Публічний реєстр
Звіт про здоров'я програмного забезпеченнясхема 0.27.0 · метрики 1.13.0 · 2026-07-23 19:09 UTC

Ivan-Pasco / clean-node-server

Clean Language Framework (Frame) for Node.js Server

TypeScriptЛіцензію не виявлено★ 0 зірок⑂ 0 форківз січ. 2026 р.Переглянути на GitHub ↗

Ivan-Pasco/clean-node-server має індекс здоров’я 49 зі 100, що відповідає смузі «У зоні ризику». Найвищий показник — Vitality (81/100), найнижчий — Community & Adoption (24/100). Останнє оновлення було 5 днів тому. Більшість нещодавньої роботи виконує один учасник.

49
загалом / 100
У зоні ризику

Індекс здоров'я програмного забезпечення

Метрики згруповано у зважені категорії на шкалі 1–100. Загальна оцінка починається як їхнє середнє; коли публічні дані активують Політику юрисдикцій високого ризику, рейтинг коригується й отримує верхню межу 49 («Під ризиком»). Готовність до ШІ не входить до індексу.

49
Відмінний85-100Зразковий; відповідає практично всім перевіреним критеріям
Добрий70-84Здоровий; незначні прогалини
Помірний50-69Прийнятний, але з помітними прогалинами; рекомендовано перевірку
У зоні ризику30-49Суттєві слабкі місця; впровадження потребує обережності
Критичний1-29Серйозні проблеми (покинутий, єдиний мейнтейнер, без базової гігієни)
ЖиттєздатністьСпільнота тавпровадженняСталість таврядуванняІнженернаякістьБезпекаГотовність доШІ

Профіль оцінок

Кожна вісь — окрема категорія. Форма важить більше, ніж середнє: здоровий об'єкт заповнює всю фігуру, тоді як профіль із піками та провалами означає, що сила в одному вимірі маскує ризик в іншому.

Власність

Ivan-PascoОсобистий обліковий запис
1 підписник10 публічних репозиторіївз черв. 2023 р.

Цей репозиторій належить особистому обліковому запису. Проєкт з єдиним власником несе більший ризик безперервності, ніж підтримуваний організацією.

Пакетні екосистеми

РеєстрПакетВерсіяЗавантажень / місВерсіїОстання публікаціяТеги
npm@ivan-pasco/clean-node-server0.1.974 376935 днів томуclean-languagewasmwebassemblyserverruntime

Метрики за категоріями

Життєздатність

Чи живий проєкт — чи пишеться код і чи виходять релізи?

81Добрий · 22% загального індексу
Як обчислюється оцінка
36/36Свіжість push — останній push 5 дн. тому
13.2/36Ритм комітів — 19/52 тижнів із комітами
18/18Обсяг комітів — 118 комітів за останній рік
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10
Використані вхідні дані
commits_last_year118
human_commit_share1
days_since_last_push5
active_weeks_last_year19
Як обчислюється оцінка
16.2/27Випускає релізи — 98 тегів версій (без релізів GitHub)
36/36Свіжість релізів — останній реліз 5 дн. тому
27/27Ритм релізів — реліз кожні ~0,7 дн.
0/10OpenSSF Scorecard: Signed-Releases — немає даних
Використані вхідні дані
releases_count98
latest_release_tagv0.1.97
releases_from_tagsтак
days_since_latest_release5
mean_days_between_releases0,7
Виключено з оцінювання (немає даних або не застосовно): OpenSSF Scorecard: Signed-Releases. Залишкові ваги перенормовано.

Спільнота та впровадження

Чи має проєкт користувачів, завантаження, увагу та влаштовані умови для контриб’юторів?

24Критичний · 18% загального індексу
Як обчислюється оцінка
0/60Зірки — 0 зірок
0/25Форки — 0 форків
0/15Спостерігачі — 0 спостерігачів
Використані вхідні дані
forks0
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Як обчислюється оцінка
22.5/22.5README
0/22.5Ліцензія — файлу ліцензії не виявлено
0/18Настанови CONTRIBUTING
0/13.5Кодекс поведінки
0/7.2Шаблон issue
0/6.3Шаблон PR
Використані вхідні дані
has_readmeтак
has_licenseні
has_contributingні
has_issue_templateні
has_code_of_conductні
has_pull_request_templateні
Як обчислюється оцінка
48.5/80Щомісячні завантаження — 4 376 завантажень/місяць у npm
0/20Залежні пакети в реєстрі — ця екосистема цього не повідомляє
Використані вхідні дані
packages@ivan-pasco/clean-node-server
dependents
ecosystemsnpm
total_downloads
monthly_downloads4 376
Виключено з оцінювання (немає даних або не застосовно): Залежні пакети в реєстрі. Залишкові ваги перенормовано.

Сталість та врядування

Чи переживе проєкт своїх людей — бас-фактор, реактивність, хто за ним стоїть і як супроводжуються пакети?

31У зоні ризику · 24% загального індексу
Як обчислюється оцінка
9/54Бас-фактор — на 1 контриб’ютор(ів) припадає половина всіх комітів
0/22.5Розподіл комітів — головний контриб’ютор — автор 100% комітів
1.4/13.5Широта контриб’юторів — 1 контриб’юторів
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Використані вхідні дані
bus_factor1
contributors_sampled1
top_contributor_share1
Як обчислюється оцінка
0/46.8Вирішення issue — закрито 0% issue
0/38.3Прийняття PR — немає вирішених pull request-ів або даних
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Використані вхідні дані
merged_prs0
open_issues1
closed_issues0
issue_closed_ratio0
closed_unmerged_prs0
Виключено з оцінювання (немає даних або не застосовно): Прийняття PR. Залишкові ваги перенормовано.

Власність та опіка

32У зоні ризику
Як обчислюється оцінка
10/30Підтримка власника — особистий (користувацький) обліковий запис
0/20Верифікований домен — не застосовно до користувацьких облікових записів
2.2/25Охоплення власника — 1 підписників у Ivan-Pasco
13.8/25Послужний список — 10 публічних репозиторіїв, вік облікового запису ~3 р.
Використані вхідні дані
followers1
owner_typeUser
is_verified
owner_loginIvan-Pasco
public_repos10
account_age_days1 127
Виключено з оцінювання (немає даних або не застосовно): Верифікований домен. Залишкові ваги перенормовано.

Супровід пакетів

100Відмінний
Як обчислюється оцінка
25/25Опубліковано й доступно — 1 пакет(ів) у npm
35/35Свіжість публікацій — остання публікація 5 дн. тому
20/20Історія версій — 93 опублікованих версій
20/20Не застарілий — активний, не deprecated і не yanked
Використані вхідні дані
packages@ivan-pasco/clean-node-server
ecosystemsnpm
any_deprecatedні
min_days_since_publish5

Інженерна якість

Чи наявні базові інженерні практики та документація?

66Помірний · 20% загального індексу
Як обчислюється оцінка
24/24Процеси CI — 3 процес(ів) CI
24/24Наявні тести
0/16Конфігурація лінтера
0/9.6Pre-commit-хуки
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — немає даних
Використані вхідні дані
has_ciтак
has_testsтак
has_editorconfigні
has_linter_configні
has_precommit_configні
Виключено з оцінювання (немає даних або не застосовно): OpenSSF Scorecard: CI-Tests. Залишкові ваги перенормовано.
Як обчислюється оцінка
30/30README
25/25Каталог документації
0/15Сайт документації / домашня сторінка
10/10Опис репозиторію
0/10Теми
10/10Wiki
Використані вхідні дані
topics
has_wikiтак
homepage
has_readmeтак
has_docs_dirтак
has_descriptionтак

Безпека

Чи міцні видимі практики безпеки й ланцюга постачання, без непослабленої пов’язаності з юрисдикціями високого ризику?

37У зоні ризику · 16% загального індексу

Стан безпеки

37У зоні ризику
Як обчислюється оцінка
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — немає даних
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
0/2.5Ліцензія — license file not detected
7.5/7.5Maintained — 30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
2/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 4
0/5SAST — no SAST tool detected
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — немає даних
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
3/7.5Vulnerabilities — 6 existing vulnerabilities detected
Використані вхідні дані
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate3,7
Виключено з оцінювання (немає даних або не застосовно): ci_tests, signed_releases. Залишкові ваги перенормовано.

Готовність до ШІ

Наскільки репозиторій оснащений для розробки та супроводу за участі ШІ-агентів? Незалежний, експериментальний бейдж — вага 0.0, тож він подається окремо і не впливає на загальний індекс здоров'я.

62Помірний · 0% загального індексу
Як обчислюється оцінка
45/45Інструкції для агентів — CLAUDE.md
0/15Машиночитана документація (llms.txt)
40/40Читабельна історія комітів — намір зазначено у 100 з 100 людських комітів (структурований заголовок або пояснювальний текст)
Використані вхідні дані
has_llms_txtні
legible_history_share1
agent_instruction_filesCLAUDE.md
agent_instruction_max_bytes5 920
Як обчислюється оцінка
0/18Розгортання однією командою
22/22Автоматизовані тести
0/11Конфігурація лінтера / форматера
11/11Статична перевірка типів — tsconfig.json
10/10Відтворюване середовище — lockfile
0/10Підтверджена практика роботи з агентами — серед останніх 100 комітів немає створених агентом
0/8Автоматизоване супроводження — автоматичних оновлень залежностей не виявлено
4/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 4
Використані вхідні дані
has_nixні
has_testsтак
lockfilespackage-lock.json
has_dockerfileні
typed_languageтак
bootstrap_files
has_devcontainerні
has_linter_configні
typecheck_configstsconfig.json
agent_commit_share0
toolchain_manifests
dependency_bot_commit_share0
Як обчислюється оцінка
45/45Типізований код — TypeScript (статично типізована)
55/55Керовані розміри файлів — 0/122 файлів вихідного коду понад 60 КБ
Використані вхідні дані
primary_languageTypeScript
largest_source_bytes31 875
source_files_sampled122
oversized_source_files0
Як обчислюється оцінка
0/40Схема API (OpenAPI/GraphQL/proto)
20/20Сервер MCP
0/40Придатні до запуску приклади
Використані вхідні дані
example_dirs
has_mcp_signalтак
api_schema_files

Ключові факти

0зірок GitHub
1контриб'юторів
118комітів за останні 12 місяців
5днів від останнього пушу
98релізів
1бас-фактор
1відкритих issue
npmпакетних екосистем

Попередження щодо збору даних

  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository
  • deps.dev does not index npm:@ivan-pasco/clean-node-server@0.1.97; advisories assessed against the repository dependency graph instead

Докладніше

OpenSSF Scorecard 3.7 / 10
3.7сукупно

Незалежна, не прив'язана до інструментів оцінка безпеки від відкритого проєкту OpenSSF Scorecard. Кожна перевірка винагороджує практику безпеки, а не інструмент конкретного постачальника. Перевірки, які Scorecard не зміг визначити, позначено н/д і виключено з оцінки безпеки (вони ніколи не зараховуються як нуль).Scorecard v5.5.0 · 2026-07-23 19:09 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
н/дCI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
0Licenselicense file not detected
10Maintained30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
4Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 4
0SASTno SAST tool detected
0Security-Policysecurity policy file not detected
н/дSigned-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
4Vulnerabilities6 existing vulnerabilities detected
Прямі залежності 16
РеєстрПакетОбмеження версіїМаніфест
npmbcryptjs^2.4.3package.json
npmbetter-sqlite3^11.0.0package.json
npmcommander^12.0.0package.json
npmcompression^1.8.1package.json
npmcookie-parser^1.4.6package.json
npmcors^2.8.6package.json
npmexpress^4.18.2package.json
npmexpress-rate-limit^8.4.1package.json
npmioredis^5.10.1package.json
npmjsonwebtoken^9.0.2package.json
npmmysql2^3.9.0package.json
npmnodemailer^8.0.10package.json
npmpg^8.11.3package.json
npmpino^10.3.1package.json
npmpino-http^11.0.0package.json
npmprom-client^15.1.3package.json
Усі залежності не зібрано

Не вдалося зібрати розв'язаний набір залежностей для цього звіту: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Звіт у форматі JSON машиночитний
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 597,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "Shell": 1668,
        "JavaScript": 47421,
        "TypeScript": 984795
      },
      "pushed_at": "2026-07-18T11:44:39Z",
      "created_at": "2026-01-25T01:01:30Z",
      "owner_type": "User",
      "updated_at": "2026-07-18T11:44:30Z",
      "description": "Clean Language Framework (Frame) for Node.js Server",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": null,
      "default_branch": "main",
      "license_spdx_raw": null,
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": null,
      "name": null,
      "type": "User",
      "login": "Ivan-Pasco",
      "company": null,
      "location": null,
      "followers": 1,
      "avatar_url": "https://avatars.githubusercontent.com/u/137369164?v=4",
      "created_at": "2023-06-22T03:23:49Z",
      "is_verified": null,
      "public_repos": 10,
      "account_age_days": 1127
    },
    "license": {
      "state": "absent",
      "spdx_id": null,
      "raw_spdx": null,
      "file_present": false,
      "scorecard_found": false,
      "profile_has_license": false
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.1.97",
          "kind": "patch",
          "published_at": "2026-07-18T11:44:03Z"
        },
        {
          "tag": "v0.1.96",
          "kind": "patch",
          "published_at": "2026-07-17T12:35:05Z"
        },
        {
          "tag": "v0.1.95",
          "kind": "patch",
          "published_at": "2026-07-14T22:31:56Z"
        },
        {
          "tag": "v0.1.94",
          "kind": "patch",
          "published_at": "2026-07-14T06:19:05Z"
        },
        {
          "tag": "v0.1.93",
          "kind": "patch",
          "published_at": "2026-07-13T20:07:34Z"
        },
        {
          "tag": "v0.1.92",
          "kind": "patch",
          "published_at": "2026-07-12T15:01:04Z"
        },
        {
          "tag": "v0.1.91",
          "kind": "patch",
          "published_at": "2026-07-12T14:58:38Z"
        },
        {
          "tag": "v0.1.90",
          "kind": "patch",
          "published_at": "2026-07-12T14:17:45Z"
        },
        {
          "tag": "v0.1.89",
          "kind": "patch",
          "published_at": "2026-07-12T05:43:30Z"
        },
        {
          "tag": "v0.1.88",
          "kind": "patch",
          "published_at": "2026-07-12T05:23:54Z"
        },
        {
          "tag": "v0.1.87",
          "kind": "patch",
          "published_at": "2026-07-11T16:16:43Z"
        },
        {
          "tag": "v0.1.86",
          "kind": "patch",
          "published_at": "2026-07-11T15:45:29Z"
        },
        {
          "tag": "v0.1.85",
          "kind": "patch",
          "published_at": "2026-07-09T00:26:34Z"
        },
        {
          "tag": "v0.1.84",
          "kind": "patch",
          "published_at": "2026-07-09T00:10:39Z"
        },
        {
          "tag": "v0.1.83",
          "kind": "patch",
          "published_at": "2026-07-08T20:44:52Z"
        },
        {
          "tag": "v0.1.82",
          "kind": "patch",
          "published_at": "2026-07-08T18:13:42Z"
        },
        {
          "tag": "v0.1.81",
          "kind": "patch",
          "published_at": "2026-07-08T15:34:21Z"
        },
        {
          "tag": "v0.1.80",
          "kind": "patch",
          "published_at": "2026-07-07T02:07:36Z"
        },
        {
          "tag": "v0.1.79",
          "kind": "patch",
          "published_at": "2026-07-06T14:56:23Z"
        },
        {
          "tag": "v0.1.78",
          "kind": "patch",
          "published_at": "2026-07-06T14:53:14Z"
        },
        {
          "tag": "v0.1.77",
          "kind": "patch",
          "published_at": "2026-07-06T14:41:57Z"
        },
        {
          "tag": "v0.1.76",
          "kind": "patch",
          "published_at": "2026-06-29T20:50:53Z"
        },
        {
          "tag": "v0.1.75",
          "kind": "patch",
          "published_at": "2026-06-29T20:46:41Z"
        },
        {
          "tag": "v0.1.74",
          "kind": "patch",
          "published_at": "2026-06-29T20:43:25Z"
        },
        {
          "tag": "v0.1.73",
          "kind": "patch",
          "published_at": "2026-06-26T14:46:07Z"
        },
        {
          "tag": "v0.1.72",
          "kind": "patch",
          "published_at": "2026-06-23T13:53:34Z"
        },
        {
          "tag": "v0.1.71",
          "kind": "patch",
          "published_at": "2026-06-23T06:07:01Z"
        },
        {
          "tag": "v0.1.70",
          "kind": "patch",
          "published_at": "2026-06-23T05:45:48Z"
        },
        {
          "tag": "v0.1.69",
          "kind": "patch",
          "published_at": "2026-06-22T06:11:59Z"
        },
        {
          "tag": "v0.1.68",
          "kind": "patch",
          "published_at": "2026-06-21T00:31:09Z"
        },
        {
          "tag": "v0.1.67",
          "kind": "patch",
          "published_at": "2026-06-20T14:31:35Z"
        },
        {
          "tag": "v0.1.66",
          "kind": "patch",
          "published_at": "2026-06-20T13:53:59Z"
        },
        {
          "tag": "v0.1.65",
          "kind": "patch",
          "published_at": "2026-06-20T03:23:38Z"
        },
        {
          "tag": "v0.1.64",
          "kind": "patch",
          "published_at": "2026-06-19T23:51:05Z"
        },
        {
          "tag": "v0.1.63",
          "kind": "patch",
          "published_at": "2026-06-19T19:58:29Z"
        },
        {
          "tag": "v0.1.62",
          "kind": "patch",
          "published_at": "2026-06-19T17:33:45Z"
        },
        {
          "tag": "v0.1.61",
          "kind": "patch",
          "published_at": "2026-06-19T16:08:00Z"
        },
        {
          "tag": "v0.1.60",
          "kind": "patch",
          "published_at": "2026-06-19T13:50:11Z"
        },
        {
          "tag": "v0.1.59",
          "kind": "patch",
          "published_at": "2026-06-19T12:56:24Z"
        },
        {
          "tag": "v0.1.58",
          "kind": "patch",
          "published_at": "2026-06-19T06:01:39Z"
        },
        {
          "tag": "v0.1.57",
          "kind": "patch",
          "published_at": "2026-06-19T01:57:48Z"
        },
        {
          "tag": "v0.1.56",
          "kind": "patch",
          "published_at": "2026-06-18T16:53:56Z"
        },
        {
          "tag": "v0.1.55",
          "kind": "patch",
          "published_at": "2026-06-18T03:35:59Z"
        },
        {
          "tag": "v0.1.54",
          "kind": "patch",
          "published_at": "2026-06-18T02:28:23Z"
        },
        {
          "tag": "v0.1.53",
          "kind": "patch",
          "published_at": "2026-06-18T00:49:02Z"
        },
        {
          "tag": "v0.1.52",
          "kind": "patch",
          "published_at": "2026-06-16T15:28:33Z"
        },
        {
          "tag": "v0.1.51",
          "kind": "patch",
          "published_at": "2026-06-16T15:09:51Z"
        },
        {
          "tag": "v0.1.50",
          "kind": "patch",
          "published_at": "2026-06-16T05:40:17Z"
        },
        {
          "tag": "v0.1.49",
          "kind": "patch",
          "published_at": "2026-06-16T04:24:30Z"
        },
        {
          "tag": "v0.1.48",
          "kind": "patch",
          "published_at": "2026-06-16T04:14:32Z"
        },
        {
          "tag": "v0.1.47",
          "kind": "patch",
          "published_at": "2026-06-16T02:16:28Z"
        },
        {
          "tag": "v0.1.46",
          "kind": "patch",
          "published_at": "2026-06-16T00:30:38Z"
        },
        {
          "tag": "v0.1.45",
          "kind": "patch",
          "published_at": "2026-06-13T04:00:35Z"
        },
        {
          "tag": "v0.1.44",
          "kind": "patch",
          "published_at": "2026-06-10T19:41:07Z"
        },
        {
          "tag": "v0.1.43",
          "kind": "patch",
          "published_at": "2026-06-05T13:05:19Z"
        },
        {
          "tag": "v0.1.42",
          "kind": "patch",
          "published_at": "2026-06-04T06:40:31Z"
        },
        {
          "tag": "v0.1.41",
          "kind": "patch",
          "published_at": "2026-06-03T05:13:31Z"
        },
        {
          "tag": "v0.1.40",
          "kind": "patch",
          "published_at": "2026-06-02T15:37:53Z"
        },
        {
          "tag": "v0.1.39",
          "kind": "patch",
          "published_at": "2026-06-02T04:36:46Z"
        },
        {
          "tag": "v0.1.38",
          "kind": "patch",
          "published_at": "2026-06-01T01:10:31Z"
        },
        {
          "tag": "v0.1.37",
          "kind": "patch",
          "published_at": "2026-06-01T01:08:38Z"
        },
        {
          "tag": "v0.1.36",
          "kind": "patch",
          "published_at": "2026-05-28T03:59:09Z"
        },
        {
          "tag": "v0.1.35",
          "kind": "patch",
          "published_at": "2026-05-24T02:08:07Z"
        },
        {
          "tag": "v0.1.34",
          "kind": "patch",
          "published_at": "2026-05-23T20:24:28Z"
        },
        {
          "tag": "v0.1.33",
          "kind": "patch",
          "published_at": "2026-05-22T02:00:47Z"
        },
        {
          "tag": "v0.1.32",
          "kind": "patch",
          "published_at": "2026-05-21T15:05:57Z"
        },
        {
          "tag": "v0.1.31",
          "kind": "patch",
          "published_at": "2026-05-20T21:33:14Z"
        },
        {
          "tag": "v0.1.30",
          "kind": "patch",
          "published_at": "2026-05-20T03:45:37Z"
        },
        {
          "tag": "v0.1.29",
          "kind": "patch",
          "published_at": "2026-05-19T06:05:41Z"
        },
        {
          "tag": "v0.1.28",
          "kind": "patch",
          "published_at": "2026-05-18T16:13:06Z"
        },
        {
          "tag": "v0.1.27",
          "kind": "patch",
          "published_at": "2026-05-18T16:11:29Z"
        },
        {
          "tag": "v0.1.26",
          "kind": "patch",
          "published_at": "2026-05-18T05:11:27Z"
        },
        {
          "tag": "v0.1.25",
          "kind": "patch",
          "published_at": "2026-05-18T04:32:03Z"
        },
        {
          "tag": "v0.1.24",
          "kind": "patch",
          "published_at": "2026-05-18T01:58:50Z"
        },
        {
          "tag": "v0.1.23",
          "kind": "patch",
          "published_at": "2026-05-18T01:54:39Z"
        },
        {
          "tag": "v0.1.22",
          "kind": "patch",
          "published_at": "2026-05-18T01:31:01Z"
        },
        {
          "tag": "v0.1.21",
          "kind": "patch",
          "published_at": "2026-05-18T01:08:36Z"
        },
        {
          "tag": "v0.1.20",
          "kind": "patch",
          "published_at": "2026-05-18T00:43:58Z"
        },
        {
          "tag": "v0.1.19",
          "kind": "patch",
          "published_at": "2026-05-17T23:43:38Z"
        },
        {
          "tag": "v0.1.18",
          "kind": "patch",
          "published_at": "2026-05-16T22:07:08Z"
        },
        {
          "tag": "v0.1.17",
          "kind": "patch",
          "published_at": "2026-05-16T19:58:01Z"
        },
        {
          "tag": "v0.1.16",
          "kind": "patch",
          "published_at": "2026-05-16T17:47:12Z"
        },
        {
          "tag": "v0.1.15",
          "kind": "patch",
          "published_at": "2026-05-16T15:27:11Z"
        },
        {
          "tag": "v0.1.14",
          "kind": "patch",
          "published_at": "2026-05-16T15:02:06Z"
        },
        {
          "tag": "v0.1.13",
          "kind": "patch",
          "published_at": "2026-05-16T14:56:46Z"
        },
        {
          "tag": "v0.1.12",
          "kind": "patch",
          "published_at": "2026-05-16T14:51:31Z"
        },
        {
          "tag": "v0.1.11",
          "kind": "patch",
          "published_at": "2026-05-16T14:38:54Z"
        },
        {
          "tag": "v0.1.10",
          "kind": "patch",
          "published_at": "2026-05-12T02:10:09Z"
        },
        {
          "tag": "v0.1.9",
          "kind": "patch",
          "published_at": "2026-05-03T04:25:29Z"
        },
        {
          "tag": "v0.1.8",
          "kind": "patch",
          "published_at": "2026-04-17T01:26:02Z"
        },
        {
          "tag": "v0.1.7",
          "kind": "patch",
          "published_at": "2026-04-01T06:30:32Z"
        },
        {
          "tag": "v0.1.6",
          "kind": "patch",
          "published_at": "2026-03-23T17:03:16Z"
        },
        {
          "tag": "v0.1.5",
          "kind": "patch",
          "published_at": "2026-02-14T15:05:56Z"
        },
        {
          "tag": "v0.1.4",
          "kind": "patch",
          "published_at": "2026-01-26T16:59:00Z"
        },
        {
          "tag": "v0.1.3",
          "kind": "patch",
          "published_at": "2026-01-26T14:56:08Z"
        },
        {
          "tag": "v0.1.2",
          "kind": "patch",
          "published_at": "2026-01-25T01:42:05Z"
        },
        {
          "tag": "v0.1.1",
          "kind": "patch",
          "published_at": "2026-01-25T01:16:18Z"
        },
        {
          "tag": "v0.1.0",
          "kind": "minor",
          "published_at": "2026-01-25T01:00:01Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "a4a5d694ff85b427b8dfa34d671e78ac6cbf45dd",
          "body": "…t body\n\nAdds the Option B convenience bridge requested by prompt 752c552c\n(tarball-upload integrity check). Returns lowercase-hex SHA-256 of the\npre-parse request body as an LP-string, so a handler can compare against\na client-supplied X-Tarball-SHA256 without materializing the body in\nlinear memor\n[…]\n.\n\nContract tests: 7 cases covering binary payloads (null bytes, 0xFF,\ntar.gz-shaped), the empty-body baseline, UTF-8 text fallback (including\nmulti-byte / emoji), and additivity with _req_body_bytes.",
          "is_bot": false,
          "headline": "feat(bridge): _req_body_sha256_hex — one-shot SHA-256 over raw reques…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-18T11:44:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b0553773a2ee4e6c2dd193b328bab7ed57237913",
          "body": "…utation detection\n\nInstruments repro_http_request.mjs with a heap-forensics probe requested by\nthe compiler team for bug #eed00ffee567 (STATE A truncation V2) attribution.\nTwo flags: --probe-heap enables the probe; --probe-fn <name> adds any custom\nexport (e.g. build_rows) to the wrap set.\n\nWhat it\n[…]\nring_builder_finalize get overwritten by any subsequent import\n    (bridge) call, attributing the mutation to the specific bridge.\n\nBaseline unchanged — no flag, no wrapping. Resolves prompt 41e44fdf.",
          "is_bot": false,
          "headline": "tools(repro): --probe-heap for __heap_ptr rewind + finalize-content m…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-18T11:27:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "88064cc93d8273e59ae8d617a14de75df52fcf08",
          "body": "- Move docs/functions-reference.md → spec/ (formal function reference table)\n- Delete system-documents/test-strategy.md (session debris)\n\ndocs/ retains 6 human-readable guides (getting-started, authentication,\ndatabase, files, http-client, http-server). No principal\nNode Server Specification.md yet — README.md serves as introduction.\n\nPart of monorepo-wide docs restructuring.",
          "is_bot": false,
          "headline": "docs: adopt docs/ + spec/ two-folder structure",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-18T05:28:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5480fe5dfae20dfda6c2e781d5a923bcfb21d6e6",
          "body": "Adds Layer 3 dev-mode capture bridge (`_dev_snapshot`) plus request/log\nring buffers scoped to each request worker. Gated on CLEAN_DEV=1; returns\nan empty LP string in production. Log interceptor is idempotent and no-op\nwhen the gate is closed. Full test parity with the Rust host at 36 tests\n(tests/\n[…]\n Acceptable under the\ndev-mode-is-single-user assumption; cross-worker fidelity via main-thread\nRPC is a follow-up if that assumption changes.\n\nHost-parity check (`--host node-server --strict`) clean.",
          "is_bot": false,
          "headline": "feat(bridge): _dev_snapshot — worker-local dev-mode capture ring buffers",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-17T12:35:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "da4361f2c807f5cf1544984ac3981c05995c7145",
          "body": "Implements the middle of the binary-safe triad\n  _req_body_bytes → _crypto_sha256_bytes → _fs_write_bytes\nso uploads (tarballs, images, arbitrary octets) can be hashed on the\nNode runtime without a UTF-8 decode detour.\n\n- New src/bridge/crypto-sha256-bytes.ts. Handle layout is identical to\n  _req_bo\n[…]\n)\n  payloads, gzip-like binary payloads, and output format\n  (64 lowercase hex chars).\n- Matches function-registry.toml entry _crypto_sha256_bytes shipped in\n  the compiler release preceding this one.",
          "is_bot": false,
          "headline": "feat(bridge): _crypto_sha256_bytes — binary-safe SHA-256 over LP handle",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-14T22:31:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4eea40e70cda66b6e3e7f835c3beb6413f30ea5e",
          "body": "Adds two additive bridges to un-stub the errors dashboard's tarball-upload\nendpoint on the Node runtime.\n\n_req_body_bytes: raw request body as an opaque byte sequence. Registers\nexpress.raw for application/octet-stream so binary payloads arrive as a\nBuffer instead of a UTF-8-decoded string. Returns \n[…]\ngic), the 0/1/3/4\nreturn-code taxonomy, allowlist enforcement, atomic-rename with no .tmp\nresidue, overwrite semantics, and Content-Length parity. Host parity check\nnow exits 0 for --host node-server.",
          "is_bot": false,
          "headline": "feat(bridge): binary-safe request body and atomic byte writes",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-14T06:19:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dac0372b86eadec45489638acd3d85aef939f4ac",
          "body": "…nner\n\nSingle-process runner that instantiates a compiled WASM against the real\ncompiled bridge (dist/), sets a fake RequestContext, invokes a named\nroute handler export, and prints response bytes to stdout with forensic\ncontext (result_ptr, LP-prefix length, byte/char counts) on stderr.\n\nPurpose: g\n[…]\nspatch path. Supports\n--dump-memory <off>[:<len>], --dump-hex-output, --wat-out, --json-output\nfor aliasing / truncation forensics.\n\nFirst consumer: compiler bug #eed00ffee567 (STATE A truncation V2).",
          "is_bot": false,
          "headline": "tools(repro): add repro_http_request.mjs — standalone HTTP handler ru…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-13T20:07:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9d3f2a2366182c875ad930c82817a32c6aea5776",
          "body": "…ot cause is compiler-side (CODEGEN-UNBOX-TO-I32-MISSING-STRING-TAG-CASE)\n\nPins 4 invariants at the node-server bridge boundary against the\n+320-stride pointer-shaped-integer symptom the reporter of\n#61ef80a34ec6 (BRIDGE-JSON-GET-INTEGER-RETURNS-POINTER-AGGREGATE-QUERY)\nattributed to a 'stale box sl\n[…]\nEN-UNBOX-TO-I32-MISSING-STRING-TAG-CASE (#0ccc47714523,\ncomponent=compiler). This test guards the bridge invariants so that a\nfuture regression at THIS layer surfaces separately from the compiler bug.",
          "is_bot": false,
          "headline": "test(bridge): regression pin for aggregate json.get + .toInteger — ro…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-13T04:56:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a115f34aabfa24f57aa256d57b99bffc1ac76fac",
          "body": "Adds push tag 'v*' as a trigger now that the workflow_dispatch dry run\nis green. Every tagged release must pass all open reporter-artifact\nreplays before shipping.",
          "is_bot": false,
          "headline": "ci(reporter-artifacts): enable release-tag trigger",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-13T01:36:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "259679b5a1410453e694866d3baedfd2cb8d2de3",
          "body": "Runs every open reporter-artifact issue's replay tarball against this\ncheckout's built node-server. Manual-dispatch only for initial rollout;\nrelease-tag trigger will be added after first green run.\n\nInstalls cln + this checkout's clean-node-server build globally so\ntarballs invoke the local build via PATH.",
          "is_bot": false,
          "headline": "ci: add reporter-artifacts replay workflow (closed-loop bug workflow)",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-13T01:34:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eeca6ddc09739bd1a8f46ceb145879ca56b6fb50",
          "body": "Adds .nvmrc → 20. Contributors with nvm auto-switch to Node 20 on `cd`\ninto the repo (or `nvm use`), matching CI (Node 20 in publish.yml) and\nthe >=18 requirement declared in package.json engines. Also unblocks\nthe pre-push hook on machines whose system Node predates vitest 2's\nminimum.\n\nRegenerates\n[…]\nson — the previous lockfile was written by an\nold npm and still claimed version 0.1.53. Re-locked under npm 10 on Node\n20 so `npm ci` in CI stays consistent with what a fresh install produces\nlocally.",
          "is_bot": false,
          "headline": "build: pin Node 20 via .nvmrc; refresh lockfile",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-12T15:55:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4d23e65577583b5c8511ecf9a0ee63df57259020",
          "body": "The previous injectArray helper walked the store to find the next handle\nabove the highest injected key, but that did not advance the module's\ninternal nextHandle counter. As a result, after\n  resetArrayStore()  // nextHandle = 1\n  injectArray([...])  // store[1] set, nextHandle still 1\n  bridge.arr\n[…]\nnextHandle keeps counting from 1 for\nstoreArray-minted handles, and never collides with the injected range in\nany realistic test.\n\nNo source changes — the bridge is correct; the test helper was wrong.",
          "is_bot": false,
          "headline": "test(bridge): array-bridge injectArray helper uses high handle range",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-12T15:01:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ce1ac734772cbc3e9abcc9718d1dd95037e57c4d",
          "body": "…w bridge tests\n\nAdds a comprehensive test strategy with five tiers (policy, unit, contract,\nintegration, canary) enforced by git hooks and CI:\n\n  - scripts/check-test-policy.mjs (Tier 0): blocks skipped tests without\n    a `// policy-allow-skip: <reason>` justification, placeholder markers,\n    emp\n[…]\ncomment.\n\nThe --no-verify used here is bootstrap-only: the pre-commit hook it\ninstalls cannot run against itself before it exists, and vitest 2 cannot\nboot on this machine's Node 16 (CI runs Node 20).",
          "is_bot": false,
          "headline": "test(strategy): tiered test suite with policy guard, hooks, and 12 ne…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-12T14:58:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "68743811f74659b7a40c5fb6759e91f354e6557e",
          "body": "…alues — resolves RUNTIME-INT-VALUES-ARE-POINTERS-STATS-STRIP\n\nAdds an end-to-end regression pinning the reporter's flow: repeated\ndb.query→_json_get→numeric-string leaf must yield the exact digits, not\n+320-stride pointer-shaped values. Complements the existing hand-rolled\nJSON case in tests/json-g\n[…]\npath a compiler-emitted handler takes.\n\nThe underlying fix (BRIDGE-JSON-GET-INTEGER-RETURNS-POINTER, commit\nb14f101 in v0.1.88) already addresses the root cause — this test\nprevents silent regression.",
          "is_bot": false,
          "headline": "test(bridge): pin db.query→json.get→numeric leaf against ptr-shaped v…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-12T14:17:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9f61d33def7afe06340a2fa3ad2264b74297913c",
          "body": "… resolves NODE-SERVER-UI-RENDER-PAGE-NO-SUBSTITUTION\n\nAlign _ui_render_page with HOST_BRIDGE.md line 419 spec and frame.ui plugin\nconvention (v3.2.7). Templates use { key } single-brace substitution with\nwhitespace tolerance and dotted paths; {{ and }} emit literal { and }.\n\nPrevious implementation\n[…]\n { item.field } placeholders per-iteration before the\nglobal pass. Key validity is restricted to identifier / dotted-path form,\nso CSS bodies and JSON literals containing { } are left as literal text.",
          "is_bot": false,
          "headline": "fix(bridge): _ui_render_page uses single-brace { key } substitution —…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-12T05:43:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b14f1018dc4e4d5de4cc7123e8cc0ff88df1b4ee",
          "body": "…GE-JSON-GET-INTEGER-RETURNS-POINTER\n\nCompiler 0.33.55 + frame.server 2.8.4 declared _json_get with\nparams=['any','string'], returns='any', expand_strings=false. The bridge\nkept the old 4-arg (jsonPtr,jsonLen,pathPtr,pathLen) shape and returned\na raw LP-string pointer, so the compiler's emit_unbox_a\n[…]\n Migrated the\nthree existing test files that were exercising the old 4-arg ABI to\nthe new signature — they now box the JSON input and unbox the result\nthe same way the compiler does at each call site.",
          "is_bot": false,
          "headline": "fix(bridge): _json_get switches to any-in/any-out ABI — resolves BRID…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-12T05:23:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "eaef219ad135be395e68afc724b48722b87daca7",
          "body": "…-SERVER-BRIDGE-OOB-TASKS-FILTER\n\nfoundation/platform-architecture/function-registry.toml declares mem_scope_push\nand mem_scope_pop as \"no-op currently\" for every host, and clean-server's Rust\nbridge treats them that way. This bridge previously called the WASM-side\nscope_pop export on every internal\n[…]\nrn from\nthe bug survives an internal pop. All 383 vitest tests pass; 14/15 canaries\npass (http_client canary DIFF is a separate compiler-side canary bug).\n\nFix commit for fingerprint 654ef241296a631e.",
          "is_bot": false,
          "headline": "fix(bridge): make mem_scope_pop a no-op for WASM heap — resolves NODE…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-11T16:16:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e6cb315f90d1bff73ea55e3029947d370fee5289",
          "body": "Pins the db.query + json.get + string.concat pattern reported as trapping\n\"memory access out of bounds\" on node-server 0.1.85. Cannot reproduce\nend-to-end against clean-errors/dist/errors.wasm today (20x sequential +\n10x concurrent /tasks?origin=error return HTTP 200) — likely already\nfixed by compi\n[…]\nesses:\n- Sequential _db_query responses don't overlap\n- Driver errors surface as parsable {ok:false} envelopes (not raw bytes)\n- _json_get chain preserves LP-string integrity under a healthy allocator",
          "is_bot": false,
          "headline": "test(bridge): regression harness for NODE-SERVER-BRIDGE-OOB-TASKS-FILTER",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-11T15:45:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "81bb3345ebcf752e205575403ac38a661b500916",
          "body": "_time_now now returns BigInt(unixSeconds) per foundation/platform-architecture\n/function-registry.toml — the registry declares it as `returns = \"i64\"` and\nNode's WebAssembly bindings require host functions bound to i64 result to\nreturn a BigInt. Previously node-server returned a heap pointer to a JS\n[…]\nal host runs with\n`--sandbox /tmp` for a file-heavy workload. Fixes the file canary DIFF\nwhere writes to /tmp/clean_canary_file.txt were rejected as\noutside-sandbox and the round-trip silently failed.",
          "is_bot": false,
          "headline": "fix(bridge): correct _time_now signature + canary driver sandbox root",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-09T00:26:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2224fba849fd124e0147e7d051df98b7815ec2e0",
          "body": "Implements the node-server child of the Cross-Component Contract\nCanaries umbrella (prompt 6ace888b-7a8d-11f1-9586-da25a95a496b,\numbrella 7fb425cb-79ba-11f1-9586-da25a95a496b).\n\nscripts/run_canaries.mjs discovers the compiler's canary corpus,\nfilters out browser-only namespaces, compiles each canary\n[…]\ns (env/file/http_client diffs, time trap). The time trap\n(_time_* i64/BigInt signature drift) is filed as\nNODE-SERVER-TIME-I64-BIGINT. The other three DIFFs need follow-up\ninvestigation before filing.",
          "is_bot": false,
          "headline": "feat(canaries): add Layer-2 nightly canary runner",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-09T00:10:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "680d2b32b3f55d0f4550faba5b4de80f9203091f",
          "body": "…SERVER-CGROUP-THROTTLE-WEDGE)\n\nWorker rotation was gated only on `readHeapPtr() - initialHeapPtr > 50MB`.\nscope_pop rewinds `__heap_ptr` but WASM `memory.grow()` is permanent — a\nsingle request that momentarily needed 60MB permanently extended\n`memory.buffer.byteLength`, but the rotation check saw \n[…]\n recycling.\n\nComplements the --memory-soft-limit mitigation shipped in 0.1.81: that\nprevents an unrecoverable wedge if the leak still happens, this stops the\nleak from accumulating in the first place.",
          "is_bot": false,
          "headline": "fix(pool): rotate on memory.buffer growth, not just __heap_ptr (NODE-…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-08T20:44:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "01f6ba6a544f4b23ac9ac3d925c4d705359e7861",
          "body": "Adds Cross-component prompts section to CLAUDE.md (mirrors the wording\nalready in the project-root CLAUDE.md) and allows a few read-only bash\npatterns previously prompted for.",
          "is_bot": false,
          "headline": "chore: document team-prompt skills and expand bash allowlist",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-08T18:13:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "73ff058b9b5572e983a996a72cea6881291d2a28",
          "body": "Implements FRAME-AUTH-REFRESH-TOKEN-NO-ROTATION and\nFRAME-AUTH-RESET-TOKEN-BRIDGES-MISSING per function-registry.toml:\n\n- _jwt_refresh_and_rotate: verify + atomically consume a refresh token's\n  jti and return a freshly-signed token (AUTH-J007 / AUTH-J009 single-use\n  rotation). Rejects replays, tok\n[…]\n-present in one\n  event-loop tick). Expired entries return 0 and are swept lazily.\n\nBoth stores expose reset* test helpers; 9 unit tests cover round-trip,\nreplay rejection, expiry, and invalid inputs.",
          "is_bot": false,
          "headline": "feat(bridge): add _jwt_refresh_and_rotate + _auth_reset_token bridges",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-08T18:13:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5e2a68507706c085c9bd651f59e2c9649c0a7911",
          "body": "… cgroup wedge\n\nUnder a systemd unit with MemoryMax, once RSS hits the ceiling the process gets\npinned in kernel mem_cgroup_handle_over_high (uninterruptible sleep) on the\nnext allocation. The listening socket stops responding and only SIGKILL clears\nit — Restart=always cannot rescue a D-state task \n[…]\nrprint\nf65b346bb0c4efcf02c43d4668f6f17031e7610cdb5b1e3b7c498aa70c7446f1). This is\na mitigation, not a leak fix — the underlying host-bridge scope tracking\n(part 2 of the suggested fix) is a follow-up.",
          "is_bot": false,
          "headline": "feat(cli): add --memory-soft-limit for graceful drain-and-exit before…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-08T15:34:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4d9321fe14eca537abf5897d0f7e20fa4571cfc9",
          "body": "The ws module was in devDependencies but imported at runtime, so production\ninstalls threw ERR_MODULE_NOT_FOUND from attachWebsocketServer(). Pino's err\nserializer expanded that into a multi-line requireStack trace on every process\nstart, and the rejected import promise held the request-scope closur\n[…]\nered no WS routes — avoids\n  loading ws (~1MB heap) for API-only deployments.\n\nPart of NODE-SERVER-CGROUP-THROTTLE-WEDGE (fingerprint\nf65b346bb0c4efcf02c43d4668f6f17031e7610cdb5b1e3b7c498aa70c7446f1).",
          "is_bot": false,
          "headline": "fix(bridge): make ws an optional dependency and skip attach when unused",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-08T15:33:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c3e74175b73ec723bae727a614dcc9034ca1d82e",
          "body": "…ING-READ-OOB-INTERMITTENT)\n\nreadRawString and readLengthPrefixedString now emit console.error with\nptr, len, bufferSize, a hex dump of bytes at ptr, the length reinterpreted\nas 4 little-endian ASCII chars, and a stack trace before throwing.\n\nThe intermittent case observed in production (len=1684632\n[…]\nbleed remain in place\n(scope_push/scope_pop rewind, per-request JS accumulator reset, worker\nrotation on error). This commit closes the diagnostic gap so future\noccurrences are not silent server-side.",
          "is_bot": false,
          "headline": "fix(bridge): log forensic context on OOB string read (NODE-SERVER-STR…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-07T02:07:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7b8e36c18175eca602bcc135ebf2a6a8fe9d6d77",
          "body": "The 0.1.78 workflow failed because clean-language-spec has foundation/\nas a subfolder at its root, not the root itself. Full checkout put the\nscript at $WORKSPACE/foundation/foundation/management/scripts/... but\nCLEAN_LANGUAGE_ROOT was set to $WORKSPACE, so the script wasn't found.\n\nFix: sparse-chec\n[…]\ne foundation/ subtree into a staging dir\n(_spec/), then move _spec/foundation to $WORKSPACE/foundation. This\ngives the layout the parity script expects (<root>/foundation/,\n<root>/clean-node-server/).",
          "is_bot": false,
          "headline": "ci(parity): sparse-checkout foundation subtree from clean-language-spec",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-06T14:56:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cd2413dd46ba08df9b82441e86fbdeb0698e98c4",
          "body": "Adds a 'parity' job to the publish workflow that runs\ncheck_host_parity.py --host node-server --strict on every pull request\nand tag push. The job checks out clean-language-spec as a sibling of\nthis repo and points CLEAN_LANGUAGE_ROOT at the workspace so the script\nresolves foundation/ and clean-nod\n[…]\nng no-op stubs; this closes the systemic gap).\n\nVerified locally:\n- baseline parity check: missing 0, exit 0\n- with _arena_scope_push/_pop removed: missing 2, exit 1\n- full test suite: 359/359 passing",
          "is_bot": false,
          "headline": "ci(parity): enforce host bridge parity against function-registry.toml",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-06T14:53:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a9b9224b9645259bc45b8a65dfded0c0b6b89e7f",
          "body": "…E-E001)\n\nCompiler 0.31.5+ (confirmed on 0.33.2) emits env._arena_scope_push\n(() -> i32) and env._arena_scope_pop (i32 -> void) as WASM imports on\nevery module. clean-node-server 0.1.72-0.1.76 shipped without handlers,\ncausing every fresh WASM to fail WebAssembly.instantiate with\n\"function import re\n[…]\n33.2-produced errors.wasm and\nvia a direct WebAssembly.instantiate smoke test — module now loads\nwithout LinkError. Regression test added in\ntests/arena-scope-bridges.test.ts.\n\nBumps 0.1.76 -> 0.1.77.",
          "is_bot": false,
          "headline": "fix(bridge): add _arena_scope_push/_arena_scope_pop stubs (HOST-BRIDG…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-07-06T14:41:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3bf77aa0ca21a378255b80a8d713e272d9cc1403",
          "body": "Port clean-server/src/locale.rs to TypeScript. Closes the host-parity gap\nfor the 8 _i18n_* bridge functions previously stubbed to throw at runtime.\n\nThe TypeScript LocaleState mirrors the Rust observable behavior:\n  - JSON translation maps flattened to dot-separated keys.\n  - BCP-47 fallback chain:\n[…]\n for some locales than the\nRust host. Inline matches Rust output exactly.\n\nCloses the i18n entry on Step 4 of the host-bridge-parity-enforcement\nprompt (was throw-error stub; now real implementation).",
          "is_bot": false,
          "headline": "feat(bridge): implement frame.locale (i18n) — replace throw-error stubs",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-29T20:50:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2b890e7973a00983972428fd1fe0786e15f58b32",
          "body": "Port clean-server's build-manifest reader (Plugin Contracts v2 §5/§8) to\nTypeScript. At startup the server looks for build-manifest.json next to\nthe main WASM. When present, it is the authoritative source for artifact\npaths: the client_hydration artifact (frontend.wasm) is served from the\ndeclared p\n[…]\nrser + path resolver (TS port of build_manifest.rs)\n- src/server.ts: manifest-first frontend.wasm + auto-registered artifact routes\n- tests/build-manifest.test.ts: 11 tests mirroring the Rust test set",
          "is_bot": false,
          "headline": "feat(server): read build-manifest.json for artifact resolution (SRV004)",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-29T20:46:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "657359ac56473033b00941291313537bab1e87f7",
          "body": "The frame.ui plugin removed _ui_inject_head_css entirely (theme values now\nlive in public/css/theme.css and ship via _ui_inject_head_link). Drop the\nhost implementation, the registration, and the state.injectedCss accumulator\n(types, pool, worker, test). See the\nall-remove-ui-inject-head-css-bridge \n[…]\nno longer\nlisted as MISSING (was never MISSING here — the implementation existed; the\nregistry no longer requires it). Remaining MISSING/UNKNOWN counts are\npre-existing drift unrelated to this change.",
          "is_bot": false,
          "headline": "chore(bridge): remove orphaned _ui_inject_head_css",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-29T20:43:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e37f1658efc1869cd40943fe520d3b76b37ce10f",
          "body": "… config bridges (BRIDGE_REG_002)\n\nCompiler 0.30.362+ lowers integer:64 .toString() to an env.int64_to_string\nWASM import. Without this bridge function the Node host fails to\ninstantiate any module that uses 64-bit integer toString. Bridge receives\na JS BigInt (Node's surfacing of WASM i64) and uses\n[…]\net_global_error_handler)\npaired with upstream FRAME-SERVER-CONFIG-FIELDS-UNIMPLEMENTED — signatures\nfollow that report's suggested fix and may need adjustment if the\nframework PR picks different ones.",
          "is_bot": false,
          "headline": "fix(bridge): add int64_to_string + _mcp_http_respond, scaffold server…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-26T14:46:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "52b0ce4ed998a75de1c86cc5ed5e7b8740981d07",
          "body": "…-WRAP-INCOMPLETE)\n\nscope_push/scope_pop correctly rewind the WASM bump heap per request, but\nthree bridges keep module-level Maps that grow with every allocation and\nare never reclaimed:\n\n  - bridge/list.ts: listStore (handle -> JS array)\n  - bridge/array.ts: arrayStore (handle -> JS array)\n  - bri\n[…]\nope_pop on both the success and\nerror paths. Safe because scope_pop has already reclaimed the WASM heap\nthe handles pointed into — any caller holding a stale handle is already\nholding a stale pointer.",
          "is_bot": false,
          "headline": "fix(bridge): release JS-side accumulators per request (NSR-HTTP-SCOPE…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-23T13:53:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b6d9509e968e3659e0a44e3c6d03838b6009c913",
          "body": "…ry coverage test\n\nThe compiler stopped emitting dot-notation bridge aliases in v0.30.123\n(see node-server CLAUDE.md \"Bridge Function Naming — Canonical Names Only\").\nThe ui.ts client-stub map kept 58 'ui.X': noop entries from that era,\nshadowed by their canonical _ui_* siblings two sections above. \n[…]\nng=0 unchanged; unknown dropped 209 → 159 (the\nremaining residual is real registry gaps tracked in\nfoundation/management/cross-component-prompts/all-registry-backfill-server-and-builtin-functions.md).",
          "is_bot": false,
          "headline": "chore(bridge): drop dead ui.X dot-notation registrations + fix regist…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-23T06:07:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "53c8a64b9baead0491d0e58d6883cd52975fdd1a",
          "body": "…-REQUEST-MEMORY-RELEASE)\n\nThe HTTP request path already wraps its handler in scope_push/scope_pop\n(commit efc7cc0), but three other handler-dispatch sites that share the\nsame long-lived init WASM instance kept advancing __heap_ptr forever:\n\n  - src/workers/sse-worker.ts: each SSE connection's emitt\n[…]\ntation, and add it to the three new\nsites. The wrapper is a no-op against modules compiled with\npre-0.30.330 compilers (no scope_push/scope_pop exports), matching\nthe existing request-worker fallback.",
          "is_bot": false,
          "headline": "fix(bridge): wrap SSE/cron/job handlers in per-call scope (NSR-NO-PER…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-23T05:45:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "93f995781b7c9edeca1148cd80e99a7cf2439350",
          "body": "…VER-UI-RENDER-PAGE-INTERP-STRICT-WHITESPACE)\n\nReplace the regex `/\\{([\\w.]+)\\}/g`, which only matched single-brace\n`{key}` with no internal whitespace, with a single-pass `{{ … }}`\nscanner. Matches HOST_BRIDGE.md / function-registry.toml (`{{ key }}`\nwith whitespace tolerated, missing keys → empty string) and the\nclean-server v1.9.57 sibling implementation. Single-brace `{key}` is\nintentionally no longer consumed so it stays available for the\ncl-iterate directive's item placeholders.",
          "is_bot": false,
          "headline": "fix(bridge): _ui_render_page substitutes {{ key }} per spec (NODE-SER…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-22T06:11:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "efc7cc0ae0c296a513211e4b1fecfdc870c81d7a",
          "body": "…p per request (CNS-MEM-SCOPE-POP)\n\nmem_scope_push now snapshots state.exports.scope_push(); mem_scope_pop\nhands the snapshot to state.exports.scope_pop(), rewinding __heap_ptr.\nThe request worker brackets each handler invocation (including the\nerror path) with the same primitives so __malloc alloca\n[…]\n concatLengthPrefixed — which never go\nthrough mem_alloc and so can't be reclaimed by the per-allocation refcount\npath — are released at request boundaries instead of leaking until the\nworker rotates.",
          "is_bot": false,
          "headline": "fix(bridge): consume compiler scope_push/scope_pop to rewind WASM hea…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-21T00:31:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3a9c2531c7168da3dba57a409e503d7de7af1f56",
          "body": "The 7679a9e fix (0.1.65) and b50d2e0 (0.1.66) added the defensive\n__heap_ptr bump to concatLengthPrefixed, string_split,\nwriteLengthPrefixedString, and writeRawBytes, but mem_alloc was\noverlooked. The compiler emits mem_alloc for every non-string object\n(records, list element slots, struct/class ins\n[…]\nogy used by nsr002-heap-ptr-overlap, covering\nconsecutive non-overlap, sentinel survival across interleaved string\nwrites, the 30-card prod render pattern, alignment, and the zero/negative\nsize no-op.",
          "is_bot": false,
          "headline": "fix(bridge): mem_alloc bumps __heap_ptr after every allocation (NSR002)",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-20T14:31:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b50d2e084e4bc76697da9b46e121f1a730520957",
          "body": "The compiler's __malloc uses the __heap_ptr exported global as a bump\npointer, but doesn't reliably advance it when re-entered from a host\nbridge call. By the time control returns to JS, the global is still at\nits pre-call value — so the next bridge malloc hands out an overlapping\npointer, the next \n[…]\nvery malloc (the\nexact prod pathology) and asserts that consecutive writeString,\nstring.concat, _json_get + concat (30-card render loop), and\nstring_split all survive without length-prefix corruption.",
          "is_bot": false,
          "headline": "fix(bridge): defensively bump __heap_ptr after every malloc (NSR002)",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-20T13:53:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7679a9e893a7741e386b73ae8a8820555e86edfd",
          "body": "…sion)\n\nThe 0.1.63 byte-level rewrite added an empty-input short-circuit that\nreturned one of the input pointers verbatim when the other was empty,\nas a malloc-saving optimization for the 30-card render loop. The\noptimization aliased the input into the result, which broke the\nownership invariant the\n[…]\nmutating an input buffer after concat must not change the result.\n- Updated the two short-circuit-aliasing pins that captured the 0.1.63\n  optimization to expect fresh buffers with equivalent content.",
          "is_bot": false,
          "headline": "fix(bridge): string.concat always returns fresh buffer (NSR002 regres…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-20T03:23:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e0e159d969bb7efb25d38fcba52d7b8419503b80",
          "body": "…E_STRING_SPLIT)\n\nThe compiler's `iterate part in parts` reads list size from offset 0 of\nthe returned pointer and element pointers at offset 16 + i*4. Returning a\nJSON-encoded length-prefixed string meant offset 0 held the JSON byte\nlength (e.g. 17 for `[\"a\",\"b\",\"c\",\"d\"]`), so the loop ran 17× past\n[…]\nclean-server's write_string_list_to_caller and the\nwasmtime_runner reference.\n\nUpdated bridge-abi tests to assert the list layout, including the exact\n\"a```b```c```d\" / \"```\" repro from the dashboard.",
          "is_bot": false,
          "headline": "fix(bridge): string.split returns Clean list, not LP-JSON (HOST_BRIDG…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-19T23:51:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d5e0911925ed66e4fa84a18845656aded9ecd2f8",
          "body": "The compiler emits byte-position substring inline, so iterating a string in\na `while i < s.length(): i += 1` loop over multibyte UTF-8 (em-dash E2 80 94,\narrow E2 86 92, CJK, emoji) yields a sequence of length-prefixed fragments\neach holding a single continuation byte. The previous string_concat dec\n[…]\n prod-symptom reproducer (prod WASM md5 14b8276e..., prod\nDB via SSH tunnel): /tutorials goes from 38 U+FFFD / 0 em-dashes preserved\nto 0 U+FFFD / 12 em-dashes preserved across 5 consecutive requests.",
          "is_bot": false,
          "headline": "fix(bridge): string.concat joins at byte level (NSR002)",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-19T19:58:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "45aff4ec840f396f36a0167e809b916e8a60116d",
          "body": "…NSR002)\n\nAdds two more guards on top of utf8-roundtrip:\n\n- http-utf8-wire.test.ts: stands up the real Express middleware stack\n  (compression, json, urlencoded, cookieParser, express.text) and verifies\n  res.type + res.send preserve multibyte UTF-8 on the wire across text/plain,\n  text/html, applic\n[…]\n round-trip, IPC, and Express's response pipeline. The\nproduction U+FFFD symptom isolated to none of them in unit/integration\ntesting — a regression introduced in any layer will now break loudly here.",
          "is_bot": false,
          "headline": "test(bridge): pin HTTP wire + SharedArrayBuffer IPC UTF-8 contracts (…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-19T17:33:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "49737ebcc4ce0923f238c772f7a649439315b241",
          "body": "NSR002 claimed clean-node-server corrupts multibyte UTF-8 in HTTP response\nbodies (em-dash bytes surfacing as U+FFFD chars). Investigation showed the\nhost bridge actually preserves UTF-8 across the full request flow when given\nvalid input: writeLengthPrefixedString / readLengthPrefixedString use\n`by\n[…]\nhows up in\nproduction traffic, WASM memory contained invalid UTF-8 before the bridge\nread it, so the corruption is upstream (compiler-emitted string-length\nhandling or framework http.respond wrapper).",
          "is_bot": false,
          "headline": "test(bridge): pin multibyte UTF-8 round-trip contract (NSR002 triage)",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-19T16:08:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ec1bb6f132275a1544245d1f92a68cccce2d7aab",
          "body": "RouteRegistry.match() did a strict method check, so HEAD requests against\nGET-registered routes (including /health, /metrics, and every WASM route)\nreturned 404. Load balancers and uptime probes using HEAD got false negatives.\n\nRFC 9110 §9.3.2: HEAD must be served identically to GET with the body\nsu\n[…]\nD', so the fix is localised to the registry — try the\nrequested method first, and for HEAD fall back to the GET route. Explicit\nHEAD handlers still win because the first pass runs before the fallback.",
          "is_bot": false,
          "headline": "fix(router): HEAD falls back to GET handler (HTTP-HEAD-RETURNS-404)",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-19T13:50:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "af0d898a49497948486574e978e59ca1fdede9b4",
          "body": "… failure\n\nCompiler 0.30.321 ships MALLOC-IGNORES-MEMORY-GROW-FAILURE — __malloc now\nreturns 0 (null) when memory.grow refuses to grow instead of returning a\ncorrupted pointer. The old bridge guard treated null-pointer and\nout-of-bounds-pointer as the same misleading \"WASM heap exhausted (see\nNSR002\n[…]\non message users have been seeing was\nthe symptom of the upstream allocator bug; with the compiler fix shipped\nand this bridge message updated, the user-visible failure now describes\nthe actual cause.",
          "is_bot": false,
          "headline": "fix(bridge): report null malloc clearly now that compiler honors grow…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-19T12:56:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c6141f5a60235d240eaeb7453d08a6b535c37f71",
          "body": "…lookup\n\nThe dot-path walker used `(current as Record<string, unknown>)[part]` for\nevery step, so `items.length` returned the array length, `items.push`\nreturned the function, and `items.constructor` returned `Array` — none of\nwhich should be reachable via a JSON path. Mirrors clean-server's\nhost-br\n[…]\nGNORES-MEMORY-GROW-FAILURE, #d8fba3f01151) — this commit closes a\nseparate correctness divergence from clean-server in the same bridge\nfunction. Adds tests/json-get-bridge.test.ts; 163/163 tests pass.",
          "is_bot": false,
          "headline": "fix(bridge): _json_get rejects Array.prototype keys and uses own-key …",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-19T06:01:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4b1f6e8b558edbe62564c0e34d33b9323703c86a",
          "body": "Adds a regression test that proves _http_respond writes state.response.status\nunconditionally regardless of any prior _http_set_cache / _http_no_cache call.\nThe two reports (5ac075ee, 70f95ccc) misclassified against node-server were\ncaused by frame.server's auto-wrap emitting a second _http_respond(200, ...)\nafter the helper had already set 4xx. Reclassified to framework; new bug\n276d424935c8 (FRAME-SERVER-AUTO-WRAP-CLOBBERS-STATUS) tracks the real fix.",
          "is_bot": false,
          "headline": "test(bridge): pin _http_respond status contract (RUN001/RUN002 triage)",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-19T04:40:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c78422a0ddccd3d133b3dbcccee44996a1048e61",
          "body": "…NTIME-DB-POOL-WEDGE)\n\nTransaction begin/commit/rollback used release() in finally blocks even when\nthe underlying op threw. mysql2 connections that error mid-stream still have\nunconsumed response bytes; releasing them back into the pool causes the next\nconsumer to trip PROTOCOL_PACKETS_OUT_OF_ORDER\n[…]\nequest-seq to the worker SAB so a timed-out sendAndWait no longer\n  leaves the worker free to clobber the next request's payload buffer.\n- 12 tests covering destroy-vs-release across every error path.",
          "is_bot": false,
          "headline": "fix(db): destroy mysql pool connections on error to prevent wedge (RU…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-19T01:57:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7ffadb3bfd848865aabdccc2684b83650718f082",
          "body": "…T-INSERT-ID-ZERO)\n\nThe db bridge dispatches each call against a fresh pooled MySQL connection,\nso LAST_INSERT_ID() — session-local — saw a different connection than the\nprior INSERT and returned 0. SQLite (single-connection) was not affected;\nPostgreSQL uses RETURNING and has no equivalent function\n[…]\nb_execute (sync + async paths)\n- tests: 14 new cases covering alias parsing, response shape, INSERT\n  detection, and the round-trip cache (INSERT -> SELECT -> cached id,\n  no driver hit on the SELECT)",
          "is_bot": false,
          "headline": "fix(db): cache last_insert_id across pool connections (FRAME-DATA-LAS…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-18T16:53:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f1976bf26ad05ed0207dedfd70a46f909518c1c6",
          "body": "…R-PAGE-MUSTACHE-SYNTAX-MISMATCH)\n\nThe substitution regex previously matched {{key}} (double-brace mustache),\nbut the canonical syntax — emitted by the frame.ui plugin's process_html\nexample and implemented by Rust clean-server — is {key} (single-brace).\nCompanion-page templates serving through clean-node-server were returned\nwith placeholders intact.\n\nAligns the node-server implementation with substitute_template in\nclean-server/src/bridge.rs.",
          "is_bot": false,
          "headline": "fix(bridge): _ui_render_page uses {key} single-brace syntax (UI-RENDE…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-18T03:35:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e5e1bfe422509c74773f2cb35160ef5137269471",
          "body": "…SPOND-RETURNS-ZERO-CLEARS-BODY)\n\nThe compiler-emitted route wrapper takes the _http_respond return value and\npasses it as the body pointer to a second _http_respond call. Returning 0 caused\nthe response body to be cleared. Matches Rust clean-server's\nwrite_string_to_caller(body) pattern and the registry's `returns = \"ptr\"`.",
          "is_bot": false,
          "headline": "fix(bridge): _http_respond returns body pointer instead of 0 (HTTP-RE…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-18T02:28:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0e68c9b343ab4b7fd534fdf16c25c35cf99322da",
          "body": "…n (NODE-MEM-ALLOC-SIGNATURE-MISMATCH)\n\nThe compiler emits memory_runtime.mem_alloc with signature (type_id: i32, size: i32) -> i32, but the JS bridge declared a single `size` parameter. JS silently dropped the second argument, so every WASM allocation called mem_alloc(0, N) and was read as size=0, \n[…]\nurned 0, and json.encode of any string produced the literal \"null\".\n\nBrings the Node host into line with function-registry.toml and the Rust host in clean-server/host-bridge/src/wasm_linker/memory.rs.",
          "is_bot": false,
          "headline": "fix(bridge): mem_alloc accepts (type_id, size) per compiler conventio…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-18T00:49:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dc2ca5e17ccfec28f1a1c495c82814f841d9116d",
          "body": "…pe (DB-BUILD-WHERE-IGNORES-DUNDER-WHERE)\n\nbuild_where_clause treated every JSON key as a column name, producing\n`WHERE __where = ?` with the SQL fragment bound as a parameter whenever\nthe framework's frame.data plugin emitted `{\"__where\":\"<fragment>\"}` for\nModel.paginate: / Model.cursor: where: blo\n[…]\nh\nno parameter binding; `__order` is validated against a strict charset\nand surfaced via WhereResult.orderBy so _db_paginate can splice it into\nORDER BY. Matches the protocol shared with clean-server.",
          "is_bot": false,
          "headline": "fix(bridge): honor __where/__order reserved keys in where_json envelo…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-16T15:28:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "163aa8e95667fbfc78b5afff5d7a22e7a0328521",
          "body": "…VER_MEM_LEAK)\n\nTwo leaks identified from production telemetry on a node-server process\nthat hit its cgroup MemoryHigh limit after days of uptime:\n\n1. request-worker.ts: the error path hardcoded `needsRestart: false`\n   and never incremented `requestCount`. WASM has no GC, so a partially\n   advanced\n[…]\nhestration, which is beyond unit test reach without significant\nmocking scaffolding. Existing 121-test suite still passes; production\nverification is the cgroup-limited reproduction in the bug report.",
          "is_bot": false,
          "headline": "fix(worker): rotate on error path + sequence terminate→spawn (NODESER…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-16T15:09:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c3619c4a46fb3dcf3b7b22daea88a411c4c7d3bf",
          "body": "…or stubs\n\nReplaces the throw-error stubs in three bridge modules with full\nimplementations matching clean-server (Rust) behaviour, closing the\nparity gap tracked in node-server-stub-implementations-triage.md.\n\n- schedule.ts: ported 5-field cron parser + setTimeout timer wheel.\n  startScheduler(stat\n[…]\nss-component bug\nDBWHERE_RAW_FRAGMENT against frame.data so both hosts can be fixed\ntogether rather than diverging node-server alone.\n\nFull vitest: 121/121 (84 prior + 37 new).\nHost parity: missing=0.",
          "is_bot": false,
          "headline": "feat(bridge): implement schedule/jobs/websocket — burn down throw-err…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-16T05:40:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9a7dfc82d1bd23814a16dd8fad75f8c824814a9a",
          "body": "…-drift fix\n\nFrame.server plugin.toml originally declared _server_sleep params as\n[\"i32\"], so the WASM import wired up as (i32) -> void. Node-server's\nhandler matched that with `ms: number`. Clean-framework now corrects\nplugin.toml to [\"integer\"] (committed in clean-framework as\n0e5547b@main), align\n[…]\nloop. Millisecond\nsleep durations fit safely in a JS number.\n\nCloses the PLUGIN-REGISTRY-DRIFT diagnostic fingerprint\nf952554dd54431f7 (cln dev-queue), the last drift the validator was\nstill flagging.",
          "is_bot": false,
          "headline": "fix(bridge): _server_sleep accepts bigint (i64) per registry/registry…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-16T04:24:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "489c8321d13f2067a95e2d586f0b69ac21adc52f",
          "body": "Replaces three throw-error stubs with real SQL builders that hit the\nexisting state.database.querySync path. The clean-server implementations\ndelegate to a `db_bridge.call(\"paginate\" | \"cursor_page\" | \"valid_field\")`\nabstraction that doesn't exist in node-server; these versions inline the\nSQL direct\n[…]\nng, cursor\npredicate, and has_more detection).\n\nCloses Step 8 items 1-3 in\nfoundation/management/cross-component-prompts/\n  all-host-bridge-parity-enforcement.md. Remaining: schedule, jobs,\nwebsocket.",
          "is_bot": false,
          "headline": "feat(bridge): implement _db_paginate, _db_cursor_page, _db_valid_field",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-16T04:14:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "05185ef8f1098cd4df5a39856ad6230d96e0a611",
          "body": "…RTE002)\n\nThe _http_route and _http_route_protected bridges previously took a numeric\nhandler index and node-server reconstructed __route_handler_${index} at\ndispatch time. The framework actually passes the WASM export name as a\nstring (e.g. __route_handler_get__ping) per the function-registry.toml\n\n[…]\nts callHandler,\n  bridge/test.ts) look up exports[handlerName] directly.\n- New test guards against regressing the naming reconstruction.\n\nCloses RTE002, RTE002-FRAMEWORK (×2). 73/73 vitest tests pass.",
          "is_bot": false,
          "headline": "fix(router): dispatch handlers by export name, not sequential index (…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-16T02:16:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "446286717ec35c56135906bed44197d20786f427",
          "body": "… gaps\n\nThree independent fixes uncovered while running tests:\n\n1. _test_http_request signature corrected to 10 raw (ptr, len) pairs.\n   Was using 5 length-prefixed pointers (readPrefixedString); the\n   compiler (wasmtime_runner.rs) and clean-server (bridge.rs:3347)\n   both emit/expect the 10-i32 fo\n[…]\nalidate which compiler v0.30.123+ no longer\n   emits. Required by tests/registry-coverage.test.ts (auto-alias\n   regression guard).\n\nTest suite: 72/72 passing (was 70/72 with 2 pre-existing failures).",
          "is_bot": false,
          "headline": "fix(bridge): correct _test_http_request ABI + close registry-coverage…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-16T00:30:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7b98fad9a0ffb4043bf3d244053a5420f0b85265",
          "body": "…gination\n\nCloses the remaining 26 entries in the host bridge parity check; clean\nparity now reports 0 missing on node-server.\n\nNew files (throw-error stubs — apps using these features fail with a\nclear message instead of crashing during WASM linking):\n- bridge/jobs.ts        — 12 _job_* stubs\n- bri\n[…]\n\ndb field/paginate → cursor_page → schedule → jobs → websocket.\n\nStub bodies reference clean-server/src/{jobs,websocket,locale}.rs and\nhost-bridge/src/wasm_linker/database.rs as the porting reference.",
          "is_bot": false,
          "headline": "feat(bridge): add throw-error stubs for jobs/websocket/schedule/db-pa…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-16T00:17:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "26e8f9a67f9fd715a9ae2c9337a5d23cb5dfe715",
          "body": "Closes 31 entries in the host bridge parity check against\nfoundation/platform-architecture/function-registry.toml:\n\n- storage (8): _storage_local_*, _storage_session_* — no-op stubs\n- UI helpers (12): _ui_focus, _ui_blur, _ui_get_focus, _ui_get_selection,\n  _ui_insert_at_cursor, _ui_text_diff, _ui_s\n[…]\noss-component-prompts/\n  all-host-bridge-parity-enforcement.md.\n\nRemaining 26 missing functions (jobs, websocket, db pagination,\nschedule) need real implementations and are tracked in the same prompt.",
          "is_bot": false,
          "headline": "feat(bridge): backfill missing storage/UI/build_state/i18n imports",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-15T23:27:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "46eea56e1d43bf1f1e805fa0480a044c584f8dfd",
          "body": "…g (SRV005)\n\nSame fix as clean-server: loader.js reads data-wasm from its own script element\nto locate frontend.wasm. Without it the fallback is a relative path that 404s on\nroutes deeper than /. Injecting data-wasm=\"/frontend.wasm\" (absolute) fixes hydration\non all routes.",
          "is_bot": false,
          "headline": "fix(bridge): add data-wasm absolute path to injected loader script ta…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-13T04:00:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "221b665a4179b8f9fb0d7ab509bc3ee5fd2464cb",
          "body": "Closes 6 cross-server parity bugs against clean-server (commits bb37270,\na6dc693, 88565eb, 2d19719, efb38cd, 2c43399):\n\n- NSRV-ENV-ERROR: register env.error host import with LP-format signature\n  so compiled modules that propagate runtime errors instantiate cleanly\n- NSRV-HTTP-HEADERS: add http_put/\n[…]\nV002: serve /loader.js (from ~/.cleen/plugins/frame.ui/runtime\n  with embedded stub fallback) and /frontend.wasm (sibling-of-main-WASM\n  first, then CWD / public / dist) ahead of the Express catch-all",
          "is_bot": false,
          "headline": "fix(bridge): port clean-server fixes to close NSRV-* error reports",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-10T19:41:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ae7c6cccb71fa166e10a44d44aa0217d3288c922",
          "body": "…ectives\n\nAdds _http_redirect_route bridge function (layer 3) that registers static\nredirect routes during WASM start() without generating a WASM handler function.\nMatches the signature in function-registry.toml:\n  (method_ptr, method_len, from_ptr, from_len, to_ptr, to_len, status) -> i32\n\nRouteReg\n[…]\nute\nentry. Server.handleRequest short-circuits on redirectTo routes, issuing the\nLocation header and status code directly without dispatching to the worker pool.\n\nResolves NODE-REDIRECT-ROUTE-MISSING.",
          "is_bot": false,
          "headline": "feat(bridge): implement _http_redirect_route for static redirect: dir…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-05T13:05:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dec28818611029e1dfa7441a48bc2446c3c8c92c",
          "body": "…e_body\n\nResolves SYNC-CANVAS-STUBS-MISSING: WASM modules with canvasScene: blocks\nemit imports for all 238 frame.canvas bridge functions even when running\nserver-side. Without host stubs, WebAssembly.instantiate fails with a\nLinkError. Added src/bridge/canvas-stubs.ts with no-op stubs whose\nsignatu\n[…]\n Mirrors the\nclean-server/src/bridge_canvas_stubs.rs pattern.\n\nAlso adds http_get_response_body (Layer 2 http_client), fixing the\npre-existing registry-coverage test failure.\n\nBumps version to 0.1.42.",
          "is_bot": false,
          "headline": "feat(bridge): add frame.canvas client-side stubs and http_get_respons…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-04T06:40:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7191f288c14f2140fb63bce2bd8237f03f8fd1b0",
          "body": "… _email_last_error\n\nFixes BRIDGE001, SRV-MISSING-BRIDGE, BRIDGE002 on the node server runtime.\nAll frame.server apps were failing at WASM instantiation because these four\nbridge functions declared in frame.server plugin.toml [bridge] were missing.\n\n- _res_download: sets Content-Disposition: attachm\n[…]\nfires async with\n  error captured in lastEmailError for _email_last_error to report\n- _email_last_error: returns error string from last failed send\n\nAlso removes unused camelToSnake helper from ui.ts.",
          "is_bot": false,
          "headline": "feat(bridge): implement _res_download, _email_configure, _email_send,…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-03T05:13:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1d80a5069663d40a4ef526fc430debc1ca2da75f",
          "body": "Part A (§FEXT-4): Full SSE wire-protocol implementation.\n- _http_sse_route registers STREAM routes by exported handler name\n- _sse_emit, _sse_emit_event, _sse_close, _sse_retry, _sse_is_connected\n  backed by a dedicated per-connection SSE worker thread\n- Worker posts events via parentPort; main thre\n[…]\n,3,5): Browser-only no-op stubs for server-side WASM\ninstantiation — DOM query, DOM patching, iframe communication, drag data.\nAll stubs return 0 or satisfy the linker; never called at server runtime.",
          "is_bot": false,
          "headline": "feat(bridge): implement SSE bridge and browser-only UI stubs",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-02T15:37:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8891684693f4d095b0057543adfc73fc1adba38b",
          "body": "BRIDGE001: replace 4-param string_matches with 3-param version using\ncompile-time pattern IDs (0=email, 1=url, 2=uuid, 3=phone, 4=date,\n5=integer, 6=number, 7=alphanumeric); old signature read pattern as a\nruntime WASM string causing always-false results.\n\nBRIDGE002: add src/bridge/test.ts implementing _test_http_request,\n_test_response_status, and _test_response_body — in-process endpoint\ntest dispatch using the route registry and handle-map pattern.",
          "is_bot": false,
          "headline": "fix(bridge): implement BRIDGE001 and BRIDGE002 fixes",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-02T04:36:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f8b87080203ce02deca30e76864908ddccb0fce7",
          "body": null,
          "is_bot": false,
          "headline": "feat(bridge): add mcp bridge source files missing from previous commit",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-01T01:10:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "702634c3c0c4a98728c9a3cbd50fb1bf9e476c6b",
          "body": "…_head_link\n\n_db_register_migration: update from 2-param (name only) to 6-param form\n(name, up_sql, down_sql as ptr+len pairs) to match frame.data plugin output.\nStore SQL strings alongside migration name; _db_run_migrations and\n_db_rollback_migration now execute stored SQL with WASM export fallback\n[…]\nmissing bridge function (was in function-registry\nbut not implemented in node server). Injects <link rel=stylesheet href=...>\ninto response head, deduplicated by href. Adds injectedLinks to WasmState.",
          "is_bot": false,
          "headline": "feat(bridge): fix _db_register_migration signature and add _ui_inject…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-06-01T01:08:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c4f5637c88d2e403fdf76ae11fa3fd8822a26cdd",
          "body": "…BRIDGE001)\n\nRemoved JSON.parse() branch that was re-serializing valid JSON objects\nwithout outer quotes, causing parameterized SQL queries to receive an\nembedded object instead of a string literal.",
          "is_bot": false,
          "headline": "fix(bridge): json.encode() always serializes as JSON string literal (…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-28T03:59:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aa2258d2da7efeeb6bffe3aeff1a36f426200d45",
          "body": "… (NSR001)\n\nCompiler 0.30.155+ emits these as WASM imports in every module. Both are\nno-ops for the bump-allocator runtime but must be registered to allow\nWASM instantiation to succeed.\n\n[dev-queue-skipped: SRV001, SRV002 are clean-server issues, not node-server]",
          "is_bot": false,
          "headline": "fix(bridge): add _state_reset_all and _state_reset_named host imports…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-24T02:08:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2ccac1a636dece5f7997047615b8bd1e086a8b2d",
          "body": "_ui_load_layout, _ui_load_page, and _ui_render_page previously constructed\npaths internally (app/pages/, app/layouts/), encoding frame.ui plugin\nconventions in the server layer. The first argument is now treated as a full\nrelative path from project root — path construction is the caller's\nresponsibility. Mirrors the same fix in clean-server.",
          "is_bot": false,
          "headline": "fix(bridge): UI template functions accept full relative paths (SRV001)",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-23T20:24:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6bebec5b7261b45973c5bccb3cb8b9f74f3c1a25",
          "body": "…UI_RENDER_PAGE_MISSING)\n\nframe.server plugin declares _ui_render_page as a bridge function for\nrender() and renderWith() DSL calls, but neither function was registered\nin the WASM imports object. WASM instantiation failed immediately with\n\"unknown import: env::_ui_render_page\".\n\nImplements _ui_rend\n[…]\ndata string.\nMissing keys produce an empty string. Includes path traversal protection.\n\nAlso registers _ui_load_page which was implemented in ui.ts since\nc5cd2ea but never wired into the bridge index.",
          "is_bot": false,
          "headline": "fix(bridge): add _ui_render_page and _ui_load_page host imports (SRV_…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-22T02:00:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "120cce4d46284f719e0e3a0e595b71a1e597fbde",
          "body": "Chrome 95+ and Firefox 103+ require 'wasm-unsafe-eval' in script-src to\nallow WebAssembly.compile() and WebAssembly.instantiate(). The previous\ndefault-src 'self' policy blocked all WASM loading in modern browsers.",
          "is_bot": false,
          "headline": "fix(security): add wasm-unsafe-eval to CSP script-src (CSP_BLOCKS_WASM)",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-21T15:05:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "50ea5099224d3fb3c5cbdd37155fbd669d64b75f",
          "body": "Compiler v0.30.134+ emits string_matches as a WASM import in all compiled\nmodules. Adds the implementation (sig: i32,i32,i32,i32 -> i32) to the string\nbridge and registers it in the env import object, preventing LinkError on\nWASM instantiation.",
          "is_bot": false,
          "headline": "fix(bridge): add string_matches host import (BRIDGE_MISSING_STDLIB)",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-20T21:33:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6ea369f74c2783c63a99817c7aee0041ab9bad25",
          "body": "…s (ASYNC001)\n\nResolves ASYNC001 — three async bridge functions were absent from the env\nimport object, causing WASM instantiation failures for modules that use\nbackground tasks or server sleep. Implements the same busy-wait pattern\nused by _time_sleep; _async_fire and _async_await are fire-and-forget stubs\nmatching the clean-server v1.9.11 fix.",
          "is_bot": false,
          "headline": "fix(bridge): add _async_fire, _async_await, _server_sleep host import…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-20T03:45:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3dc30aa431da766343ac05ae370a439b460a5317",
          "body": "…FEAT001)\n\nAdds _ui_load_page to createUiBridge() in src/bridge/ui.ts, resolving\napp/pages/{name}.html with the same path-traversal guard used by\n_ui_load_layout. Closes the render() parity gap between clean-server\nand clean-node-server reported as FEAT001.",
          "is_bot": false,
          "headline": "feat(bridge): add _ui_load_page bridge function for render() parity (…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-19T06:05:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c5cd2eaf404c86005c9678460240639f2f5e1b68",
          "body": "Tests encoded the old broken convention (1=equal, 0=different).\nCompiler codegen emits i32.eqz after string_compare, requiring 0=equal,\nnon-zero=different. Updated to match the corrected bridge implementation.",
          "is_bot": false,
          "headline": "test(bridge-abi): update string_compare expectations to match spec",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-18T16:13:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1160e95be43ba0c7d51ea914998fad962b730211",
          "body": "…turn convention\n\nNSR002: _http_redirect signature was (urlPtr, urlLen, permanent) but compiler\nemits (status, urlPtr, urlLen) per function-registry.toml spec. Status is now\npassed directly instead of being derived from a boolean permanent flag.\nAdded separate _res_redirect(urlPtr, urlLen, status) i\n[…]\n: string_compare was returning 1 for equal, 0 for different. Compiler\ncodegen emits i32.eqz after calling string_compare, so it expects 0=equal,\nnon-zero=different. Inverted the return value to match.",
          "is_bot": false,
          "headline": "fix(bridge): correct _http_redirect param order and string_compare re…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-18T16:11:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2a3b54da20e5ff511844bbe9648a4563efcf12b6",
          "body": "… bounds check, ui snake_case rename\n\nNSR001: sanitizeHeaderValue now strips all chars outside RFC 7230 obs-text range\n(tab, 0x20–0x7E, 0x80–0xFF), preventing U+FFFD and other Unicode chars that\nNode.js v22 rejects in HTTP headers.\n\nNSR002: writeLengthPrefixedString now validates ptr+totalSize <= bu\n[…]\nctHeadCss to _ui_load_layout/_ui_inject_head_css\nin ui.ts and index.ts to match plugin.toml [bridge] declarations — the compiler\nemits snake_case WASM imports matching the canonical plugin.toml names.",
          "is_bot": false,
          "headline": "fix(bridge): resolve NSR001/NSR002/NSR003 — header sanitization, heap…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-18T05:11:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ead96808127c2f82bbe58202db81000da2e4a878",
          "body": "…al names only\n\nThe compiler (v0.30.123) was fixed to emit only canonical _namespace_fn import\nnames. Dot-notation aliases (db.query, req.param, etc.) are no longer emitted as\nseparate WASM imports, so the auto-alias derivation loop in createBridgeImports()\nis dead code.\n\nRemove the loop. Update the\n[…]\n method imports that the compiler always emitted as dot-notation primaries\n(string.concat, math.sin, integer.toString, list.*, etc.) remain explicitly\nregistered — those are unaffected by this change.",
          "is_bot": false,
          "headline": "refactor(bridge): remove auto-alias loop — compiler now emits canonic…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-18T04:32:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8d514c1c29930e16ede1a1478863634bf0c7620a",
          "body": "_auth_hash_password and _auth_verify_password were never canonical names.\nThe registry defines _crypto_hash_password and _crypto_verify_password.\nNo backward compatibility needed in a development project with a single spec.",
          "is_bot": false,
          "headline": "refactor(bridge): remove backward-compat crypto aliases",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-18T01:58:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0d2537bc70bde52ce9ef26fc4af9806438818eec",
          "body": "…issing functions\n\nAdds a registry coverage test that reads function-registry.toml and verifies\nthe env object covers every canonical name and alias. Fixed all 43 gaps it found:\n\ncrypto.ts: renamed _auth_hash_password/_auth_verify_password to canonical\n_crypto_hash_password/_crypto_verify_password; \n[…]\nrd and\n_auth_verify_password pointing to renamed canonical functions.\n\ntests/registry-coverage.test.ts: parses module field to skip memory_runtime\nentries; checks every env-module canonical and alias.",
          "is_bot": false,
          "headline": "fix(bridge): full registry coverage — canonical names, aliases, and m…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-18T01:54:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f75809490b8a9747d9acc04717c0fae14115d6a9",
          "body": "…nent prompt format\n\nAdds a \"Bridge Function Naming\" section to CLAUDE.md explaining the dual\n_namespace_fn / namespace.fn registration requirement and pointing to\nHOST_BRIDGE.md for the full spec. Updates the cross-component prompt\nformat reference to point at the README instead of embedding a stale\ninline template.",
          "is_bot": false,
          "headline": "docs(bridge): document dual-naming requirement and update cross-compo…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-18T01:31:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0b67de00959a697cdb496771234fedce3f48c750",
          "body": "…efixed bridge functions\n\nThe compiler emits WASM imports in both _namespace_fn and namespace.fn\nstyles for all bridge namespaces. The env object only registered underscore\nnames, causing LinkError on db.query, req.param, http.respond, etc.\n\nRefactors createBridgeImports() to build env as a named va\n[…]\nnt. Keys starting with __ (e.g. __stack_pointer) are skipped.\n\nCovers all namespaces: db, req, http, json, html, ui, session, auth,\ncrypto, file, and any future additions automatically.\n\nFixes NSR004.",
          "is_bot": false,
          "headline": "fix(bridge): auto-generate dot-notation aliases for all underscore-pr…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-18T01:08:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b2da585eae44180331fa671d59cf934d5f65b0cb",
          "body": "The compiler generates both camelCase and snake_case dot-notation imports\nfor every frame.ui bridge function. The previous partial fix added camelCase\nstubs but left 29 snake_case variants uncovered, causing a LinkError on\nui.set_state (and others) at WASM instantiation.\n\nAdds camelToSnake() and a p\n[…]\n-build loop in createUiClientStubs() that\nderives snake_case aliases from all camelCase ui.* entries automatically.\nFuture bridge function additions stay in sync without manual listing.\n\nFixes NSR003.",
          "is_bot": false,
          "headline": "fix(bridge): auto-generate snake_case aliases for all ui.* client stubs",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-18T00:43:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8908755e96fa8dba0499246da21e9b075b496450",
          "body": "…ry pre-grow, ui client stubs\n\nNSR003: frame.ui 2.6.9 registers client-side bridge functions as WASM imports in\nserver builds. Add no-op stubs for all ui.* functions in createUiClientStubs()\nand spread them into the linker env — satisfies the linker without runtime overhead.\n\nNSR001: http.redirect()\n[…]\nffset is outside the\nbounds of the DataView\". Add preGrowMemory() (16 MB default) called at startup in\nboth server.ts and request-worker.ts so memory.grow() is never triggered during\nrequest handling.",
          "is_bot": false,
          "headline": "fix(bridge): resolve NSR001/NSR002/NSR003 — header sanitization, memo…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-17T23:43:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "290f9ffb80976996590a1a1dbdd6ef509854df07",
          "body": "…ring_split to LP-pointer ABI\n\nWASM calls these functions with one i32 LP-pointer per string argument\n(pointing to [4-byte LE length][UTF-8 content]). The previous (ptr, len,\nptr, len) signature misread the second LP-pointer as a length value, causing\nexponential memory growth and offset-out-of-boun\n[…]\nted call site expectation.\n\nAdds bridge-abi.test.ts with 12 ABI contract tests covering LP-pointer and\nraw ptr+len conventions across all four affected functions.\n\nFixes: NODE-STRING-BRIDGE-CONVENTION",
          "is_bot": false,
          "headline": "fix(bridge): switch string.concat, string_compare, string_replace, st…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-16T22:07:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "62c2349a6d0abe2646706f92bae323de4a4eb704",
          "body": "…mer into shutdown\n\nNODE-DB-BRIDGE-OOB: writeLengthPrefixedString, readLengthPrefixedString, and\nreadRawString each called memory.buffer multiple times. When WASM malloc causes\na memory.grow(), the old ArrayBuffer is detached and replaced. All reads and\nwrites now snapshot the buffer once after mall\n[…]\nver.start(), so it fired unconditionally 35 seconds\nafter startup regardless of whether shutdown was in progress. Moved into\nthe shutdown() handler so the watchdog only runs when a signal is received.",
          "is_bot": false,
          "headline": "fix(bridge): snap memory buffer once after malloc, move force-exit ti…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-16T19:58:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "22a2684ca2c1b3fd3f87750e98bd5ec5b8525b03",
          "body": "The compiler exports handlers as __route_handler_0, __route_handler_1, ...\nin registration order. The WASM table index passed to _http_route is an\ninternal offset unrelated to the export naming scheme.\n\nRouteRegistry now maintains a sequential counter and stores it as the\nhandlerIndex, replacing the raw WASM table offset. Dispatch uses\n__route_handler_${handlerIndex} with the counter-based index.\n\nFixes NODE-HANDLER-DISPATCH-V2.",
          "is_bot": false,
          "headline": "fix(bridge): dispatch route handlers via sequential registration counter",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-16T17:47:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3ebefc8d27eec7b579279fc30f4f78d942335442",
          "body": "…ort names\n\nThe compiler emits handler indices as function table offsets, not named\nexports. Constructing __route_handler_<N> / __handler_<N> export names\nnever matched anything in the WASM module.\n\nBoth callHandler() and request-worker.ts now use\n__indirect_function_table.get(handlerIndex) — the same pattern already\nused by the array bridge for callbacks.\n\nFixes NODE-HANDLER-DISPATCH.",
          "is_bot": false,
          "headline": "fix(bridge): dispatch route handlers via WASM function table, not exp…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-16T15:27:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f696b4a102e1be2346e247a9437cc9de9b66eb85",
          "body": "…pected\n\nstart() resolved the port as: port || getConfiguredPort() || this.config.port\ngetConfiguredPort() always returned truthy 3000 (its module-level default),\nso this.config.port (the parsed --port value) was never reached.\n\nPassing config.port explicitly makes the CLI flag win unconditionally.\n\nFixes NODE-PORT-FLAG-IGNORED.",
          "is_bot": false,
          "headline": "fix(server): pass config.port to server.start() so --port flag is res…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-16T15:02:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3352fb8fd439ba8a4d75654a3e5c8e16f873a1de",
          "body": "…e.js v22\n\nObject.create alone is insufficient: JS [[Set]] walks the prototype chain\nand throws TypeError when the prototype property is non-writable, even on\nthe shadow object. Object.defineProperty creates an OWN property directly,\nbypassing the prototype chain check entirely.\n\nFixes NODE-WASM-MALLOC-READONLY (complete fix, supersedes v0.1.12).",
          "is_bot": false,
          "headline": "fix(wasm): use Object.defineProperty to install malloc wrapper on Nod…",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-16T14:56:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0a89695e9c12d639be722d1b6446d1fa4d432375",
          "body": "Node.js v22 (V8) enforces that WebAssembly.Instance.exports properties\nare non-writable per spec. wrapMalloc() was assigning directly to\nexports.malloc, throwing TypeError on v22+.\n\nFixes NODE-WASM-MALLOC-READONLY by using Object.create(instance.exports)\nto create a shadow object — the wrapper becomes an own property while\nall other WASM exports remain accessible via the prototype chain.",
          "is_bot": false,
          "headline": "fix(wasm): shadow WASM exports to allow malloc wrapping on Node.js v22",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-16T14:51:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2eee5bf7c6bc5be1d59eee48bd5949a146500faa",
          "body": null,
          "is_bot": false,
          "headline": "chore(settings): update allowed commands",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-16T14:39:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "859f850340226d98e0746a3d01b5e9ff6afa51f6",
          "body": "Implements SyncMysqlDriver using the same SharedArrayBuffer + Atomics\npattern as SyncPostgresDriver, with a mysql-worker thread handling async\nmysql2 operations. Adds mysql/mysql2 protocol cases to createDatabaseDriver.\n\nFixes FEATURE-NODE-MYSQL reported against 0.30.110.",
          "is_bot": false,
          "headline": "feat(database): add MySQL driver via worker-thread sync bridge",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-16T14:38:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e7cdc68081e67671d497762fad26d4f9727ad62d",
          "body": "Register _html_escape, _html_raw, print_string, console_input, and\nall 29 math dot-notation aliases (math.sin, math.cos, etc.) that\nwere in the HOST_BRIDGE spec but not wired into the env import object.",
          "is_bot": false,
          "headline": "feat(bridge): add missing HOST_BRIDGE functions per spec",
          "author_name": "Ivan",
          "author_login": "Ivan-Pasco",
          "committed_at": "2026-05-12T02:10:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 98,
      "commits_last_year": 118,
      "latest_release_at": "2026-07-18T11:44:03Z",
      "latest_release_tag": "v0.1.97",
      "releases_from_tags": true,
      "days_since_last_push": 5,
      "active_weeks_last_year": 19,
      "days_since_latest_release": 5,
      "mean_days_between_releases": 0.7
    },
    "community": {
      "has_readme": true,
      "has_license": false,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 28,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "@ivan-pasco/clean-node-server",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "clean-language",
            "wasm",
            "webassembly",
            "server",
            "runtime"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@ivan-pasco/clean-node-server",
          "is_deprecated": false,
          "latest_version": "0.1.97",
          "repository_url": "https://github.com/Ivan-Pasco/clean-node-server",
          "versions_count": 93,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 4376,
          "first_published_at": "2026-01-25T02:57:33.837000Z",
          "latest_published_at": "2026-07-18T11:45:36.434000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0,
        "collected_at": null
      },
      "open_issues_and_prs": 1
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": true,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 31875,
      "source_files_sampled": 122,
      "oversized_source_files": 0,
      "agent_instruction_files": [
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 5920
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "bcryptjs",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.4.3"
        },
        {
          "name": "better-sqlite3",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^11.0.0"
        },
        {
          "name": "commander",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^12.0.0"
        },
        {
          "name": "compression",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.8.1"
        },
        {
          "name": "cookie-parser",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.4.6"
        },
        {
          "name": "cors",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.8.6"
        },
        {
          "name": "express",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.18.2"
        },
        {
          "name": "express-rate-limit",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^8.4.1"
        },
        {
          "name": "ioredis",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.10.1"
        },
        {
          "name": "jsonwebtoken",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^9.0.2"
        },
        {
          "name": "mysql2",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.9.0"
        },
        {
          "name": "nodemailer",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^8.0.10"
        },
        {
          "name": "pg",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^8.11.3"
        },
        {
          "name": "pino",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^10.3.1"
        },
        {
          "name": "pino-http",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^11.0.0"
        },
        {
          "name": "prom-client",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^15.1.3"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 0,
        "open_issues": 1,
        "closed_ratio": 0,
        "closed_issues": 0,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "Ivan-Pasco",
          "commits": 118,
          "avatar_url": "https://avatars.githubusercontent.com/u/137369164?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "nightly-canaries.yml",
        "publish.yml",
        "reporter-artifacts.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 0,
            "reason": "license file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 4,
            "reason": "dependency not pinned by hash detected -- score normalized to 4",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 4,
            "reason": "6 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "a4a5d694ff85b427b8dfa34d671e78ac6cbf45dd",
        "ran_at": "2026-07-23T19:09:07Z",
        "aggregate_score": 3.7,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-23T08:46:10Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": null,
      "ci_last_conclusion": "FAILURE",
      "oldest_open_issues": [
        {
          "number": 1,
          "created_at": "2026-07-13T04:02:03Z",
          "last_comment_at": "2026-07-18T11:45:37Z",
          "last_comment_author": "github-actions"
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/Ivan-Pasco/clean-node-server",
    "host": "github.com",
    "name": "clean-node-server",
    "owner": "Ivan-Pasco"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "at_risk",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 49,
      "inputs": {
        "security": 37,
        "vitality": 81,
        "community": 24,
        "governance": 31,
        "engineering": 66
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 81,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 77,
            "inputs": {
              "commits_last_year": 118,
              "human_commit_share": 1,
              "days_since_last_push": 5,
              "active_weeks_last_year": 19
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "19/52 weeks with commits",
                "points": 13.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 19
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "118 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 118
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 88,
            "inputs": {
              "releases_count": 98,
              "latest_release_tag": "v0.1.97",
              "releases_from_tags": true,
              "days_since_latest_release": 5,
              "mean_days_between_releases": 0.7
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "98 version tags (no GitHub releases)",
                "points": 16.2,
                "status": "partial",
                "details": [
                  {
                    "code": "version_tags_no_releases",
                    "params": {
                      "count": 98
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~0.7 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 0.7
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 24,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "critical",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 25,
            "inputs": {
              "has_readme": true,
              "has_license": false,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "no license file detected",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "license_absent",
                    "params": {}
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 61,
            "inputs": {
              "packages": [
                "@ivan-pasco/clean-node-server"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 4376
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "4,376 downloads/month across npm",
                "points": 48.5,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 4376,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 31,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "critical",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "merged_prs": 0,
              "open_issues": 1,
              "closed_issues": 0,
              "issue_closed_ratio": 0,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "0% of issues closed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 0
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "no decided pull requests or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_decided_prs_or_data",
                    "params": {}
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 32,
            "inputs": {
              "followers": 1,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "Ivan-Pasco",
              "public_repos": 10,
              "account_age_days": 1127
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "1 followers of Ivan-Pasco",
                "points": 2.2,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 1,
                      "login": "Ivan-Pasco"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "10 public repos, account ~3 yr old",
                "points": 13.8,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 10
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 3
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "@ivan-pasco/clean-node-server"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 5
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 5 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "93 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 93
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 66,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 60,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "3 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 37,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 37,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 3.7
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 4",
                "points": 2,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "6 existing vulnerabilities detected",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 62,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 5920
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "100 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 100,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "at_risk",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 47,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "package-lock.json"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "tsconfig.json"
              ],
              "agent_commit_share": 0,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 4",
                "points": 4,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 31875,
              "source_files_sampled": 122,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/122 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 122,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "critical",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 20,
            "inputs": {
              "example_dirs": [],
              "has_mcp_signal": true,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
    "deps.dev does not index npm:@ivan-pasco/clean-node-server@0.1.97; advisories assessed against the repository dependency graph instead"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-23T19:09:13.595025Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/i/Ivan-Pasco/clean-node-server.svg",
  "full_name": "Ivan-Pasco/clean-node-server",
  "license_state": "absent",
  "license_spdx": null
}

Оцінки — це сигнали, а не гарантії. Вони відображають публічно видимі практики на GitHub — це не аудит коду й не гарантія безпеки.

Відсутні дані виключаються, а ваги перенормовуються — нуль за відсутність ніколи не ставиться. Методологія версіонована й відкрита: метрики v1.13.0, схема v0.27.0 — повна методологія · вікі метрик.

Як окремий результат виглядає на тлі всього реєстру: сукупна статистикаnpm.