest": "crates/cargo-intent/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "repo-snapshot",
"manifest": "crates/cargo-intent/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "serde",
"manifest": "crates/cargo-intent/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "serde_json",
"manifest": "crates/cargo-intent/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "toml",
"manifest": "crates/cargo-intent/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "clap",
"manifest": "crates/cargo-proof/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "proof-engine",
"manifest": "crates/cargo-proof/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "proof-protocol",
"manifest": "crates/cargo-proof/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "proof-provider-api",
"manifest": "crates/cargo-proof/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "serde",
"manifest": "crates/cargo-proof/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "serde_json",
"manifest": "crates/cargo-proof/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "toml",
"manifest": "crates/cargo-proof/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "repo-edit",
"manifest": "crates/intent-edit/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "repo-protocol",
"manifest": "crates/intent-edit/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "serde",
"manifest": "crates/intent-edit/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "toml",
"manifest": "crates/intent-edit/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "serde",
"manifest": "crates/intent-engine/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "serde_json",
"manifest": "crates/intent-engine/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "toml",
"manifest": "crates/intent-engine/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "allow-core",
"manifest": "crates/intent-model/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "serde",
"manifest": "crates/intent-model/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "toml",
"manifest": "crates/intent-model/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "serde",
"manifest": "crates/intent-protocol/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "serde_json",
"manifest": "crates/intent-protocol/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "toml",
"manifest": "crates/intent-protocol/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "proof-adapter-command",
"manifest": "crates/proof-adapter-cargo-allow/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "proof-protocol",
"manifest": "crates/proof-adapter-cargo-allow/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "proof-provider-api",
"manifest": "crates/proof-adapter-cargo-allow/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "repo-protocol",
"manifest": "crates/proof-adapter-cargo-allow/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "serde",
"manifest": "crates/proof-adapter-cargo-allow/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "sha2",
"manifest": "crates/proof-adapter-cargo-allow/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "toml",
"manifest": "crates/proof-adapter-cargo-allow/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "proof-protocol",
"manifest": "crates/proof-adapter-command/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "proof-provider-api",
"manifest": "crates/proof-adapter-command/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "repo-protocol",
"manifest": "crates/proof-adapter-command/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "serde",
"manifest": "crates/proof-adapter-command/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "toml",
"manifest": "crates/proof-adapter-command/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "proof-protocol",
"manifest": "crates/proof-adapter-hawk/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "proof-provider-api",
"manifest": "crates/proof-adapter-hawk/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "repo-protocol",
"manifest": "crates/proof-adapter-hawk/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "serde",
"manifest": "crates/proof-adapter-hawk/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "toml",
"manifest": "crates/proof-adapter-hawk/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "proof-protocol",
"manifest": "crates/proof-adapter-ripr/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "proof-provider-api",
"manifest": "crates/proof-adapter-ripr/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "repo-protocol",
"manifest": "crates/proof-adapter-ripr/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "serde",
"manifest": "crates/proof-adapter-ripr/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
},
{
"name": "toml",
"manifest": "crates/proof-adapter-ripr/Cargo.toml",
"ecosystem": "crates",
"version_constraint": null
}
],
"all_dependencies": {
"error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
"source": null,
"packages": [],
"collected": false,
"truncated": false,
"total_count": null,
"direct_count": null,
"indirect_count": null
}
},
"maintainership": {
"issues": {
"open_prs": 2,
"merged_prs": 2077,
"open_issues": 405,
"closed_ratio": 0.41,
"closed_issues": 281,
"closed_unmerged_prs": 39
},
"bus_factor": 1,
"bot_contributors": 1,
"top_contributors": [
{
"type": "User",
"login": "EffortlessSteven",
"commits": 2308,
"avatar_url": "https://avatars.githubusercontent.com/u/15812269?v=4"
}
],
"contributors_sampled": 1,
"top_contributor_share": 1
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"ci.yml",
"release.yml",
"ub-review.yml"
],
"has_docs_dir": true,
"linter_configs": [],
"has_editorconfig": true,
"has_linter_config": false,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"Cargo.lock"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 3,
"reason": "branch protection is not maximal on development and all release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 10,
"reason": "22 out of 22 merged PRs checked by a CI test -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/12 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 6,
"reason": "project has 2 contributing companies or organizations -- score normalized to 6",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 0,
"reason": "project was created within the last 90 days. Please review its contents carefully",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": 10,
"reason": "packaging workflow detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 6,
"reason": "dependency not pinned by hash detected -- score normalized to 6",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 0,
"reason": "SAST tool is not run on all commits -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 10,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 10,
"reason": "0 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "3366897b078191bee344d03af2d27bf635e322fd",
"ran_at": "2026-07-25T12:18:32Z",
"aggregate_score": 5.6,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": true,
"has_dependabot_config": true
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-25T11:45:57Z",
"oldest_open_prs": [
{
"number": 2623,
"created_at": "2026-07-22T06:25:55Z",
"last_comment_at": "2026-07-22T06:58:24Z",
"last_comment_author": "chatgpt-codex-connector"
},
{
"number": 2802,
"created_at": "2026-07-25T09:40:48Z",
"last_comment_at": "2026-07-25T09:40:56Z",
"last_comment_author": "coderabbitai"
}
],
"last_merged_pr_at": "2026-07-25T11:39:32Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": [
{
"number": 1466,
"created_at": "2026-06-06T19:34:20Z",
"last_comment_at": "2026-07-23T23:55:08Z",
"last_comment_author": "EffortlessSteven"
},
{
"number": 1471,
"created_at": "2026-06-06T20:28:23Z",
"last_comment_at": "2026-07-23T23:55:09Z",
"last_comment_author": "EffortlessSteven"
},
{
"number": 1476,
"created_at": "2026-06-06T20:34:39Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 1477,
"created_at": "2026-06-06T21:39:35Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 1776,
"created_at": "2026-06-21T16:09:45Z",
"last_comment_at": "2026-07-23T23:19:14Z",
"last_comment_author": "EffortlessSteven"
},
{
"number": 1777,
"created_at": "2026-06-21T16:09:46Z",
"last_comment_at": "2026-07-23T23:39:13Z",
"last_comment_author": "EffortlessSteven"
},
{
"number": 1779,
"created_at": "2026-06-21T16:10:40Z",
"last_comment_at": "2026-07-23T23:39:39Z",
"last_comment_author": "EffortlessSteven"
},
{
"number": 1780,
"created_at": "2026-06-21T16:11:47Z",
"last_comment_at": "2026-07-23T23:16:58Z",
"last_comment_author": "EffortlessSteven"
},
{
"number": 1781,
"created_at": "2026-06-21T16:12:23Z",
"last_comment_at": "2026-07-23T23:17:25Z",
"last_comment_author": "EffortlessSteven"
},
{
"number": 1782,
"created_at": "2026-06-21T16:12:25Z",
"last_comment_at": "2026-07-23T23:16:33Z",
"last_comment_author": "EffortlessSteven"
},
{
"number": 1783,
"created_at": "2026-06-21T16:13:02Z",
"last_comment_at": "2026-07-23T23:19:42Z",
"last_comment_author": "EffortlessSteven"
},
{
"number": 1784,
"created_at": "2026-06-21T16:13:04Z",
"last_comment_at": "2026-07-23T23:40:58Z",
"last_comment_author": "EffortlessSteven"
},
{
"number": 1785,
"created_at": "2026-06-21T16:13:39Z",
"last_comment_at": "2026-07-21T03:23:39Z",
"last_comment_author": "EffortlessSteven"
},
{
"number": 1786,
"created_at": "2026-06-21T16:13:41Z",
"last_comment_at": "2026-06-21T21:20:10Z",
"last_comment_author": "EffortlessSteven"
},
{
"number": 1787,
"created_at": "2026-06-21T16:13:42Z",
"last_comment_at": "2026-06-21T21:20:26Z",
"last_comment_author": "EffortlessSteven"
},
{
"number": 1797,
"created_at": "2026-06-21T16:15:22Z",
"last_comment_at": "2026-07-23T23:16:03Z",
"last_comment_author": "EffortlessSteven"
},
{
"number": 1808,
"created_at": "2026-06-21T16:17:18Z",
"last_comment_at": "2026-07-23T23:54:37Z",
"last_comment_author": "EffortlessSteven"
},
{
"number": 1809,
"created_at": "2026-06-21T16:17:19Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 1823,
"created_at": "2026-06-21T19:50:34Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 1825,
"created_at": "2026-06-21T19:51:17Z",
"last_comment_at": null,
"last_comment_author": null
}
]
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/EffortlessMetrics/cargo-allow",
"host": "github.com",
"name": "cargo-allow",
"owner": "EffortlessMetrics"
},
"metrics": {
"overall": {
"key": "overall",
"band": "moderate",
"name": "Overall health",
"note": null,
"notes": [],
"value": 62,
"inputs": {
"security": 56,
"vitality": 76,
"community": 50,
"governance": 53,
"engineering": 74
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 76,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "moderate",
"name": "Development activity",
"note": null,
"notes": [],
"value": 60,
"inputs": {
"commits_last_year": 2295,
"human_commit_share": 0.87,
"days_since_last_push": 0,
"active_weeks_last_year": 9
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "9/52 weeks with commits",
"points": 6.2,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 9
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "2295 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 2295
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "project was created within the last 90 days. Please review its contents carefully",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 100,
"inputs": {
"releases_count": 5,
"latest_release_tag": "v0.1.11",
"releases_from_tags": false,
"days_since_latest_release": 7,
"mean_days_between_releases": 8.8
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "5 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 5
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 7 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 7
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~8.8 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 8.8
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "repository_too_young",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "moderate",
"name": "Community & Adoption",
"value": 50,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "critical",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 1,
"inputs": {
"forks": 2,
"stars": 0,
"watchers": 0,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "0 stars",
"points": 0,
"status": "missed",
"details": [
{
"code": "stars",
"params": {
"count": 0
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "2 forks",
"points": 0,
"status": "missed",
"details": [
{
"code": "forks",
"params": {
"count": 2
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "0 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 0
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "excellent",
"name": "Community health",
"note": null,
"notes": [],
"value": 92,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": true,
"has_issue_template": false,
"has_code_of_conduct": true,
"has_pull_request_template": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (Apache-2.0)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "Apache-2.0"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 18,
"status": "met",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 13.5,
"status": "met",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 6.3,
"status": "met",
"details": [],
"max_points": 6.3
}
]
},
{
"key": "ecosystem_adoption",
"band": "moderate",
"name": "Ecosystem adoption (downloads)",
"note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"registry_dependents"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 68,
"inputs": {
"packages": [
"allow-core",
"allow-diff",
"allow-rust",
"allow-files",
"allow-match",
"cargo-allow"
],
"dependents": null,
"ecosystems": "crates",
"total_downloads": 34397,
"monthly_downloads": 11465
},
"components": [
{
"key": "monthly_downloads",
"name": "Monthly downloads",
"detail": "11,465 downloads/month across crates",
"points": 54.1,
"status": "partial",
"details": [
{
"code": "downloads_monthly",
"params": {
"count": 11465,
"ecosystems": "crates"
}
}
],
"max_points": 80
},
{
"key": "registry_dependents",
"name": "Registry dependents",
"detail": "not reported by this ecosystem",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_reported_by_this_ecosystem",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "moderate",
"name": "Sustainability & Governance",
"value": 53,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 16,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 1,
"top_contributor_share": 1
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 100% of commits",
"points": 0,
"status": "missed",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 100
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "1 contributors",
"points": 1.4,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 1
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 2 contributing companies or organizations -- score normalized to 6",
"points": 6,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "moderate",
"name": "Issue & PR responsiveness",
"note": null,
"notes": [],
"value": 57,
"inputs": {
"merged_prs": 2077,
"open_issues": 405,
"closed_issues": 281,
"issue_closed_ratio": 0.41,
"closed_unmerged_prs": 39
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "41% of issues closed",
"points": 19.2,
"status": "partial",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 41
}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "2077/2116 decided PRs merged",
"points": 37.5,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 2077,
"decided": 2116
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/12 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "moderate",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 54,
"inputs": {
"followers": 7,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "EffortlessMetrics",
"public_repos": 75,
"account_age_days": 852
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "7 followers of EffortlessMetrics",
"points": 6.5,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 7,
"login": "EffortlessMetrics"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "75 public repos, account ~2 yr old",
"points": 17.7,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 75
}
},
{
"code": "account_age_years",
"params": {
"years": 2
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"allow-core",
"allow-diff",
"allow-rust",
"allow-files",
"allow-match",
"cargo-allow"
],
"ecosystems": "crates",
"any_deprecated": false,
"min_days_since_publish": 7
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "6 package(s) on crates",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 6,
"ecosystems": "crates"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 7 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 7
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "12 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 12
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "good",
"name": "Engineering Quality",
"value": 74,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "good",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 74,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": true,
"has_linter_config": false,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "3 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 3
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 6.4,
"status": "met",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "22 out of 22 merged PRs checked by a CI test -- score normalized to 10",
"points": 20,
"status": "met",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "good",
"name": "Documentation",
"note": null,
"notes": [],
"value": 75,
"inputs": {
"topics": [],
"has_wiki": true,
"homepage": null,
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "moderate",
"name": "Security",
"value": 56,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "moderate",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 56,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 17,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 1,
"scorecard_aggregate": 5.6
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection is not maximal on development and all release branches",
"points": 2.2,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "22 out of 22 merged PRs checked by a CI test -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/12 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 2 contributing companies or organizations -- score normalized to 6",
"points": 1.5,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "project was created within the last 90 days. Please review its contents carefully",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 6",
"points": 3,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is not run on all commits -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "0 existing vulnerabilities detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 2
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "good",
"name": "AI Readiness",
"value": 80,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "excellent",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 85,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 1,
"agent_instruction_files": [
"AGENTS.md"
],
"agent_instruction_max_bytes": 5031
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "AGENTS.md",
"points": 45,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "AGENTS.md"
}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "87 of 87 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 87,
"sampled": 87
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "excellent",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 85,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"Cargo.lock"
],
"has_dockerfile": false,
"typed_language": true,
"bootstrap_files": [
"justfile"
],
"has_devcontainer": false,
"has_linter_config": false,
"typecheck_configs": [],
"agent_commit_share": 0.48,
"toolchain_manifests": [
"Cargo.toml",
"crates/allow-core/Cargo.toml",
"crates/allow-diff/Cargo.toml",
"crates/allow-files/Cargo.toml",
"crates/allow-inventory/Cargo.toml",
"crates/allow-match/Cargo.toml",
"crates/allow-policy-legacy/Cargo.toml",
"crates/allow-policy/Cargo.toml",
"crates/allow-report/Cargo.toml",
"crates/allow-rust/Cargo.toml",
"crates/cargo-allow/Cargo.toml",
"crates/cargo-intent/Cargo.toml",
"crates/cargo-proof/Cargo.toml",
"crates/intent-edit/Cargo.toml",
"crates/intent-engine/Cargo.toml",
"crates/intent-model/Cargo.toml",
"crates/intent-protocol/Cargo.toml",
"crates/proof-adapter-cargo-allow/Cargo.toml",
"crates/proof-adapter-command/Cargo.toml",
"crates/proof-adapter-hawk/Cargo.toml",
"crates/proof-adapter-ripr/Cargo.toml",
"crates/proof-engine/Cargo.toml",
"crates/proof-protocol/Cargo.toml",
"crates/proof-provider-api/Cargo.toml",
"crates/repo-edit/Cargo.toml",
"crates/repo-protocol/Cargo.toml",
"crates/repo-snapshot/Cargo.toml",
"crates/rust-source-index/Cargo.toml"
],
"dependency_bot_commit_share": 0.13
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "justfile",
"points": 18,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "justfile"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "Rust (statically typed)",
"points": 11,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Rust"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "48 of the last 100 commits agent-authored or agent-credited",
"points": 10,
"status": "met",
"details": [
{
"code": "agent_authored_commits",
"params": {
"count": 48,
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "13 of the last 100 commits are automated dependency updates",
"points": 8,
"status": "met",
"details": [
{
"code": "dependency_bot_commits",
"params": {
"count": 13,
"sampled": 100
}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 6",
"points": 6,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"primary_language": "Rust",
"largest_source_bytes": 229120,
"source_files_sampled": 1010,
"oversized_source_files": 4
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Rust (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Rust"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "4/1010 source files over 60KB",
"points": 54.8,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 1010,
"oversized": 4
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "at_risk",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"example_dirs": [
"examples"
],
"has_mcp_signal": false,
"api_schema_files": []
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": "examples",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "examples"
}
}
],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"Could not fetch crates package 'cargo-proof' from its registry",
"Could not fetch crates package 'intent-edit' from its registry",
"GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
],
"report_type": "repository",
"generated_at": "2026-07-25T12:18:48.202021Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/e/EffortlessMetrics/cargo-allow.svg",
"full_name": "EffortlessMetrics/cargo-allow",
"license_state": "standard",
"license_spdx": "Apache-2.0"
}