Звіт у форматі JSON машиночитний
{
"data": {
"repo": {
"topics": [],
"is_fork": false,
"size_kb": 80378,
"has_wiki": false,
"homepage": null,
"languages": {
"JavaScript": 54471,
"TypeScript": 3273861
},
"pushed_at": "2026-07-17T15:04:06Z",
"created_at": "2026-04-05T23:05:32Z",
"owner_type": "User",
"updated_at": "2026-07-17T15:05:31Z",
"description": "Web research for pi with smart and safe tooling + agent system",
"is_archived": false,
"is_disabled": false,
"license_spdx": "MIT",
"default_branch": "main",
"license_spdx_raw": "MIT",
"primary_language": "TypeScript",
"significant_languages": [
"TypeScript"
]
},
"owner": {
"blog": null,
"name": "Lincoln",
"type": "User",
"login": "Lincoln504",
"company": null,
"location": null,
"followers": 1,
"avatar_url": "https://avatars.githubusercontent.com/u/56658553?v=4",
"created_at": "2019-10-16T22:41:49Z",
"is_verified": null,
"public_repos": 2,
"account_age_days": 2470
},
"license": {
"state": "standard",
"spdx_id": "MIT",
"raw_spdx": "MIT",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v1.0.8",
"kind": "patch",
"published_at": "2026-07-17T15:04:12Z"
}
],
"recent_commits": [
{
"oid": "873f305df196e6506600fd2443a9452435c86c86",
"body": null,
"is_bot": false,
"headline": "Merge branch 'main' of https://github.com/Lincoln504/pi-research",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-17T15:03:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7b1750764f49a23664db0abb7505c16af743e561",
"body": "- Add comprehensive CHANGELOG.md documenting all versions from 0.1.13 through 1.0.7\n- Include CHANGELOG.md in published package (docs/CHANGELOG.md)\n- Add 'Maximum 4 simultaneous calls' constraint to research-tool-usage prompt\n- Emphasize topic consolidation to fit 4-call maximum",
"is_bot": false,
"headline": "chore(release): v1.0.8",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-17T15:03:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "00dba47d1ce9ad01236a94c68cb982fbc37acbe2",
"body": null,
"is_bot": true,
"headline": "chore(ci): regenerate docs/deps.svg (detailed module graph) [skip ci]",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-07-17T14:55:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3559040d648cd7cf514b15cf2a22a457ddcbffc3",
"body": "…olidation constraint\n\n- Add comprehensive CHANGELOG.md documenting all versions from 0.1.13 through 1.0.7\n- Include CHANGELOG.md in published package (docs/CHANGELOG.md)\n- Add 'Maximum 4 simultaneous calls' constraint to research-tool-usage prompt\n- Emphasize topic consolidation to fit 4-call maximum",
"is_bot": false,
"headline": "docs: add CHANGELOG to docs/, include in package, and add 4-call cons…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-17T14:54:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "18b43cd1c104346379a87cf86e91196e486f1c95",
"body": null,
"is_bot": false,
"headline": "chore(release): v1.0.7",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-14T21:39:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b36a55065be090102f9c9cd07bab3f9513d8d311",
"body": "…xit-code misclassification, unsurfaced quality signals, SIGINT cancellation, citation-provenance gaps\n\nFindings from a live-log-verified reliability analysis\n(ISSUES-ANALYSIS-2026-07-09.md) plus a follow-up regression sweep, each\nverified in source and covered by new/updated tests:\n\n- Browser sched\n[…]\ny renderers,\n cache-friendly dynamic tool loading) — none required for this release.\n\nFull verification: type-check, lint, and the full test suite (133 files /\n1938 tests) all green; npm audit clean.",
"is_bot": false,
"headline": "fix: browser-pool leader-election race, researcher retry-exemption, e…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-14T21:38:20Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e73f8eb78b10fd5b4f0eb939265eb46f8857ad94",
"body": "…searcher tools)\n\nExpand the Research tools section into a Tool inventory covering both\nsurfaces: the three pi-registered tools (research,\nresearch_knowledge_search, health) and the seven researcher-agent\ntools, with the gathering-budget scope stated precisely (search /\nsecurity_search / stackexchange / youtube_transcript share\nMAX_GATHERING_CALLS; scrape and grep have their own budgets) and a\ncross-reference to PI_RESEARCH_DISABLED_TOOLS.",
"is_bot": false,
"headline": "docs(architecture): single canonical tool inventory (host-facing + re…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-04T21:19:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1464a96f0f67f4392adbb971ca4401cd4a4c3cd3",
"body": "…6 audit\n\nComment-only: note the missing release concurrency group and the\ntag-pinned (non-SHA-pinned) actions in both workflows. No behavior\nchange.",
"is_bot": false,
"headline": "docs(ci): record deferred low-severity hardening TODOs from post-1.0.…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-04T20:11:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7752bb15d30f70f0ce97f49f471aa7ad0cf50439",
"body": null,
"is_bot": false,
"headline": "chore(release): v1.0.6",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-04T19:34:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "693fbe4961621817e90ad54834eab15eaf406082",
"body": "…ribution\n\nThe agent skill can pass --depth 0 (only the pi extension tool and TUI\nare floor-limited to 1); and migration.ts holds only the strategy types —\nthe drop/backup/re-embed logic lives in store.ts.",
"is_bot": false,
"headline": "docs(architecture): correct depth-0 availability and migration.ts att…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-04T19:13:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "945336e84eae5030be1e83258b465915e41cf995",
"body": "…ctly\n\nA Proxy get trap may not substitute a wrapper for a non-writable\nnon-configurable own data property, so a frozen observer (a common\ndefensive pattern for SDK callback bags) made the engine throw TypeError\nat the property access itself — outside every guard, failing the run the\nwrapper exists \n[…]\no protect. Proxy a fresh empty target and close over the\nobserver instead: no own properties, no invariant can bind the trap.\nhas/getPrototypeOf forward so `in` checks and instanceof stay transparent.",
"is_bot": false,
"headline": "fix(orchestration): makeSafeObserver must not proxy the observer dire…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-04T19:13:47Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d36ab4fa5e1ffdc455f528515674a266e83b01d5",
"body": null,
"is_bot": false,
"headline": "chore(release): v1.0.5",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-04T15:47:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0961d804af8e508a4b7796d2e0a111770bbb6ac7",
"body": "…r transcribed links\n\nFinal adversarial-review pass on the v1.0.5 diff:\n- the two Content-Length pre-screen throws in scrapeWithFetch were the one\n remaining unconsumed-body path in the function — and they fire on the\n largest responses; cancel the body first (same class as the redirect/!ok\n drains)\n- registerTranscribedLinks now refreshes the session's last-activity\n timestamp, matching every sibling register function's TTL contract",
"is_bot": false,
"headline": "fix: drain bodies on Content-Length pre-screen throws; TTL refresh fo…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-04T15:46:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b16027e4445ef6d37bea0c7770e845624d027262",
"body": "…links\n\nLog-verified failure (Jul 4 run): a researcher grounded its report in a\nvideo transcript but cited it title-only; parseCitations extracts URLs, so\nthe citation was unparseable and the synthesis fallback rebuilt sources\nfrom the link pool — relabeling the transcript's watch URL '[Source:\nScra\n[…]\nllback labels those 'YouTube Transcript'\n- researcher prompt: do not scrape YouTube video links (app shell only) —\n read them with youtube_transcript; channel/playlist discovery scrapes\n remain fine",
"is_bot": false,
"headline": "fix(youtube): keep transcript provenance in the final report's cited …",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-04T15:38:26Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cba58626918612df4316ca4d86635867224351c6",
"body": "… --model preflight, streaming caps, socket drains, observer isolation\n\n- knowledge store: a failed 'backup' migration now aborts (old model kept,\n next open retries) instead of escalating to a data-destroying 'drop';\n countRows before backup is best-effort\n- deep orchestrator: a run with zero col\n[…]\ns+call guarded)\n so throwing/rejecting SDK or TUI observer callbacks can never fail a run\n- SSRF comments corrected (WHATWG URL normalization covers numeric IP\n encodings; pinned by regression test)",
"is_bot": false,
"headline": "fix: adversarial-review hardening — migration abort, hollow-run gate,…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-04T15:34:36Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "83ea4568dec9e9f3f653a9196f88b69456ab8175",
"body": "…correct error classification and minimal-model api ids\n\nFindings from an adversarial review, each verified in source:\n\n- A run that collects ZERO researcher reports now THROWS with the recorded\n root causes instead of returning 'Research completed but no summary was\n generated.' on the success pa\n[…]\nsts: orchestrator zero-report rejection (asserts the 429 cause text),\nSDK model-pin, provider-mismatch not-ready, and a new factory suite pinning\nthe api-id map against pi-ai's literal KnownApi union.",
"is_bot": false,
"headline": "fix: fail loud on zero-report runs; single-model runs under --model; …",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-04T13:57:40Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "827d116b6da66c6ccb05461f51a04d904879aa74",
"body": null,
"is_bot": false,
"headline": "release: v1.0.4 — content-based pi credential detection",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-04T13:36:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "25532d1517e5a56d47af23d2e0a78e982043600c",
"body": "…ence; registry no longer gated on auth.json\n\nTwo related defects around 'auth.json exists' being used as a proxy for\n'keys available':\n\n- model-registry-factory: with no explicit key, the registry was built from\n pi's configuration ONLY when auth.json existed — a models.json-only setup\n (per-prov\n[…]\ns.json-only keys (credentials → pi-config, ready) with\nprovider env keys stripped from the child env, since pi honors those too;\nthe existing model-required fixture now writes a real credential entry.",
"is_bot": false,
"headline": "fix(credentials): detect pi keys by pi's own semantics, not file pres…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-04T13:36:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "04792f8319b1a54ddf08c8219b576fe13c8814ba",
"body": "Replace 'pi auth (storage)' phrasing everywhere with pi's configuration,\nkeeping the literal file paths: the key comes from ~/.pi/agent/auth.json\nand custom models from ~/.pi/agent/models.json — both verified against\npi-coding-agent's own AuthStorage/ModelRegistry defaults. Printout labels\nare now uniform: 'pi config (keys)' / 'pi config (models)' in configBlock,\nthe CLI help (realigned), the launcher's guidance, and SKILL.md.",
"is_bot": false,
"headline": "docs,cli: pi has configuration files, not a named 'auth' feature",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-04T12:59:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d923f2ef217992fa440dcdd747d6d3a2473276a8",
"body": "The sentence after the pi-extension install told extension users to\nconfigure a model and key — the extension needs neither (session model +\npi auth). Now stated per mode: extension works out of the box; standalone\nrequires PI_RESEARCH_MODEL, plus the API key only without pi. Drop the\n'(all optional)' qualifier from the CONFIGURATION API-keys heading — the\nLLM key is conditionally required and each row states its own condition.",
"is_bot": false,
"headline": "docs: mode-accurate install config note in the README",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-04T12:49:16Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3587ea269c334681144e616708e9e34278179552",
"body": "Verified end-to-end: the CLI credential bridge promotes PI_RESEARCH_API_KEY\n(and PROVIDER) from config.env/cli.env, with the provider inferred from a\nprovider/model-id PI_RESEARCH_MODEL. Worded per mode: the programmatic SDK\ntakes the apiKey option / env var / pi auth (no file bridge there).",
"is_bot": false,
"headline": "docs: note the API key can live in config.env for the CLI/skill",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-04T12:46:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "af9daa0f61ab7adec97f7dab62a7636fc8eec2c4",
"body": "Document the model requirement once, clearly, in each obvious place: the\nAGENT-SKILL install section (including the pi-extension shortcut, which\nnow says the model step still applies), SDK.md install + options table,\nthe CONFIGURATION.md PI_RESEARCH_MODEL row, the skill's SKILL.md\nconfig block and b\n[…]\nites, and\nthe .env.example comment. All state the same fact: the standalone\nCLI / agent skill / SDK run on the configured PI_RESEARCH_MODEL and never\nfollow the model selected inside the pi extension.",
"is_bot": false,
"headline": "release: v1.0.3 — configured-model requirement, docs",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-04T12:42:03Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "15f33b408a12f3291567b393d3b374ba7b352571",
"body": "…LI/skill; align the SDK session model with RESEARCH_MODEL\n\nThe standalone CLI / agent skill now run only on an explicitly configured\nmodel and never follow the model selected inside the pi extension:\n\n- cli: with pi credentials (auth.json) but no PI_RESEARCH_MODEL, research\n and knowledge fail fas\n[…]\n/ the install-time note in both\noutput forms; SDK seeding pinned via the registry lookup; object\npass-through pinned against a decoy registry so the old fallback path\ncannot coincidentally satisfy it.",
"is_bot": false,
"headline": "fix(model-resolution): require a configured model on the standalone C…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-04T12:42:03Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e90474b36464ecddac3ac4fc19ed9eeb85355e64",
"body": "…onversion fallback\n\nThe third-party list now presents html-to-markdown as the converter with\nnode-html-markdown noted only as the pure-JS fallback, per maintainer\ndirection — one brief mention in the architecture doc.",
"is_bot": false,
"headline": "release: v1.0.2 — timeout robustness fix; de-emphasize the markdown-c…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-04T11:29:58Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b4cfcc40256bb74e44b4e10ad412f21dabb79292",
"body": "…n.abort() hangs\n\nRoot-caused from a live stall: with the provider account quota-exhausted\n(GLM 1308 'usage limit reached', HTTP 429), a researcher sat 26+ minutes\npast its 15-minute PI_RESEARCH_TIMEOUT_MS with no timeout ever firing.\nThe timeout's rejection was gated on session.abort() SETTLING\n(.f\n[…]\np await on\nabort() is bounded by a 10s grace so retries cannot hang there either.\nRegression test: prompt AND abort never settle → runResearcher still\nrejects with the timeout error under fake timers.",
"is_bot": false,
"headline": "fix(orchestration): make the researcher timeout fire even when sessio…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-04T11:29:58Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6cf9c57a41038f1ae3acc3a609ea73ed7c156959",
"body": "… the entry points are esbuild-bundled; html-to-markdown repo moved\n\n- THIRD-PARTY-NOTICES called camoufox-js a transitive dependency in the\n ua-parser-js override rationale; it is a direct dependency (ua-parser-js\n is the transitive one).\n- 'dist/* is built with esbuild --packages=external' overs\n[…]\nLicensing conclusion\n unchanged.\n- ARCHITECTURE linked html-to-markdown at its pre-org-move URL; the\n installed @kreuzberg/html-to-markdown-node declares\n github.com/kreuzberg-dev/html-to-markdown.",
"is_bot": false,
"headline": "docs: dependency-notice precision — camoufox-js is a direct dep; only…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-04T11:03:52Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f07288de840aab83556abbdb85ef881788b5d919",
"body": "…-doc gate polling\n\nThe three bare transport patterns (throttle_violation, too many requests,\nrate limit) could classify a healthy result as an environment failure — a\nsecurity advisory body that merely says \"rate limit\" would silently skip\nthe test. Anchored to the shapes the clients actually emit:\n[…]\n status that fell into the generic waiting branch. Capture via\n'if !' and substitute '{}' so the poll logs the honest missing-run line.\nBoth paths exercised locally under bash -e against the live API.",
"is_bot": false,
"headline": "test(integration),ci(release): anchor throttle classification; single…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-04T10:51:45Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "86924d6563957a4b00693ebbfad487b71ab48340",
"body": "- AGENT-SKILL: the engine box in the flow diagram is the CLI entry\n (dist/cli.mjs), not the SDK (which has no transpiled dist).\n- CONFIGURATION: PI_RESEARCH_MODEL also selects the session model on the\n standalone CLI/SDK when no --model/model option is given — the table row\n previously described \n[…]\nw one line plus a pointer\n to the canonical doc.\n- README: drop the launcher-internal parenthetical about which dependency\n the launcher probes — the launcher prints that guidance itself at runtime.",
"is_bot": false,
"headline": "docs: pre-1.0.1 audit trims — accuracy fixes and dedup, no new content",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-04T10:42:22Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "652c1a99b5aff8dd5a72fb9abf7c9b3c2b1d7ed4",
"body": "…uTube live-skip\n\nfix(cli): wrap uninstallSkill in the same try/catch as install, so an\ninstaller throw (e.g. unwritable ~/.pi manifest) keeps the --json output\ncontract via reportError instead of leaking a plain-text fatal to stderr.\nExit code was already correctly nonzero on that path.\n\nci: set PI\n[…]\nPoToken fetches actually ran in CI and passed via the tolerant\nfailure branch (a latent hang-flake source). Now behavior matches the\ndocumented contract; the other seven parallel files are unaffected.",
"is_bot": false,
"headline": "fix: v1.0.1 audit follow-ups — skill-uninstall --json contract, CI Yo…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-04T10:31:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1afa2194130c2433770306fc91c7acee71f76c60",
"body": "…e, CI-gated release\n\nfeat(cli): add a `skill` command (install | uninstall | status) that links the\nbundled agent skill into the coding agents on this machine (Claude, Codex,\nOpenClaw). It's the standalone-CLI equivalent of the pi extension's\n`/research-config → Install in External Agents`, for use\n[…]\n a hermetic install→status→uninstall subprocess\nround-trip against an isolated HOME). Full suite 1893 green; type-check, lint,\ndeps:check, prod audit (0 vulns), tarball manifest (222 files) all clean.",
"is_bot": false,
"headline": "release: v1.0.1 — CLI skill install/uninstall, install-doc restructur…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-04T10:20:16Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "75a9ec7c071b78fecc8bdcdcb0d77021a918268a",
"body": "…m safety\n\nMatch the registry chmod posture introduced in the previous commit (83a4cfa4):\non Windows, chmodSync only toggles the read-only attribute and a throw on\nan exotic filesystem must not fail a saveConfig whose data is already\ndurably written (the atomic writeFileSync + rename have already co\n[…]\nod at line 373 was already guarded; this existing config.env\nchmodSync at line 878 (hardened in f57c889b) was not. Wrapping it means\nboth save-paths now treat the permission-tightening as best-effort.",
"is_bot": false,
"headline": "fix(config): wrap config.env chmodSync in try/catch for cross-platfor…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-04T09:23:20Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "83a4cfa4749746c50d5d2ad30448d8b7d90af3b6",
"body": "Consistency gap surfaced in the f57c889b audit: the user-scope config.env\nis written 0o600 in a 0o700 dir (hardened because it may hold API keys),\nbut the LOCAL-scope project-settings.json and BOTH lock files were written\numask-default (~0644), sitting in the same owner-only state dir.\n\nThe registry\n[…]\ne).\n\n- config.ts: registry temp write { encoding, mode: 0o600 } + chmodSync\n after rename; both lock opens (registry + config.env) now 0o600.\n- config.test.ts: assert the hardened write + lock opens.",
"is_bot": false,
"headline": "fix(config): write the project-settings registry + locks mode 0o600",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-04T09:08:40Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ed2d9fd6f25296d8af37b540a5e0a332053646ee",
"body": "Resolve two user-facing naming inconsistencies surfaced in the pre-release\nsweep.\n\n1. The component health operation was called \"Health Check\" (the tool label,\n the healthcheck/ module, HEALTH_CHECK_TIMEOUT_MS, most docs) but \"Run\n Diagnostics\" in the /research-config TUI. \"Diagnostics\" now refe\n[…]\nATION, KNOWLEDGE-STORE); index.test.ts mock string.\n\n\"database\" is retained where it is technically accurate (the LanceDB vector\ndatabase instance, NVD/OSV security databases, \"is a vector database\").",
"is_bot": false,
"headline": "refactor: unify naming — \"Health Check\" and \"knowledge store\" everywhere",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-04T07:52:15Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "46d5e497424be83ed4752b60bd806b2a663cc29c",
"body": "Final hardening from the pre-release audit.\n\nRelease pipeline (release-blocking):\n- release.yml: drop `registry-url` from the publish job's setup-node step.\n npm OIDC Trusted Publishing authenticates via the GitHub OIDC token and\n only takes that path when it finds NO other auth; setup-node's regi\n[…]\n\nTests:\n- deep-research-orchestrator: regression tests for the throwing-observer\n contract (verified to fail on the reverted code).\n- text-utils: regression tests for balance-aware bracket stripping.",
"is_bot": false,
"headline": "fix: pre-1.0.0 audit fixes — release pipeline, crash-safety, citations",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-04T07:51:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c73e6cf37c604cc661b3556fb22e984851cd5bd2",
"body": "…release-pipeline hardening\n\nApplies the pre-release audit findings for the v1.0.0 hardening sweep (f57c889b)\nthat were left uncommitted, plus regression tests for the crash-safety/security\nfixes and release-pipeline hardening.\n\nProduction fixes (audit-driven):\n- file-lock-service: rename-to-trash +\n[…]\npublishing).\n- cvss.ts: fix misleading docstring — cite the full changed-scope vector\n (AV:P/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H -> 6.9/MEDIUM); the shorthand\n S:C/C:H/I:H/A:H alone scores 10.0/CRITICAL.",
"is_bot": false,
"headline": "fix: finish pre-1.0.0 hardening — audit findings, regression guards, …",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-04T03:31:57Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "54887bdddcc9ab8948f30a3f7d59008b085d4a54",
"body": null,
"is_bot": true,
"headline": "chore(ci): regenerate docs/deps.svg (detailed module graph) [skip ci]",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-07-04T02:16:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f57c889b6e7b2e05d49a60822b5b99112b0c9d99",
"body": "…ring, tests, docs\n\nSecurity/network:\n- Browser subresource SSRF closed: DNS-aware request validation with a\n per-worker verdict cache, plus a response-side serverAddr rebinding\n backstop that poisons the scrape (benign-classified, page closed)\n- ~/.pi/research/config.env written 0600 in a 0700 di\n[…]\nrs, THIRD-PARTY-NOTICES link)\n- Prompt fixes: frontmatter leak removed, budget/tool wording matches\n reality; removed the dead mock-factory helper, orphaned stress scripts,\n and stale ignore entries",
"is_bot": false,
"headline": "fix: pre-1.0.0 hardening sweep — security, crash-safety, config, stee…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-04T02:14:57Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b570fd1168ed40f2a381334a13c4d3f12c3f1f7c",
"body": "… and flake-free\n\nSame class of defect the severity test had, across the Security Search block:\n\n- Weak assertions: several tests asserted only expect(text.length).toBeGreaterThan(50)\n or expect(text).toContain('<term>') — but the tool's FAILURE body (\"Security\n Vulnerability Search Failed\") echoe\n[…]\nithub'] so it's actually tested.\n\nError-handling tests (empty terms, invalid db, special chars) and the Stack Exchange /\nGrep blocks are unchanged. Verified locally against the live APIs: all 31 pass.",
"is_bot": false,
"headline": "test(security): make the Security Search integration tests meaningful…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-04T01:12:32Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3f5a93ae2392f37df777299881bc2b414bc5d14b",
"body": "…rams\n\nThe strengthened assertion in eceef524 exposed a pre-existing bug this test had\nalways masked with a vacuous toBeDefined(): it passed `severity: ['HIGH','CRITICAL']`\n(the schema takes a single string, security.ts:28) and `databases: ['cisa']` (the\nkey is 'cisa_kev'), so the tool returned \"Inv\n[…]\nactually runs a CISA KEV severity-filtered search\nand asserts the real \"Security Vulnerability Search Results\" report. Verified locally\n(passes against the live CISA API; skips visibly on rate-limit).",
"is_bot": false,
"headline": "test(security): fix the severity-filter integration test's invalid pa…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-04T01:06:20Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "eceef5249ca4d4ad5287a4632df4e60da4f49e69",
"body": "…rage\n\nFrom the test-quality audit — make tests fail when the behavior regresses:\n\n- tools-extended.test.ts: convert every `if (isNetworkUnavailable(text)) return;`\n to `return ctx.skip()` so a rate-limited CI run is VISIBLY skipped, not silently\n passed; strengthen the vacuous severity assertion \n[…]\n, 169.254 metadata, IPv6 private, mixed public+private\n (fail-closed), a public-only pass, and that the loopback flag doesn't relax it.\n\nTest-only; no production source changed. 1777 unit tests pass.",
"is_bot": false,
"headline": "test: close false-greens and add the untested SSRF DNS-rebinding cove…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-04T00:56:36Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "650c07ee64d68d18cf5b6fc23ffd685faacbd2d9",
"body": "…th; tolerance + probe-doc refinements\n\nFrom the adversarial review of the health/probe changes:\n\n- A1 (health idle path): a store DISABLED for reason 'mode' (Knowledge Mode was\n none — revivable) was mislabeled \"native embedding/vector stack unavailable on\n this platform\" on a perfectly capable h\n[…]\nrror patterns to the shapes the\n tools actually emit (\"HTTP 429 from …\", \"HTTP 429: …\", \"(HTTP 503)\") so a vuln\n description that merely mentions an HTTP status in its body is not falsely tolerated.",
"is_bot": false,
"headline": "fix(health,knowledge): accurate DISABLED reason in the idle health pa…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-04T00:46:13Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "da7987d3a55d60a4fb54e8f578129006f6fba8b9",
"body": "…er hang init)\n\nThe out-of-process probe loads the model on the WebGPU EP to test a real compute.\nOn a first-ever run the model isn't cached, so the probe would DOWNLOAD it — and\non a GPU-less host that load can hang for minutes. With the health check no longer\nwarming the embedder early (f466b458),\n[…]\napable host uses CPU embeddings on its very first run and switches\nto WebGPU from the second (once the model is cached) — negligible, and it avoids the\nprior duplicate model download inside the probe.",
"is_bot": false,
"headline": "fix(knowledge): defer the WebGPU probe until the model is cached (nev…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-04T00:25:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b9920103acb5a267e495ffd559f829cc238d1f05",
"body": "…ers)\n\nGitHub runners have no real GPU, so the default EMBEDDING_DEVICE=auto runs the\nout-of-process WebGPU viability probe, which on a GPU-less host loads the model\non the Dawn/WebGPU EP and then either crashes (software Vulkan) or hangs — and\nthat probe can only ever fall back to CPU anyway. It wa\n[…]\nntless probe, no stall, no hang. No integration test asserts a\nwebgpu device. The real WebGPU path stays covered by the mocked\nwebgpu-viability unit tests. Real-user auto/webgpu behavior is unchanged.",
"is_bot": false,
"headline": "ci: force EMBEDDING_DEVICE=cpu in the integration jobs (GPU-less runn…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-04T00:20:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1492d2bdc35917c89ca9585b70450e139266b3c8",
"body": null,
"is_bot": true,
"headline": "chore(ci): regenerate docs/deps.svg (detailed module graph) [skip ci]",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-07-03T23:55:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f466b45836381294d84d2afffd45e73cec7264a5",
"body": "…ake the WebGPU probe one-time & fast-fail\n\nRoot cause of the ~45s (×N) ubuntu-CI integration stall: a non-forced\nKnowledgeStore health check resolved the store via getService(), which lazily\nran the LanceDB open + ONNX model load + out-of-process WebGPU probe. On a\nGPU-less runner the probe didn't \n[…]\nrance helper treat upstream HTTP 429/503\nthrottling as an environment condition (like the existing rate-limit patterns),\nfixing the intermittent Stack Exchange / security-tool flakes on shared CI IPs.",
"is_bot": false,
"headline": "fix(health,knowledge): stop the health check forcing embedder init; m…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T23:53:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ed726d84c79d4fa48381614047a9811ce883bd10",
"body": "…cleanup\n\nRelease gate:\n- release.yml publish job now mirrors current CI's fast blocking checks:\n production-dep audit (--omit=dev --audit-level=moderate), deps:check\n architecture rules, and ripgrep parity. Adds a note that the cross-OS\n unit/integration matrix in ci.yml gates main before a rele\n[…]\np redundant `export` on 10 file-local-only symbols.\n- constants.ts: correct gathering-budget comment (add youtube_transcript).\n- .env.example: show DEBUG default (false) per the file's own convention.",
"is_bot": false,
"headline": "chore(release): pre-1.0.0 polish — align release gate with CI, docs, …",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T21:47:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a89d129da160b00f5285b7941ca001284c5366d7",
"body": "Signed-off-by: Lincoln <56658553+Lincoln504@users.noreply.github.com>",
"is_bot": false,
"headline": "Fix formatting in README for search depth levels",
"author_name": "Lincoln",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T21:38:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0d035e874b3e4885b2211746d7d61f8d36ef5b45",
"body": "Corrected grammatical errors in the README content.\n\nSigned-off-by: Lincoln <56658553+Lincoln504@users.noreply.github.com>",
"is_bot": false,
"headline": "Fix grammar in research description in README",
"author_name": "Lincoln",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T21:36:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0aefbd412d30eb349d8dbe13613fecf508d4a74b",
"body": "…ounded writer drain\n\nThe knowledge store was freshness-blind at read time: rebuildDocument served\ncached scrapes (and knowledge-search reference docs) up to the eviction TTL\nwith the row's age discarded, so time-sensitive queries could land stale\ncontent as authoritative. Now:\n- rebuildDocument com\n[…]\nsession-deduped, so free cache batches would allow an unbounded re-submit\nloop), and the knowledge-store re-scope singleton (not reachable concurrently\nin the shipped CLI/SDK/extension process model).",
"is_bot": false,
"headline": "fix(knowledge,tools): read-time cache freshness, grep budget split, b…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T20:24:47Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ed1d059070f8ec54bb4850eade08b7249601ed70",
"body": "Updated wording from 'high quantity pool of sources' to 'high volume sources'.\n\nSigned-off-by: Lincoln <56658553+Lincoln504@users.noreply.github.com>",
"is_bot": false,
"headline": "Fix wording in research description",
"author_name": "Lincoln",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T20:03:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "71df6c6042657c0cf229695532a645957137a45b",
"body": "Signed-off-by: Lincoln <56658553+Lincoln504@users.noreply.github.com>",
"is_bot": false,
"headline": "Remove markdown link from README description",
"author_name": "Lincoln",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T20:03:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f859e853bff073a3c582e78cdbdde62434a7b04f",
"body": "Updated README to include a link to the pi project and improved clarity in the research process description.\n\nSigned-off-by: Lincoln <56658553+Lincoln504@users.noreply.github.com>",
"is_bot": false,
"headline": "Enhance README with pi link and clarify research process",
"author_name": "Lincoln",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T20:01:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f2a967e149ce4447b4bb5b33d84ae905b4e9271c",
"body": "The SIGINT/SIGTERM handler called process.exit() directly, bypassing the flushAndExit drain\nthe normal exit path uses — so buffered stdout (e.g. --json into a pipe) could truncate when\na signal arrived mid-write. Hoist flushAndExit to module scope and use it from the signal\nhandler too. (The exit CODE on clean Ctrl-C is left as-is: changing 70→130/143 is a\ndocumented user-facing contract change, not a mechanical fix.)",
"is_bot": false,
"headline": "fix(cli): drain stdout/stderr on a signal-triggered exit",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T18:36:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "dff9f8a15e1dd44480b6746928b01522e65d9ecb",
"body": "…uit-breaker map\n\n- nvd-client: the per-request page size was hard-capped at 20 (Math.min(20, maxResults))\n while MAX_RESULTS_PER_PAGE (2000, NVD 2.0's ceiling) only bounded the caller-facing\n maxResults — so a request for >20×maxPages results silently truncated. Scale pageSize to\n min(MAX_RESULT\n[…]\nreakers with oldest-entry eviction (mirrors\n error-tracker's MAX_PATTERNS) so a cleanup path that ever skips clearSessionCircuitBreaker\n can't grow the map unboundedly over a long-lived TUI process.",
"is_bot": false,
"headline": "fix(security,browser): scale NVD page size and bound the session circ…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T18:36:41Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5cbf106ac52fb8c870a4a39aaf969974f2be6d4d",
"body": "…sing non-JSON bodies\n\n- The circuit breaker wrapped only per-video fetchOne, leaving the once-per-batch seed\n session + PoToken mint — the steps most prone to a systemic BotGuard/attestation outage —\n uncovered, so every batch paid the full timeout on each during an outage. Route both\n through t\n[…]\nurned '', so the caller reported\n \"bot-protection rejected the token\" for ANY non-JSON body (HTML interstitial, shape\n change). Log a short snippet on parse failure so the real cause is diagnosable.",
"is_bot": false,
"headline": "fix(youtube): fail-fast the seed/mint under outage and stop misdiagno…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T18:36:41Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3ebe3c5971006e71de912ff6131e2dfa152b22f1",
"body": null,
"is_bot": true,
"headline": "chore(ci): regenerate docs/deps.svg (detailed module graph) [skip ci]",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-07-03T18:23:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c5b1417de4a3c3551b2278d1010311f6cc219c1f",
"body": "…ll, tighten typescript\n\n- docs/SDK.md: the documented plain-Node recipe (`--experimental-strip-types`, \"default\n from 23.6+\") throws ERR_UNSUPPORTED_TYPESCRIPT_SYNTAX — the source uses `enum` and\n constructor parameter properties, which strip-only mode rejects. Document\n `--experimental-transfor\n[…]\n only the built run.mjs is executed.\n- package.json: tighten the typescript devDependency to `>=6.0.3 <6.1.0` so a future 6.1\n can't float past @typescript-eslint's peer ceiling and break the linter.",
"is_bot": false,
"headline": "chore(packaging,docs): correct the SDK runtime recipe, trim the tarba…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T18:22:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8be624c40c86e555b25ea483e5977ebfa069b7c7",
"body": "…gent audit\n\n- youtube: the transcript circuit breaker matched 'timeout' but withTimeout() rejects with\n \"...timed out\" (no contiguous \"timeout\"), so genuine hangs never counted toward the\n breaker and every researcher paid the full timeout during an outage. Match 'timed out'.\n- github-advisories:\n[…]\nlike the query already\n is — they are templated verbatim into the researcher's trusted-seed evidence block. Also\n document --config for status/knowledge-config and the knowledge 5-query cap in help.",
"is_bot": false,
"headline": "fix(security,youtube,cli,extension): release-hardening from a multi-a…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T18:22:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "adeb82578a811fcb933ff255a5a505739e6acf80",
"body": "…bedder reconnect-clear\n\n- exportForWeb is reachable from the public SDK (exportKnowledge) at any time but was the\n one read left outside trackOperation — a concurrent close() could free the native handle\n mid-query. Wrap it like the sibling reads.\n- reconnectFactory did not await clearEmbeddingIn\n[…]\nng its dispose(). Without the await, getEmbedder() (for unchanged\n config) returned the same still-disposing instance — so a leader-handoff reconnect handed\n back the very embedder it was replacing.",
"is_bot": false,
"headline": "fix(knowledge): close the exportForWeb teardown race and await the em…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T18:22:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5748deaadb4a6f4094ceb716d776e4088bbed979",
"body": "…ning batch\n\nAdversarial self-review of the just-pushed fixes surfaced three of my own regressions:\n- sdk.ts: `_isRunning` was set before the try, but the `await getService()` between them\n can throw (container-disposal race / unregistered service). On that throw the flag never\n reset and, since n\n[…]\n the other count knobs.\n- stackexchange: the new maxPages cap used Math.max(1, ...), which changed the meaning of\n maxPages=0/negative (previously \"no pages\") to \"one page\". Cap only the upper bound.",
"is_bot": false,
"headline": "fix(sdk,config,stackexchange): repair edge cases from the prior harde…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T18:22:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1aba2e88347295fec0821e9f11cdfaa8eff41653",
"body": null,
"is_bot": true,
"headline": "chore(ci): regenerate docs/deps.svg (detailed module graph) [skip ci]",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-07-03T17:27:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a3164c71124c176ecd90f93b49b3559d84965b1a",
"body": "statusMessage was written in 12 observer paths and read nowhere — the header already\nrenders panel.title and each phase shows via per-slice status, so it was pure dead stores.\nRemove the field and all writes (behavior-neutral), and drop the now-obsolete test that\nasserted the dead field was not rendered.",
"is_bot": false,
"headline": "refactor(tui): remove the dead statusMessage panel field",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T17:26:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "35c41b9aebffeac50412e63f003445720b0de8b6",
"body": "…signals, bound inputs and metric labels\n\n- osv-types: guard range.events (upstream validates only the vuln id) — an unguarded\n events.find() threw a TypeError that failed the whole term in Promise.allSettled and\n discarded all its vulns.\n- web-scraper + stackexchange: honor an already-aborted sig\n[…]\niling garbage like '10abc')\n and add an integer flag applied to the count knobs (worker threads/concurrency, researcher\n and scrape counts) so a fractional value can't reach poolifier / loop bounds.",
"is_bot": false,
"headline": "fix(security,config,resilience): guard OSV events, honor pre-aborted …",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T17:26:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ae539ff9c85359cd434264ea03feb3a0e45ff54d",
"body": "…tion, HTTP embed guard, Windows write false-failure\n\n- process-lifecycle isProcessAlive: compare start times with ±1s tolerance. The macOS/BSD\n fallback derives start time as floor(Date.now()/1000) - `ps etimes`; both terms are\n independently quantized, so the same process reads 1s apart and a st\n[…]\n temp unlink best-effort.\n copyFile already persisted the state; an AV-locked temp unlink was falling through to the\n catch and reporting \"Failed to write state\" for a write that actually succeeded.",
"is_bot": false,
"headline": "fix(infra): tolerate start-time jitter, fix stdio-capture flag corrup…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T17:26:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a24b302333300be2603504f4093ae2a4c327db55",
"body": "…t, no teardown-noise errors, close a listener leak\n\n- Thread the task-timeout AbortController's signal into executeScrapeTask and close the\n page on abort. page.setDefaultTimeout only bounds Playwright's action/nav verbs, NOT\n Response reads: a large/slow PDF's response.body() (or a slowloris tri\n[…]\ndown() could no longer clear it.\n- browser-client: remove the outer-signal abort listener on the timeout path too, else a\n shared long-lived run signal accumulates one listener per timed-out request.",
"is_bot": false,
"headline": "fix(browser): free worker slot on stuck scrape, single-shot pool rese…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T17:26:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "df1b89dad68e4fb76a1c99c971219f88187f0ef0",
"body": "…on state, always fire a terminal callback\n\n- runDeepResearch: the _lastSessionId/_lastResearchId/_lastRunSummary module singletons\n are last-writer-wins, so two overlapping runs on one SDK instance silently corrupted\n each other's reported session/metrics/reports. Concurrent runs are documented-u\n[…]\nired onStart but no terminal\n callback, leaving the TUI/headless quick slice stuck \"in progress\". Add an outer catch\n that fires onError exactly once (guarded so the inner catch isn't double-fired).",
"is_bot": false,
"headline": "fix(sdk,orchestration): guard concurrent SDK runs, free per-run sessi…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T17:26:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "66628369e69df6d9403f030e776a12d043487ea3",
"body": "parseCitations stripped a trailing ')' blindly, running BEFORE normalizeUrl — so a\ncitation to a balanced-paren URL (e.g. Wikipedia's ..._(programming_language)) lost its\nclosing paren and shipped as a broken 404 in the CITED LINKS section, defeating the\nbalance-aware fix that only lived in normaliz\n[…]\n Export and reuse\nstripTrailingLlmPunctuation so both paths handle trailing punctuation identically\n(strip an unbalanced ')', keep a balanced one; preserve unreserved '_'/'~'). Adds a\nregression test.",
"is_bot": false,
"headline": "fix(citations): preserve balanced-paren URLs in parseCitations",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T17:26:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "44dfde4c4d13cb096b8eaf16f7edda7c05371124",
"body": "…heck, close-coord reads, revive ORT net\n\n- addDocuments: the version-mismatch retry refreshed the table handle but discarded\n it, re-running every attempt against the same version-pinned snapshot — under\n concurrent cross-process writes all retries re-conflicted and the batch was silently\n dropp\n[…]\n\n- Embedder: re-register the global ref on the idle→active revive so the beforeExit ORT\n teardown net survives an idle dispose; WeakSet-guard the shutdown task so re-registration\n leaks no callback.",
"is_bot": false,
"headline": "fix(knowledge): stop concurrent-write doc loss, race-free FTS stale c…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T17:26:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a68603b682a52e6c3aa5f577705fe4c0627f994b",
"body": null,
"is_bot": true,
"headline": "chore(ci): regenerate docs/deps.svg (detailed module graph) [skip ci]",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-07-03T08:07:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a8ba40afd00bdc333bcde4037e0ee6fc278ecd42",
"body": "… docstring\n\nThree small correctness fixes:\n\n- Query XSS heuristic. The event-handler pattern was boundary-anchored to (^|[\\s\"'<]) to\n avoid false positives like \"pokemon2=\", but the class omitted '/', so tag-internal\n slash-delimited handlers (<svg/onload=, <img/onerror=) passed. Switch to a nega\n[…]\ny, and the code correctly uses one unified formula). Rewrite the\n header to match the accurate inline comment. No runtime change.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix: XSS heuristic slash-handler gap, scrape-failure undercount, CVSS…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T08:05:17Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "efcc99111af8a2a32529a5a24833e33d8e4252c6",
"body": "…e; store ops vs close)\n\nTwo latent teardown races (not currently reachable on a supported path, but fragile):\n\n- ServiceContainer.reset() awaited an in-flight disposal once, then called disposeAll()\n again. If a fresh, non-reentrant disposeAll() (P2) started in the microtask gap, reset's\n own dis\n[…]\nUrlAndType, and clear through trackOperation so close() awaits them\n and they skip cleanly (neutral value) once isClosing is set.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(core,knowledge): harden teardown races (container reset vs dispos…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T08:05:07Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "5ede30fed629f26ed8e2e6282c92c8e4f119b28a",
"body": "The CITED LINKS block splitter used `\\d+\\.` to match an ordered-list marker but was not\nanchored to line start, so it matched a digits-then-dot run ANYWHERE — including inside\nURLs. `report-2024.pdf` parsed as `report-`, `/v2.0/` as `/v`, and an IP-literal URL like\n`192.168.1.10` was shredded and dr\n[…]\nl so blocks[i] / writtenNumbers[i] stay index-aligned.\n\nTests: digits-then-dot URLs preserved in both the [N] and N. marker forms.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(citations): stop parseCitations splitting URLs on digits-then-dot",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T08:04:57Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "ae21af1b48eacfa0cd75cbf513d4628d9ef3473b",
"body": "…ycle\n\nFour observer→render defects where the panel showed a wrong or stuck state:\n\n- Failed researcher looked identical to a success. onResearcherFailure set the slice\n status to 'failed' then completeSlice() — but the render suppresses the status field on\n a completed slice and draws it muted, e\n[…]\not; quick-mode search\ncompletion leaves the slice active until the researcher finishes; quick-mode failure marks\nthe slice failed.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(tui): render researcher failures; fix quick-mode & eval-box lifec…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T08:04:43Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "53531e8f58a48141fd70489c9a7c1008d7a61775",
"body": "…registry\n\nThe token count and cost the research tool reports (details.totalTokens, the export\n\"Total cost\" footer, and /research print-mode) were read from panelState.totalTokens/\ntotalCost — a TUI-observer-only tally. Two consequences:\n\n - Headless/SDK/print-mode runs use HeadlessObserver, which \n[…]\nsive metrics.clearSession() after each unit test to keep session-metric assertions\ndeterministic if vitest isolation ever changes.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(core): unify LLM token/cost accounting on the run-scoped metrics …",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T08:04:25Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "e0fa814901165e752a5eafc5dff63596f1664857",
"body": "…g (Windows CI red)\n\nThe Windows unit-test leg was failing (2/2 recent runs) with unhandled\n\"Cannot reset container while disposing\" rejections thrown from index.test.ts's\nafterEach. Root cause was a teardown race: a disposeAll() sets isDisposing=true while\nawaiting each service's async dispose(), a\n[…]\nh await the reset (prevents overlap with the next test). +1 regression test that\nstarts a disposal and calls reset() concurrently.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(core): reset() waits out an in-flight disposal instead of throwin…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T07:16:23Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "13af4f00fe1341645e3c019e3003572461e4e19a",
"body": "The coordinator's round-1 search count (\"N results\", climbing as queries return) is\nwritten to its slice status and rendered in the token row. Commit 0a9da110 changed the\ncoordinator-column detector from a label substring to `sliceId === 'coord'` to stop a\nresearcher whose query contains \"planning\" \n[…]\n the status text always\nrenders. Token/cost blanking for the coordinator (and its sweep-2 tests) is preserved.\n+1 regression test.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(tui): restore the coordinator's live search-count display",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T07:00:59Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "f801f1f8423390fd2f1d65b492cab4bd6d20332e",
"body": "… pdf-oxide-wasm\n\nThree dependency corrections after auditing which pins are genuine compat constraints\nvs. incidental floating ranges that ship an untested version:\n\n- typebox ^1.1.38 -> 1.1.38 (exact). TypeBox is a real runtime dep here — it builds\n every tool's parameter schema and validates LLM\n[…]\neck, type-check:tests, lint, build, 1751 unit tests, deps:check, verify-package\n(223 files), npm audit (0 vulns), publish dry-run.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore(deps): align typebox to the host pin; move undici to 8; refresh…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T06:47:16Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "4df90d7feae5a81c8f78eab56d31853d5354229f",
"body": null,
"is_bot": true,
"headline": "chore(ci): regenerate docs/deps.svg (detailed module graph) [skip ci]",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-07-03T04:37:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "78fff588c915761dda30ac27a271dad537862360",
"body": "An explicit status clear (status=undefined, e.g. a tool's done: event) took the\ndirect-write branch of updateSliceStatus and left the slice's flashStatus() timer\narmed. The next tool's status then saw that stale timer as \"still active\" and QUEUED\ninstead of showing immediately; when the stale timer \n[…]\nwith a per-slice\nclearSliceStatusFlash() on the clear path — same-slice only, no cross-researcher\nrefcounting. +1 regression test.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(tui): cancel a slice's pending status pop on explicit clear",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T04:35:38Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "c0863596f80e475ab6bcf7bb0b7c5fd5846e9c99",
"body": "Success paths emitted { ok: true, ... } JSON, but every error path (missing\ncredentials, query validation, and the reportError catch-all for runtime/config/rate-\nlimit errors) printed plain text to stderr regardless of --json, so a machine consumer\nhad to special-case stderr on every failure. Thread\n[…]\nor, exitCode } (plus stack under PI_RESEARCH_DEBUG) on\nstdout when --json is set; the plain-text behavior is unchanged without it.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(cli): honor --json on error paths, not just success paths",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T04:35:38Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "f29034c1efbc4c87a428e5fbe2564dde7ca16301",
"body": "… package root\n\nindex.ts re-exported the entire sdk.ts module with `export *`, which leaked\ngetSDKContainer() — marked @internal, test-only, and consumed solely by\nshutdown-perf.test.ts via a direct relative import — from the package's primary entry\npoint. Replaced the wildcard with an explicit name\n[…]\nchable via the separate, intentional `/sdk` raw-module subpath, which is a\ndeliberate advanced-consumer surface, not touched here.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "refactor(sdk): don't re-publish the internal getSDKContainer from the…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T04:35:38Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "9b1ffe26d95f132c4f8f72456fdfb50392a6c4a3",
"body": "lazyInitialization was set (usually false, with intent comments) at ~24 registration\nsites but NEVER read — register() always stores instance:null, so every service is\nlazy regardless. Eager-vs-lazy is actually driven by the init-time\ncriticalInfrastructure/eagerServices name lists, which proactivel\n[…]\nock\nFileLockService registration in the infrastructure init module (the browser/knowledge\nsites were wired in the locking commit).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "refactor(container): remove the dead lazyInitialization flag",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T04:35:38Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "6eea5d04d5d9a56ec920c73ae456547bb0a834be",
"body": "…rches\n\nA severity-filtered NVD search only ever sent cvssV3Severity. NVD's API filters\nbefore pi-research sees the data and only matches a CVE's own metric of that version,\nso any CVE carrying ONLY a CVSS v2 score (mostly pre-~2021, ~57k for HIGH alone) was\nsilently dropped — the client-side v2/v4 \n[…]\ny under the 6s no-key\nthrottle — documented NVD_API_KEY as the mitigation. 5 new tests incl. the dual-rated\nno-re-band regression.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(security): recover CVSS v2-only CVEs in severity-filtered NVD sea…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T04:35:38Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "2198128d6f527b6388a9a2839f97103dfe015ea6",
"body": "FileLockService was the last liveness check in the codebase still using a bare\nprocess.kill(pid, 0) — every other check (GPU, state-session, embedding) already\npairs PID with process start time via ProcessLifecycleService. Under PID reuse a\nrecycled PID made a dead owner's lock look \"alive\", delayin\n[…]\ne container cleanup commit. 6 new tests (legacy compat, same/foreign-PID\nreuse, memoization-not-per-tick, own-start-time-failure).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(locking): PID+start-time (reuse-safe) liveness in FileLockService",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T04:35:38Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "4c3bf57b1e1bfda5d18533045510065e08131aee",
"body": null,
"is_bot": true,
"headline": "chore(ci): regenerate docs/deps.svg (detailed module graph) [skip ci]",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-07-03T04:05:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c2cb7640d3e675cc7b775588459a63025077f7ff",
"body": "quarantineFutureState() is deliberately excluded from cleanupOldBackups (a .quarantine copy\nmust never be restored into an older reader), so nothing pruned them. A machine repeatedly\nrunning an older build against newer state (rollback, bisect, flip-flopping installs) leaked\none orphaned copy per occurrence forever. Cap retention to the newest few after each write.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(state): bound quarantine-file retention",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T04:04:02Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "fd6d98644ac56e3c85a19d2b83a7721a3fa91fba",
"body": "StateBrowserApi.isPidAlive and StateBrowserManager.isPidAlive formed a complete parallel\nliveness-check path that nothing invoked — StateManager composes browserApi but only calls\nget/set/clearBrowserServer, and the live liveness path is StateManager.isPidAlive ->\nprocessLifecycle.isPidAlive. Deleted the ~40 dead lines; the standardized PID+startTime\ncheck in ProcessLifecycleService is the single source of truth.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "refactor(state): remove the dead isPidAlive pathway",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T04:04:02Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "019f8cc139a2c8160840a4d71dd43c41ee02e90b",
"body": "…values\n\nconfig.ts and cli.ts each carried a hand-rolled parseDotEnv, and they diverged: the CLI's\ncopy stripped a matched pair of surrounding quotes, config.ts's did not. For non-project\nkeys the divergence was masked (the CLI bridges them into process.env, which wins), but\nproject-scoped keys are \n[…]\n in config.ts (the CLI's copy existed\nonly \"to avoid a dependency on an unexported helper\" — now exported), with regression tests.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "refactor(config): single dotenv parser — fixes quoted project-scoped …",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T04:04:02Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "ae57b154b417a388ed772c972094f6263d73f586",
"body": "…ainst shutdown\n\ngetResearchReports() and runResearchDetailed().reports always returned an empty Map —\na documented public SDK feature, silently broken. Two independent causes:\n\n- Reports are stored keyed by researchId (\"sdk-<ts>\"), but getResearchReports looked\n them up by _lastSessionId, a distin\n[…]\ninit first; _doInit's own failure cleanup\ncalls _doShutdown() directly so it can't re-enter and deadlock awaiting its own promise.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(sdk): return per-researcher reports from a run; serialize init ag…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T04:03:50Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "18569d5fd68b739e5f7495409c17bae310c3d5c4",
"body": "…gs dropped on a leader handoff\n\nThree related robustness gaps in the knowledge store, all reachable in normal use:\n\n- close() vs compaction race: only addDocuments registered into activeWrites, so\n a Ctrl+C-driven close() firing while the post-run FTS rebuild / optimize ran in the\n background cou\n[…]\nleader. Consolidated the two divergent copies of isEmbedderUnreachable into one\nshared, broadened classifier in embedder-utils.ts.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(knowledge): harden compaction teardown/locking and retry embeddin…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T04:03:40Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "47a8c9e5144fcfacbdcce419be18ca9d76d55a90",
"body": "- ARCHITECTURE.md: stdio capture lives at src/utils/stdio-capture.ts (not a non-existent\n src/tui/utils/); terminal-protocol handling is delegated to @earendil-works/pi-tui.\n HealthCheckService is a Core service; WriterQueue is defined in src/knowledge/.\n completeSimple is re-exported from src/co\n[…]\nhed (npm\n latest is still v0.1.13).\n- AGENT-SKILL.md / skill README: document the knowledge-config subcommand (was undercounted).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: fix architecture/README/skill drift",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T03:19:21Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "0a9da11045eebefce15a3805f33a7d5fb1fa3317",
"body": "The panel hid the coordinator column's token/cost/status by matching \"planning\"/\n\"complexity\" (and \"plan\"/\"coord\" in the sort comparator) against the slice LABEL. In\nquick mode the slice id/label is the query itself, so a query like \"urban planning\nnews\" blanked that column's counters; a researcher'\n[…]\npecialist\") could likewise be mis-sorted into the coordinator's slot. Key both off the\nstable 'coord' slice id. +regression tests.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(tui): identify the coordinator column by slice id, not label text",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T03:19:21Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "496b2376d02b1ca6834a28a3857e6b713fa994f0",
"body": "cleanupResearchServices re-derived config from disk via getConfig(ctx.cwd) instead of\nthe config the run actually resolved, so an SDK caller's options.config override (e.g.\nKNOWLEDGE_STORE_MODE:'none' to stay off the native vector stack, or to enable a store a\nrun wrote to) was ignored during the po\n[…]\nS-rebuild/optimize gate. Thread the\nrun's resolved Config through to cleanupResearchServices; both orchestrators pass\nthis.config.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(orchestration): honor the run's resolved config in post-run cleanup",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T03:19:10Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "461a3238a81657cee70f126481da8ac7a729c78d",
"body": "…eManager on teardown\n\nTwo SDK-lifecycle correctness fixes:\n\n- research_manager_latency_ms was emitted via metrics.observe() AFTER runWithRunRegistry's\n AsyncLocalStorage scope closed, so it fell back to session scope and accumulated unbounded\n across calls in a long-lived process (e.g. a benchmar\n[…]\nch calls shutdown) would resurrect it just to dispose it. Use\n container.tryGet so cleanup only touches an already-live instance.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(sdk): scope run latency to the run registry; don't resurrect Stat…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T03:19:10Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "bfe925e146f6c7b33a06fff8310be757630df747",
"body": "validateAndSanitizeQuery (length bounds, whitespace-only rejection, dangerous-content\ncheck) was enforced only on the pi tool path. The standalone CLI — and the skill\nlauncher that forwards to it — called runDeepResearch directly, so a whitespace-only\nor >100k-char query reached the orchestrator ung\n[…]\npty positional list). cmdResearch now applies the same gate before dispatching,\nexiting 64 with the validation message on failure.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(cli): validate and sanitize the research query on the CLI/skill path",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T03:18:58Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "524abdedda231c4ad306fe4a7a6e8acf605f65c9",
"body": "saveConfig read the per-directory settings registry OUTSIDE the file lock and only\nlocked the write, so two concurrent local writes — e.g. `knowledge-config set` run in\nparallel across several directories — could both read the same pre-change snapshot and\nclobber each other's entry (a lost update). \n[…]\n — all in one critical\nsection. Both write sites (saveConfig local scope and the legacy .pi-research.env\nmigration) go through it.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(config): read-modify-write the project registry under one lock",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T03:18:58Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "f55702504954f22065c27aee5ff5ae84cdce78ab",
"body": "…ped on Windows\n\nOn Windows a global `npm i -g` install resolves `pi-research` to a `.cmd` shim, which\n(post Node CVE-2024-27980) can only be spawned with shell:true. But shell:true routed\nthe untrusted research query through cmd.exe, where an unescaped `&`/`|`/`%VAR%`/`^`\nis a command-injection vec\n[…]\nth\nguidance (set PI_RESEARCH_BIN/PI_RESEARCH_PATH) rather than run unsafely. Non-Windows\nand node-path resolutions are unaffected.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "security(skill-launcher): don't pass the query through cmd.exe unesca…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T03:18:48Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "de05d9904e2cb67b3b2c732227339bdc3717cc1f",
"body": "…ressive-cleanup path exists\n\nThe comment claimed \"The /knowledge-store optimize path can opt into aggressive\ncleanup,\" but no command exposes that — the /knowledge-store pi command is query-only,\nand the sole production caller invokes optimize() with defaults. The\ndeleteUnverified/cleanupOlderThan options are a reserved knob with no wiring today;\nsay so instead of implying a user-facing path that doesn't exist. Comment-only.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(knowledge): correct optimize() comment — no /knowledge-store agg…",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T02:29:53Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "64b234c8e3411377f201a5d0e85a727b69bdb842",
"body": null,
"is_bot": true,
"headline": "chore(ci): regenerate docs/deps.svg (detailed module graph) [skip ci]",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-07-03T00:07:38Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "673c86830064ac76e7b01cd7461c06a37780cb09",
"body": "The level-2/level-3 hard-cap tests still named and asserted the old 60/150 caps\n(loosely, via toBeLessThanOrEqual) while the actual ROUND_HARD_CAP is 45/100. The\nloose bound couldn't catch a regression that raised the cap. Retitle and assert the\nreal 45/100 caps.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "test(planning): tighten stale ROUND_HARD_CAP assertions to the real caps",
"author_name": "Lincoln504",
"author_login": "Lincoln504",
"committed_at": "2026-07-03T00:06:11Z",
"body_truncated": false,
"is_coding_agent": true
}
],
"releases_count": 1,
"commits_last_year": 1196,
"latest_release_at": "2026-07-17T15:04:12Z",
"latest_release_tag": "v1.0.8",
"releases_from_tags": false,
"days_since_last_push": 5,
"active_weeks_last_year": 16,
"days_since_latest_release": 5,
"mean_days_between_releases": null
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": false,
"health_percentage": 42,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "@lincoln504/pi-research",
"exists": true,
"license": "MIT",
"keywords": [
"pi",
"pi-package",
"pi-extension",
"openclaw",
"agent-skill",
"research",
"agent",
"web-search",
"scraping",
"stealth-browser",
"camoufox",
"security",
"stack-exchange"
],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/@lincoln504/pi-research",
"is_deprecated": false,
"latest_version": "1.0.8",
"repository_url": "https://github.com/Lincoln504/pi-research",
"versions_count": 21,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 2031,
"first_published_at": "2026-04-19T05:29:37.230000Z",
"latest_published_at": "2026-07-17T15:14:25.656000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 5
}
]
},
"popularity": {
"forks": 2,
"stars": 20,
"watchers": 0,
"fork_history": {
"days": [
{
"date": "2026-05-05",
"count": 1
},
{
"date": "2026-05-12",
"count": 1
}
],
"complete": true,
"collected": 2,
"total_forks": 2
},
"star_history": null,
"open_issues_and_prs": 0
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": false,
"bootstrap_files": [],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [
"tsconfig.json"
],
"toolchain_manifests": [],
"largest_source_bytes": 57491,
"source_files_sampled": 357,
"oversized_source_files": 0,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"dependencies": {
"manifests": [
"package.json"
],
"advisories": {
"error": null,
"scope": "repository_graph",
"source": "osv",
"findings": [
{
"name": "adm-zip",
"direct": false,
"version": "0.5.17",
"severity": "high",
"ecosystem": "npm",
"cvss_score": 7.5,
"advisory_ids": [
"GHSA-xcpc-8h2w-3j85"
],
"fixed_version": "0.6.0",
"advisory_count": 1,
"oldest_advisory_days": 12
},
{
"name": "brace-expansion",
"direct": false,
"version": "5.0.6",
"severity": "high",
"ecosystem": "npm",
"cvss_score": 7.5,
"advisory_ids": [
"GHSA-3jxr-9vmj-r5cp"
],
"fixed_version": "5.0.7",
"advisory_count": 1,
"oldest_advisory_days": 1
},
{
"name": "fast-uri",
"direct": false,
"version": "3.1.2",
"severity": "high",
"ecosystem": "npm",
"cvss_score": 7.5,
"advisory_ids": [
"GHSA-4c8g-83qw-93j6",
"GHSA-v2hh-gcrm-f6hx"
],
"fixed_version": "4.1.1",
"advisory_count": 2,
"oldest_advisory_days": 1
},
{
"name": "sharp",
"direct": false,
"version": "0.34.5",
"severity": "high",
"ecosystem": "npm",
"cvss_score": 7.3,
"advisory_ids": [
"GHSA-f88m-g3jw-g9cj"
],
"fixed_version": "0.35.0",
"advisory_count": 1,
"oldest_advisory_days": 0
},
{
"name": "protobufjs",
"direct": false,
"version": "7.6.4",
"severity": "moderate",
"ecosystem": "npm",
"cvss_score": 5.3,
"advisory_ids": [
"GHSA-j3f2-48v5-ccww"
],
"fixed_version": "8.6.6",
"advisory_count": 1,
"oldest_advisory_days": 1
}
],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {
"high": 4,
"moderate": 1
},
"advisory_count": 6,
"affected_count": 5,
"assessed_count": 629,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"npm"
],
"dependencies": [
{
"name": "@earendil-works/pi-ai",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": ">=0.80.7 <1"
},
{
"name": "@earendil-works/pi-coding-agent",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": ">=0.80.7 <1"
},
{
"name": "@earendil-works/pi-tui",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": ">=0.80.7 <1"
},
{
"name": "@huggingface/transformers",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "4.2.0"
},
{
"name": "@kreuzberg/html-to-markdown-node",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^3.5.5"
},
{
"name": "@lancedb/lancedb",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "0.29.0"
},
{
"name": "apache-arrow",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "21.1.0"
},
{
"name": "bgutils-js",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^3.2.0"
},
{
"name": "camoufox-js",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^0.10.2"
},
{
"name": "esbuild",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^0.28.1"
},
{
"name": "impit",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "0.13.0"
},
{
"name": "jsdom",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^29.1.1"
},
{
"name": "node-html-markdown",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^2.0.0"
},
{
"name": "pdf-oxide-wasm",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^0.3.70"
},
{
"name": "playwright-core",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "1.60.0"
},
{
"name": "poolifier",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^5.3.2"
},
{
"name": "typebox",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "1.1.38"
},
{
"name": "undici",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^8.6.0"
},
{
"name": "youtubei.js",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^17.2.0"
}
],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "@earendil-works/pi-ai",
"direct": true,
"version": "0.80.7",
"ecosystem": "npm"
},
{
"name": "@earendil-works/pi-coding-agent",
"direct": true,
"version": "0.80.7",
"ecosystem": "npm"
},
{
"name": "@earendil-works/pi-tui",
"direct": true,
"version": "0.80.7",
"ecosystem": "npm"
},
{
"name": "@huggingface/transformers",
"direct": true,
"version": "4.2.0",
"ecosystem": "npm"
},
{
"name": "@kreuzberg/html-to-markdown-node",
"direct": true,
"version": "3.7.2",
"ecosystem": "npm"
},
{
"name": "@lancedb/lancedb",
"direct": true,
"version": "0.29.0",
"ecosystem": "npm"
},
{
"name": "apache-arrow",
"direct": true,
"version": "21.1.0",
"ecosystem": "npm"
},
{
"name": "bgutils-js",
"direct": true,
"version": "3.2.0",
"ecosystem": "npm"
},
{
"name": "camoufox-js",
"direct": true,
"version": "0.10.2",
"ecosystem": "npm"
},
{
"name": "esbuild",
"direct": true,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "impit",
"direct": true,
"version": "0.13.0",
"ecosystem": "npm"
},
{
"name": "jsdom",
"direct": true,
"version": "29.1.1",
"ecosystem": "npm"
},
{
"name": "node-html-markdown",
"direct": true,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "pdf-oxide-wasm",
"direct": true,
"version": "0.3.70",
"ecosystem": "npm"
},
{
"name": "playwright-core",
"direct": true,
"version": "1.60.0",
"ecosystem": "npm"
},
{
"name": "poolifier",
"direct": true,
"version": "5.3.2",
"ecosystem": "npm"
},
{
"name": "typebox",
"direct": true,
"version": "1.1.38",
"ecosystem": "npm"
},
{
"name": "undici",
"direct": true,
"version": "7.28.0",
"ecosystem": "npm"
},
{
"name": "undici",
"direct": true,
"version": "8.5.0",
"ecosystem": "npm"
},
{
"name": "undici",
"direct": true,
"version": "8.6.0",
"ecosystem": "npm"
},
{
"name": "youtubei.js",
"direct": true,
"version": "17.2.0",
"ecosystem": "npm"
},
{
"name": "@anthropic-ai/sdk",
"direct": false,
"version": "0.91.1",
"ecosystem": "npm"
},
{
"name": "@asamuzakjp/css-color",
"direct": false,
"version": "5.1.11",
"ecosystem": "npm"
},
{
"name": "@asamuzakjp/dom-selector",
"direct": false,
"version": "7.1.1",
"ecosystem": "npm"
},
{
"name": "@asamuzakjp/generational-cache",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "@asamuzakjp/nwsapi",
"direct": false,
"version": "2.3.9",
"ecosystem": "npm"
},
{
"name": "@aws-crypto/crc32",
"direct": false,
"version": "5.2.0",
"ecosystem": "npm"
},
{
"name": "@aws-crypto/sha256-browser",
"direct": false,
"version": "5.2.0",
"ecosystem": "npm"
},
{
"name": "@aws-crypto/sha256-js",
"direct": false,
"version": "5.2.0",
"ecosystem": "npm"
},
{
"name": "@aws-crypto/supports-web-crypto",
"direct": false,
"version": "5.2.0",
"ecosystem": "npm"
},
{
"name": "@aws-crypto/util",
"direct": false,
"version": "5.2.0",
"ecosystem": "npm"
},
{
"name": "@aws-sdk/client-bedrock-runtime",
"direct": false,
"version": "3.1048.0",
"ecosystem": "npm"
},
{
"name": "@aws-sdk/core",
"direct": false,
"version": "3.974.11",
"ecosystem": "npm"
},
{
"name": "@aws-sdk/core",
"direct": false,
"version": "3.974.14",
"ecosystem": "npm"
},
{
"name": "@aws-sdk/credential-provider-env",
"direct": false,
"version": "3.972.37",
"ecosystem": "npm"
},
{
"name": "@aws-sdk/credential-provider-env",
"direct": false,
"version": "3.972.40",
"ecosystem": "npm"
},
{
"name": "@aws-sdk/credential-provider-http",
"direct": false,
"version": "3.972.39",
"ecosystem": "npm"
},
{
"name": "@aws-sdk/credential-provider-http",
"direct": false,
"version": "3.972.42",
"ecosystem": "npm"
},
{
"name": "@aws-sdk/credential-provider-ini",
"direct": false,
"version": "3.972.41",
"ecosystem": "npm"
},
{
"name": "@aws-sdk/credential-provider-ini",
"direct": false,
"version": "3.972.44",
"ecosystem": "npm"
},
{
"name": "@aws-sdk/credential-provider-login",
"direct": false,
"version": "3.972.41",
"ecosystem": "npm"
},
{
"name": "@aws-sdk/credential-provider-login",
"direct": false,
"version": "3.972.44",
"ecosystem": "npm"
},
{
"name": "@aws-sdk/credential-provider-node",
"direct": false,
"version": "3.972.42",
"ecosystem": "npm"
},
{
"name": "@aws-sdk/credential-provider-node",
"direct": false,
"version": "3.972.45",
"ecosystem": "npm"
},
{
"name": "@aws-sdk/credential-provider-process",
"direct": false,
"version": "3.972.37",
"ecosystem": "npm"
},
{
"name": "@aws-sdk/credential-provider-process",
"direct": false,
"version": "3.972.40",
"ecosystem": "npm"
},
{
"name": "@aws-sdk/credential-provider-sso",
"direct": false,
"version": "3.972.41",
"ecosystem": "npm"
},
{
"name": "@aws-sdk/credential-provider-sso",
"direct": false,
"version": "3.972.44",
"ecosystem": "npm"
},
{
"name": "@aws-sdk/credential-provider-web-identity",
"direct": false,
"version": "3.972.41",
"ecosystem": "npm"
},
{
"name": "@aws-sdk/credential-provider-web-identity",
"direct": false,
"version": "3.972.44",
"ecosystem": "npm"
},
{
"name": "@aws-sdk/eventstream-handler-node",
"direct": false,
"version": "3.972.16",
"ecosystem": "npm"
},
{
"name": "@aws-sdk/eventstream-handler-node",
"direct": false,
"version": "3.972.17",
"ecosystem": "npm"
},
{
"name": "@aws-sdk/middleware-eventstream",
"direct": false,
"version": "3.972.12",
"ecosystem": "npm"
},
{
"name": "@aws-sdk/middleware-eventstream",
"direct": false,
"version": "3.972.13",
"ecosystem": "npm"
},
{
"name": "@aws-sdk/middleware-websocket",
"direct": false,
"version": "3.972.19",
"ecosystem": "npm"
},
{
"name": "@aws-sdk/middleware-websocket",
"direct": false,
"version": "3.972.22",
"ecosystem": "npm"
},
{
"name": "@aws-sdk/nested-clients",
"direct": false,
"version": "3.997.12",
"ecosystem": "npm"
},
{
"name": "@aws-sdk/nested-clients",
"direct": false,
"version": "3.997.9",
"ecosystem": "npm"
},
{
"name": "@aws-sdk/signature-v4-multi-region",
"direct": false,
"version": "3.996.27",
"ecosystem": "npm"
},
{
"name": "@aws-sdk/signature-v4-multi-region",
"direct": false,
"version": "3.996.29",
"ecosystem": "npm"
},
{
"name": "@aws-sdk/token-providers",
"direct": false,
"version": "3.1048.0",
"ecosystem": "npm"
},
{
"name": "@aws-sdk/token-providers",
"direct": false,
"version": "3.1054.0",
"ecosystem": "npm"
},
{
"name": "@aws-sdk/types",
"direct": false,
"version": "3.973.8",
"ecosystem": "npm"
},
{
"name": "@aws-sdk/types",
"direct": false,
"version": "3.973.9",
"ecosystem": "npm"
},
{
"name": "@aws-sdk/util-locate-window",
"direct": false,
"version": "3.965.5",
"ecosystem": "npm"
},
{
"name": "@aws-sdk/xml-builder",
"direct": false,
"version": "3.972.24",
"ecosystem": "npm"
},
{
"name": "@aws-sdk/xml-builder",
"direct": false,
"version": "3.972.26",
"ecosystem": "npm"
},
{
"name": "@aws/lambda-invoke-store",
"direct": false,
"version": "0.2.4",
"ecosystem": "npm"
},
{
"name": "@babel/helper-string-parser",
"direct": false,
"version": "7.29.7",
"ecosystem": "npm"
},
{
"name": "@babel/helper-validator-identifier",
"direct": false,
"version": "7.29.7",
"ecosystem": "npm"
},
{
"name": "@babel/parser",
"direct": false,
"version": "7.29.7",
"ecosystem": "npm"
},
{
"name": "@babel/runtime",
"direct": false,
"version": "7.29.2",
"ecosystem": "npm"
},
{
"name": "@babel/types",
"direct": false,
"version": "7.29.7",
"ecosystem": "npm"
},
{
"name": "@bcoe/v8-coverage",
"direct": false,
"version": "1.0.2",
"ecosystem": "npm"
},
{
"name": "@bramus/specificity",
"direct": false,
"version": "2.4.2",
"ecosystem": "npm"
},
{
"name": "@bufbuild/protobuf",
"direct": false,
"version": "2.12.1",
"ecosystem": "npm"
},
{
"name": "@csstools/color-helpers",
"direct": false,
"version": "6.1.0",
"ecosystem": "npm"
},
{
"name": "@csstools/css-calc",
"direct": false,
"version": "3.2.1",
"ecosystem": "npm"
},
{
"name": "@csstools/css-color-parser",
"direct": false,
"version": "4.1.9",
"ecosystem": "npm"
},
{
"name": "@csstools/css-parser-algorithms",
"direct": false,
"version": "4.0.0",
"ecosystem": "npm"
},
{
"name": "@csstools/css-syntax-patches-for-csstree",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@csstools/css-tokenizer",
"direct": false,
"version": "4.0.0",
"ecosystem": "npm"
},
{
"name": "@earendil-works/pi-agent-core",
"direct": false,
"version": "0.80.7",
"ecosystem": "npm"
},
{
"name": "@emnapi/core",
"direct": false,
"version": "1.10.0",
"ecosystem": "npm"
},
{
"name": "@emnapi/core",
"direct": false,
"version": "1.11.1",
"ecosystem": "npm"
},
{
"name": "@emnapi/runtime",
"direct": false,
"version": "1.10.0",
"ecosystem": "npm"
},
{
"name": "@emnapi/wasi-threads",
"direct": false,
"version": "1.2.1",
"ecosystem": "npm"
},
{
"name": "@emnapi/wasi-threads",
"direct": false,
"version": "1.2.2",
"ecosystem": "npm"
},
{
"name": "@esbuild/aix-ppc64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/android-arm",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/android-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/android-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/darwin-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/darwin-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/freebsd-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/freebsd-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-arm",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-ia32",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-loong64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-mips64el",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-ppc64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-riscv64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-s390x",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/linux-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/netbsd-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/netbsd-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/openbsd-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/openbsd-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/openharmony-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/sunos-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/win32-arm64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/win32-ia32",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@esbuild/win32-x64",
"direct": false,
"version": "0.28.1",
"ecosystem": "npm"
},
{
"name": "@eslint-community/eslint-utils",
"direct": false,
"version": "4.9.1",
"ecosystem": "npm"
},
{
"name": "@eslint-community/regexpp",
"direct": false,
"version": "4.12.2",
"ecosystem": "npm"
},
{
"name": "@eslint/config-array",
"direct": false,
"version": "0.23.5",
"ecosystem": "npm"
},
{
"name": "@eslint/config-helpers",
"direct": false,
"version": "0.6.0",
"ecosystem": "npm"
},
{
"name": "@eslint/core",
"direct": false,
"version": "1.2.1",
"ecosystem": "npm"
},
{
"name": "@eslint/js",
"direct": false,
"version": "10.0.1",
"ecosystem": "npm"
},
{
"name": "@eslint/object-schema",
"direct": false,
"version": "3.0.5",
"ecosystem": "npm"
},
{
"name": "@eslint/plugin-kit",
"direct": false,
"version": "0.7.1",
"ecosystem": "npm"
},
{
"name": "@exodus/bytes",
"direct": false,
"version": "1.15.1",
"ecosystem": "npm"
},
{
"name": "@google/genai",
"direct": false,
"version": "1.52.0",
"ecosystem": "npm"
},
{
"name": "@huggingface/jinja",
"direct": false,
"version": "0.5.9",
"ecosystem": "npm"
},
{
"name": "@huggingface/tokenizers",
"direct": false,
"version": "0.1.3",
"ecosystem": "npm"
},
{
"name": "@humanfs/core",
"direct": false,
"version": "0.19.1",
"ecosystem": "npm"
},
{
"name": "@humanfs/node",
"direct": false,
"version": "0.16.7",
"ecosystem": "npm"
},
{
"name": "@humanwhocodes/module-importer",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "@humanwhocodes/retry",
"direct": false,
"version": "0.4.3",
"ecosystem": "npm"
},
{
"name": "@img/colour",
"direct": false,
"version": "1.1.0",
"ecosystem": "npm"
},
{
"name": "@img/sharp-darwin-arm64",
"direct": false,
"version": "0.34.5",
"ecosystem": "npm"
},
{
"name": "@img/sharp-darwin-x64",
"direct": false,
"version": "0.34.5",
"ecosystem": "npm"
},
{
"name": "@img/sharp-libvips-darwin-arm64",
"direct": false,
"version": "1.2.4",
"ecosystem": "npm"
},
{
"name": "@img/sharp-libvips-darwin-x64",
"direct": false,
"version": "1.2.4",
"ecosystem": "npm"
},
{
"name": "@img/sharp-libvips-linux-arm",
"direct": false,
"version": "1.2.4",
"ecosystem": "npm"
},
{
"name": "@img/sharp-libvips-linux-arm64",
"direct": false,
"version": "1.2.4",
"ecosystem": "npm"
},
{
"name": "@img/sharp-libvips-linux-ppc64",
"direct": false,
"version": "1.2.4",
"ecosystem": "npm"
},
{
"name": "@img/sharp-libvips-linux-riscv64",
"direct": false,
"version": "1.2.4",
"ecosystem": "npm"
},
{
"name": "@img/sharp-libvips-linux-s390x",
"direct": false,
"version": "1.2.4",
"ecosystem": "npm"
},
{
"name": "@img/sharp-libvips-linux-x64",
"direct": false,
"version": "1.2.4",
"ecosystem": "npm"
},
{
"name": "@img/sharp-libvips-linuxmusl-arm64",
"direct": false,
"version": "1.2.4",
"ecosystem": "npm"
},
{
"name": "@img/sharp-libvips-linuxmusl-x64",
"direct": false,
"version": "1.2.4",
"ecosystem": "npm"
},
{
"name": "@img/sharp-linux-arm",
"direct": false,
"version": "0.34.5",
"ecosystem": "npm"
},
{
"name": "@img/sharp-linux-arm64",
"direct": false,
"version": "0.34.5",
"ecosystem": "npm"
},
{
"name": "@img/sharp-linux-ppc64",
"direct": false,
"version": "0.34.5",
"ecosystem": "npm"
},
{
"name": "@img/sharp-linux-riscv64",
"direct": false,
"version": "0.34.5",
"ecosystem": "npm"
},
{
"name": "@img/sharp-linux-s390x",
"direct": false,
"version": "0.34.5",
"ecosystem": "npm"
},
{
"name": "@img/sharp-linux-x64",
"direct": false,
"version": "0.34.5",
"ecosystem": "npm"
},
{
"name": "@img/sharp-linuxmusl-arm64",
"direct": false,
"version": "0.34.5",
"ecosystem": "npm"
},
{
"name": "@img/sharp-linuxmusl-x64",
"direct": false,
"version": "0.34.5",
"ecosystem": "npm"
},
{
"name": "@img/sharp-wasm32",
"direct": false,
"version": "0.34.5",
"ecosystem": "npm"
},
{
"name": "@img/sharp-win32-arm64",
"direct": false,
"version": "0.34.5",
"ecosystem": "npm"
},
{
"name": "@img/sharp-win32-ia32",
"direct": false,
"version": "0.34.5",
"ecosystem": "npm"
},
{
"name": "@img/sharp-win32-x64",
"direct": false,
"version": "0.34.5",
"ecosystem": "npm"
},
{
"name": "@jridgewell/resolve-uri",
"direct": false,
"version": "3.1.2",
"ecosystem": "npm"
},
{
"name": "@jridgewell/sourcemap-codec",
"direct": false,
"version": "1.5.5",
"ecosystem": "npm"
},
{
"name": "@jridgewell/trace-mapping",
"direct": false,
"version": "0.3.31",
"ecosystem": "npm"
},
{
"name": "@kreuzberg/html-to-markdown-node-darwin-arm64",
"direct": false,
"version": "3.7.2",
"ecosystem": "npm"
},
{
"name": "@kreuzberg/html-to-markdown-node-darwin-x64",
"direct": false,
"version": "3.7.2",
"ecosystem": "npm"
},
{
"name": "@kreuzberg/html-to-markdown-node-linux-arm64-gnu",
"direct": false,
"version": "3.7.2",
"ecosystem": "npm"
},
{
"name": "@kreuzberg/html-to-markdown-node-linux-x64-gnu",
"direct": false,
"version": "3.7.2",
"ecosystem": "npm"
},
{
"name": "@kreuzberg/html-to-markdown-node-win32-arm64-msvc",
"direct": false,
"version": "3.7.2",
"ecosystem": "npm"
},
{
"name": "@kreuzberg/html-to-markdown-node-win32-x64-msvc",
"direct": false,
"version": "3.7.2",
"ecosystem": "npm"
},
{
"name": "@lancedb/lancedb-darwin-arm64",
"direct": false,
"version": "0.29.0",
"ecosystem": "npm"
},
{
"name": "@lancedb/lancedb-linux-arm64-gnu",
"direct": false,
"version": "0.29.0",
"ecosystem": "npm"
},
{
"name": "@lancedb/lancedb-linux-arm64-musl",
"direct": false,
"version": "0.29.0",
"ecosystem": "npm"
},
{
"name": "@lancedb/lancedb-linux-x64-gnu",
"direct": false,
"version": "0.29.0",
"ecosystem": "npm"
},
{
"name": "@lancedb/lancedb-linux-x64-musl",
"direct": false,
"version": "0.29.0",
"ecosystem": "npm"
},
{
"name": "@lancedb/lancedb-win32-arm64-msvc",
"direct": false,
"version": "0.29.0",
"ecosystem": "npm"
},
{
"name": "@lancedb/lancedb-win32-x64-msvc",
"direct": false,
"version": "0.29.0",
"ecosystem": "npm"
},
{
"name": "@mariozechner/clipboard",
"direct": false,
"version": "0.3.9",
"ecosystem": "npm"
},
{
"name": "@mariozechner/clipboard-darwin-arm64",
"direct": false,
"version": "0.3.9",
"ecosystem": "npm"
},
{
"name": "@mariozechner/clipboard-darwin-universal",
"direct": false,
"version": "0.3.9",
"ecosystem": "npm"
},
{
"name": "@mariozechner/clipboard-darwin-x64",
"direct": false,
"version": "0.3.9",
"ecosystem": "npm"
},
{
"name": "@mariozechner/clipboard-linux-arm64-gnu",
"direct": false,
"version": "0.3.9",
"ecosystem": "npm"
},
{
"name": "@mariozechner/clipboard-linux-arm64-musl",
"direct": false,
"version": "0.3.9",
"ecosystem": "npm"
},
{
"name": "@mariozechner/clipboard-linux-riscv64-gnu",
"direct": false,
"version": "0.3.9",
"ecosystem": "npm"
},
{
"name": "@mariozechner/clipboard-linux-x64-gnu",
"direct": false,
"version": "0.3.9",
"ecosystem": "npm"
},
{
"name": "@mariozechner/clipboard-linux-x64-musl",
"direct": false,
"version": "0.3.9",
"ecosystem": "npm"
},
{
"name": "@mariozechner/clipboard-win32-arm64-msvc",
"direct": false,
"version": "0.3.9",
"ecosystem": "npm"
},
{
"name": "@mariozechner/clipboard-win32-x64-msvc",
"direct": false,
"version": "0.3.9",
"ecosystem": "npm"
},
{
"name": "@mistralai/mistralai",
"direct": false,
"version": "2.2.6",
"ecosystem": "npm"
},
{
"name": "@napi-rs/wasm-runtime",
"direct": false,
"version": "1.1.5",
"ecosystem": "npm"
},
{
"name": "@nodable/entities",
"direct": false,
"version": "2.1.0",
"ecosystem": "npm"
},
{
"name": "@nolyfill/domexception",
"direct": false,
"version": "1.0.28",
"ecosystem": "npm"
},
{
"name": "@opentelemetry/api",
"direct": false,
"version": "1.9.0",
"ecosystem": "npm"
},
{
"name": "@opentelemetry/semantic-conventions",
"direct": false,
"version": "1.41.1",
"ecosystem": "npm"
},
{
"name": "@oxc-project/types",
"direct": false,
"version": "0.133.0",
"ecosystem": "npm"
},
{
"name": "@protobufjs/aspromise",
"direct": false,
"version": "1.1.2",
"ecosystem": "npm"
},
{
"name": "@protobufjs/base64",
"direct": false,
"version": "1.1.2",
"ecosystem": "npm"
},
{
"name": "@protobufjs/codegen",
"direct": false,
"version": "2.0.5",
"ecosystem": "npm"
},
{
"name": "@protobufjs/eventemitter",
"direct": false,
"version": "1.1.1",
"ecosystem": "npm"
},
{
"name": "@protobufjs/fetch",
"direct": false,
"version": "1.1.1",
"ecosystem": "npm"
},
{
"name": "@protobufjs/float",
"direct": false,
"version": "1.0.2",
"ecosystem": "npm"
},
{
"name": "@protobufjs/path",
"direct": false,
"version": "1.1.2",
"ecosystem": "npm"
},
{
"name": "@protobufjs/pool",
"direct": false,
"version": "1.1.0",
"ecosystem": "npm"
},
{
"name": "@protobufjs/utf8",
"direct": false,
"version": "1.1.1",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-android-arm64",
"direct": false,
"version": "1.0.3",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-darwin-arm64",
"direct": false,
"version": "1.0.3",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-darwin-x64",
"direct": false,
"version": "1.0.3",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-freebsd-x64",
"direct": false,
"version": "1.0.3",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-linux-arm-gnueabihf",
"direct": false,
"version": "1.0.3",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-linux-arm64-gnu",
"direct": false,
"version": "1.0.3",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-linux-arm64-musl",
"direct": false,
"version": "1.0.3",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-linux-ppc64-gnu",
"direct": false,
"version": "1.0.3",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-linux-s390x-gnu",
"direct": false,
"version": "1.0.3",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-linux-x64-gnu",
"direct": false,
"version": "1.0.3",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-linux-x64-musl",
"direct": false,
"version": "1.0.3",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-openharmony-arm64",
"direct": false,
"version": "1.0.3",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-wasm32-wasi",
"direct": false,
"version": "1.0.3",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-win32-arm64-msvc",
"direct": false,
"version": "1.0.3",
"ecosystem": "npm"
},
{
"name": "@rolldown/binding-win32-x64-msvc",
"direct": false,
"version": "1.0.3",
"ecosystem": "npm"
},
{
"name": "@rolldown/pluginutils",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "@silvia-odwyer/photon-node",
"direct": false,
"version": "0.3.4",
"ecosystem": "npm"
},
{
"name": "@sindresorhus/is",
"direct": false,
"version": "4.6.0",
"ecosystem": "npm"
},
{
"name": "@smithy/core",
"direct": false,
"version": "3.24.3",
"ecosystem": "npm"
},
{
"name": "@smithy/core",
"direct": false,
"version": "3.24.4",
"ecosystem": "npm"
},
{
"name": "@smithy/credential-provider-imds",
"direct": false,
"version": "4.3.3",
"ecosystem": "npm"
},
{
"name": "@smithy/credential-provider-imds",
"direct": false,
"version": "4.3.4",
"ecosystem": "npm"
},
{
"name": "@smithy/fetch-http-handler",
"direct": false,
"version": "5.4.3",
"ecosystem": "npm"
},
{
"name": "@smithy/fetch-http-handler",
"direct": false,
"version": "5.4.4",
"ecosystem": "npm"
},
{
"name": "@smithy/is-array-buffer",
"direct": false,
"version": "2.2.0",
"ecosystem": "npm"
},
{
"name": "@smithy/node-http-handler",
"direct": false,
"version": "4.7.3",
"ecosystem": "npm"
},
{
"name": "@smithy/signature-v4",
"direct": false,
"version": "5.4.3",
"ecosystem": "npm"
},
{
"name": "@smithy/signature-v4",
"direct": false,
"version": "5.4.4",
"ecosystem": "npm"
},
{
"name": "@smithy/types",
"direct": false,
"version": "4.14.2",
"ecosystem": "npm"
},
{
"name": "@smithy/util-buffer-from",
"direct": false,
"version": "2.2.0",
"ecosystem": "npm"
},
{
"name": "@smithy/util-utf8",
"direct": false,
"version": "2.3.0",
"ecosystem": "npm"
},
{
"name": "@standard-schema/spec",
"direct": false,
"version": "1.1.0",
"ecosystem": "npm"
},
{
"name": "@swc/helpers",
"direct": false,
"version": "0.5.21",
"ecosystem": "npm"
},
{
"name": "@tybys/wasm-util",
"direct": false,
"version": "0.10.2",
"ecosystem": "npm"
},
{
"name": "@types/chai",
"direct": false,
"version": "5.2.3",
"ecosystem": "npm"
},
{
"name": "@types/command-line-args",
"direct": false,
"version": "5.2.3",
"ecosystem": "npm"
},
{
"name": "@types/command-line-usage",
"direct": false,
"version": "5.0.4",
"ecosystem": "npm"
},
{
"name": "@types/deep-eql",
"direct": false,
"version": "4.0.2",
"ecosystem": "npm"
},
{
"name": "@types/esrecurse",
"direct": false,
"version": "4.3.1",
"ecosystem": "npm"
},
{
"name": "@types/estree",
"direct": false,
"version": "1.0.8",
"ecosystem": "npm"
},
{
"name": "@types/jsdom",
"direct": false,
"version": "28.0.3",
"ecosystem": "npm"
},
{
"name": "@types/json-schema",
"direct": false,
"version": "7.0.15",
"ecosystem": "npm"
},
{
"name": "@types/node",
"direct": false,
"version": "22.19.19",
"ecosystem": "npm"
},
{
"name": "@types/node",
"direct": false,
"version": "24.12.4",
"ecosystem": "npm"
},
{
"name": "@types/node",
"direct": false,
"version": "25.5.2",
"ecosystem": "npm"
},
{
"name": "@types/retry",
"direct": false,
"version": "0.12.0",
"ecosystem": "npm"
},
{
"name": "@types/tough-cookie",
"direct": false,
"version": "4.0.5",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/eslint-plugin",
"direct": false,
"version": "8.60.0",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/parser",
"direct": false,
"version": "8.60.0",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/project-service",
"direct": false,
"version": "8.60.0",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/scope-manager",
"direct": false,
"version": "8.60.0",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/tsconfig-utils",
"direct": false,
"version": "8.60.0",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/type-utils",
"direct": false,
"version": "8.60.0",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/types",
"direct": false,
"version": "8.60.0",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/typescript-estree",
"direct": false,
"version": "8.60.0",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/utils",
"direct": false,
"version": "8.60.0",
"ecosystem": "npm"
},
{
"name": "@typescript-eslint/visitor-keys",
"direct": false,
"version": "8.60.0",
"ecosystem": "npm"
},
{
"name": "@vitest/coverage-v8",
"direct": false,
"version": "4.1.7",
"ecosystem": "npm"
},
{
"name": "@vitest/expect",
"direct": false,
"version": "4.1.7",
"ecosystem": "npm"
},
{
"name": "@vitest/mocker",
"direct": false,
"version": "4.1.7",
"ecosystem": "npm"
},
{
"name": "@vitest/pretty-format",
"direct": false,
"version": "4.1.7",
"ecosystem": "npm"
},
{
"name": "@vitest/runner",
"direct": false,
"version": "4.1.7",
"ecosystem": "npm"
},
{
"name": "@vitest/snapshot",
"direct": false,
"version": "4.1.7",
"ecosystem": "npm"
},
{
"name": "@vitest/spy",
"direct": false,
"version": "4.1.7",
"ecosystem": "npm"
},
{
"name": "@vitest/utils",
"direct": false,
"version": "4.1.7",
"ecosystem": "npm"
},
{
"name": "@webgpu/types",
"direct": false,
"version": "0.1.70",
"ecosystem": "npm"
},
{
"name": "acorn",
"direct": false,
"version": "8.16.0",
"ecosystem": "npm"
},
{
"name": "acorn-jsx",
"direct": false,
"version": "5.3.2",
"ecosystem": "npm"
},
{
"name": "acorn-jsx-walk",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "acorn-loose",
"direct": false,
"version": "8.5.2",
"ecosystem": "npm"
},
{
"name": "acorn-walk",
"direct": false,
"version": "8.3.5",
"ecosystem": "npm"
},
{
"name": "adm-zip",
"direct": false,
"version": "0.5.17",
"ecosystem": "npm"
},
{
"name": "agent-base",
"direct": false,
"version": "7.1.4",
"ecosystem": "npm"
},
{
"name": "ajv",
"direct": false,
"version": "6.14.0",
"ecosystem": "npm"
},
{
"name": "ajv",
"direct": false,
"version": "8.20.0",
"ecosystem": "npm"
},
{
"name": "ansi-regex",
"direct": false,
"version": "5.0.1",
"ecosystem": "npm"
},
{
"name": "ansi-styles",
"direct": false,
"version": "4.3.0",
"ecosystem": "npm"
},
{
"name": "arg",
"direct": false,
"version": "5.0.2",
"ecosystem": "npm"
},
{
"name": "array-back",
"direct": false,
"version": "6.2.3",
"ecosystem": "npm"
},
{
"name": "assertion-error",
"direct": false,
"version": "2.0.1",
"ecosystem": "npm"
},
{
"name": "ast-v8-to-istanbul",
"direct": false,
"version": "1.0.0",
"ecosystem": "npm"
},
{
"name": "astral-regex",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "balanced-match",
"direct": false,
"version": "4.0.4",
"ecosystem": "npm"
},
{
"name": "base64-js",
"direct": false,
"version": "1.5.1",
"ecosystem": "npm"
},
{
"name": "baseline-browser-mapping",
"direct": false,
"version": "2.10.20",
"ecosystem": "npm"
},
{
"name": "better-sqlite3",
"direct": false,
"version": "12.9.0",
"ecosystem": "npm"
},
{
"name": "bidi-js",
"direct": false,
"version": "1.0.3",
"ecosystem": "npm"
},
{
"name": "bignumber.js",
"direct": false,
"version": "9.3.1",
"ecosystem": "npm"
},
{
"name": "bindings",
"direct": false,
"version": "1.5.0",
"ecosystem": "npm"
},
{
"name": "bl",
"direct": false,
"version": "4.1.0",
"ecosystem": "npm"
},
{
"name": "boolbase",
"direct": false,
"version": "1.0.0",
"ecosystem": "npm"
},
{
"name": "boolean",
"direct": false,
"version": "3.2.0",
"ecosystem": "npm"
},
{
"name": "bowser",
"direct": false,
"version": "2.14.1",
"ecosystem": "npm"
},
{
"name": "brace-expansion",
"direct": false,
"version": "5.0.6",
"ecosystem": "npm"
},
{
"name": "browserslist",
"direct": false,
"version": "4.28.2",
"ecosystem": "npm"
},
{
"name": "buffer",
"direct": false,
"version": "5.7.1",
"ecosystem": "npm"
},
{
"name": "buffer-equal-constant-time",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "callsites",
"direct": false,
"version": "3.1.0",
"ecosystem": "npm"
},
{
"name": "caniuse-lite",
"direct": false,
"version": "1.0.30001788",
"ecosystem": "npm"
},
{
"name": "chai",
"direct": false,
"version": "6.2.2",
"ecosystem": "npm"
},
{
"name": "chalk",
"direct": false,
"version": "4.1.2",
"ecosystem": "npm"
},
{
"name": "chalk",
"direct": false,
"version": "5.6.2",
"ecosystem": "npm"
},
{
"name": "chalk-template",
"direct": false,
"version": "0.4.0",
"ecosystem": "npm"
},
{
"name": "chownr",
"direct": false,
"version": "1.1.4",
"ecosystem": "npm"
},
{
"name": "cli-progress",
"direct": false,
"version": "3.12.0",
"ecosystem": "npm"
},
{
"name": "color-convert",
"direct": false,
"version": "2.0.1",
"ecosystem": "npm"
},
{
"name": "color-name",
"direct": false,
"version": "1.1.4",
"ecosystem": "npm"
},
{
"name": "color-support",
"direct": false,
"version": "1.1.3",
"ecosystem": "npm"
},
{
"name": "command-line-args",
"direct": false,
"version": "6.0.2",
"ecosystem": "npm"
},
{
"name": "command-line-usage",
"direct": false,
"version": "7.0.4",
"ecosystem": "npm"
},
{
"name": "commander",
"direct": false,
"version": "14.0.3",
"ecosystem": "npm"
},
{
"name": "compare-versions",
"direct": false,
"version": "5.0.3",
"ecosystem": "npm"
},
{
"name": "convert-source-map",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "cross-spawn",
"direct": false,
"version": "7.0.6",
"ecosystem": "npm"
},
{
"name": "css-select",
"direct": false,
"version": "5.2.2",
"ecosystem": "npm"
},
{
"name": "css-tree",
"direct": false,
"version": "3.2.1",
"ecosystem": "npm"
},
{
"name": "css-what",
"direct": false,
"version": "6.2.2",
"ecosystem": "npm"
},
{
"name": "data-uri-to-buffer",
"direct": false,
"version": "4.0.1",
"ecosystem": "npm"
},
{
"name": "data-urls",
"direct": false,
"version": "7.0.0",
"ecosystem": "npm"
},
{
"name": "debug",
"direct": false,
"version": "4.4.3",
"ecosystem": "npm"
},
{
"name": "decimal.js",
"direct": false,
"version": "10.6.0",
"ecosystem": "npm"
},
{
"name": "decompress-response",
"direct": false,
"version": "6.0.0",
"ecosystem": "npm"
},
{
"name": "deep-extend",
"direct": false,
"version": "0.6.0",
"ecosystem": "npm"
},
{
"name": "deep-is",
"direct": false,
"version": "0.1.4",
"ecosystem": "npm"
},
{
"name": "define-data-property",
"direct": false,
"version": "1.1.4",
"ecosystem": "npm"
},
{
"name": "define-properties",
"direct": false,
"version": "1.2.1",
"ecosystem": "npm"
},
{
"name": "dependency-cruiser",
"direct": false,
"version": "17.4.2",
"ecosystem": "npm"
},
{
"name": "depngn",
"direct": false,
"version": "0.6.0",
"ecosystem": "npm"
},
{
"name": "detect-libc",
"direct": false,
"version": "2.1.2",
"ecosystem": "npm"
},
{
"name": "detect-node",
"direct": false,
"version": "2.1.0",
"ecosystem": "npm"
},
{
"name": "diff",
"direct": false,
"version": "8.0.4",
"ecosystem": "npm"
},
{
"name": "dom-serializer",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "domelementtype",
"direct": false,
"version": "2.3.0",
"ecosystem": "npm"
},
{
"name": "domhandler",
"direct": false,
"version": "5.0.3",
"ecosystem": "npm"
},
{
"name": "domutils",
"direct": false,
"version": "3.2.2",
"ecosystem": "npm"
},
{
"name": "dot-prop",
"direct": false,
"version": "6.0.1",
"ecosystem": "npm"
},
{
"name": "ecdsa-sig-formatter",
"direct": false,
"version": "1.0.11",
"ecosystem": "npm"
},
{
"name": "electron-to-chromium",
"direct": false,
"version": "1.5.342",
"ecosystem": "npm"
},
{
"name": "emoji-regex",
"direct": false,
"version": "8.0.0",
"ecosystem": "npm"
},
{
"name": "end-of-stream",
"direct": false,
"version": "1.4.5",
"ecosystem": "npm"
},
{
"name": "enhanced-resolve",
"direct": false,
"version": "5.22.0",
"ecosystem": "npm"
},
{
"name": "entities",
"direct": false,
"version": "4.5.0",
"ecosystem": "npm"
},
{
"name": "entities",
"direct": false,
"version": "8.0.0",
"ecosystem": "npm"
},
{
"name": "es-define-property",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "es-errors",
"direct": false,
"version": "1.3.0",
"ecosystem": "npm"
},
{
"name": "es-module-lexer",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "es6-error",
"direct": false,
"version": "4.1.1",
"ecosystem": "npm"
},
{
"name": "escalade",
"direct": false,
"version": "3.2.0",
"ecosystem": "npm"
},
{
"name": "escape-string-regexp",
"direct": false,
"version": "4.0.0",
"ecosystem": "npm"
},
{
"name": "eslint",
"direct": false,
"version": "10.4.0",
"ecosystem": "npm"
},
{
"name": "eslint-scope",
"direct": false,
"version": "9.1.2",
"ecosystem": "npm"
},
{
"name": "eslint-visitor-keys",
"direct": false,
"version": "3.4.3",
"ecosystem": "npm"
},
{
"name": "eslint-visitor-keys",
"direct": false,
"version": "5.0.1",
"ecosystem": "npm"
},
{
"name": "espree",
"direct": false,
"version": "11.2.0",
"ecosystem": "npm"
},
{
"name": "esquery",
"direct": false,
"version": "1.7.0",
"ecosystem": "npm"
},
{
"name": "esrecurse",
"direct": false,
"version": "4.3.0",
"ecosystem": "npm"
},
{
"name": "estraverse",
"direct": false,
"version": "5.3.0",
"ecosystem": "npm"
},
{
"name": "estree-walker",
"direct": false,
"version": "3.0.3",
"ecosystem": "npm"
},
{
"name": "esutils",
"direct": false,
"version": "2.0.3",
"ecosystem": "npm"
},
{
"name": "expand-template",
"direct": false,
"version": "2.0.3",
"ecosystem": "npm"
},
{
"name": "expect-type",
"direct": false,
"version": "1.3.0",
"ecosystem": "npm"
},
{
"name": "extend",
"direct": false,
"version": "3.0.2",
"ecosystem": "npm"
},
{
"name": "fancy-log",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "fast-deep-equal",
"direct": false,
"version": "3.1.3",
"ecosystem": "npm"
},
{
"name": "fast-json-stable-stringify",
"direct": false,
"version": "2.1.0",
"ecosystem": "npm"
},
{
"name": "fast-levenshtein",
"direct": false,
"version": "2.0.6",
"ecosystem": "npm"
},
{
"name": "fast-uri",
"direct": false,
"version": "3.1.2",
"ecosystem": "npm"
},
{
"name": "fast-xml-builder",
"direct": false,
"version": "1.2.0",
"ecosystem": "npm"
},
{
"name": "fast-xml-parser",
"direct": false,
"version": "5.7.3",
"ecosystem": "npm"
},
{
"name": "fdir",
"direct": false,
"version": "6.5.0",
"ecosystem": "npm"
},
{
"name": "fetch-blob",
"direct": false,
"version": "3.2.0",
"ecosystem": "npm"
},
{
"name": "fflate",
"direct": false,
"version": "0.8.3",
"ecosystem": "npm"
},
{
"name": "file-entry-cache",
"direct": false,
"version": "8.0.0",
"ecosystem": "npm"
},
{
"name": "file-uri-to-path",
"direct": false,
"version": "1.0.0",
"ecosystem": "npm"
},
{
"name": "find-replace",
"direct": false,
"version": "5.0.2",
"ecosystem": "npm"
},
{
"name": "find-up",
"direct": false,
"version": "5.0.0",
"ecosystem": "npm"
},
{
"name": "fingerprint-generator",
"direct": false,
"version": "2.1.82",
"ecosystem": "npm"
},
{
"name": "flat-cache",
"direct": false,
"version": "4.0.1",
"ecosystem": "npm"
},
{
"name": "flatbuffers",
"direct": false,
"version": "25.9.23",
"ecosystem": "npm"
},
{
"name": "flatted",
"direct": false,
"version": "3.4.2",
"ecosystem": "npm"
},
{
"name": "formdata-polyfill",
"direct": false,
"version": "4.0.10",
"ecosystem": "npm"
},
{
"name": "fs-constants",
"direct": false,
"version": "1.0.0",
"ecosystem": "npm"
},
{
"name": "fsevents",
"direct": false,
"version": "2.3.3",
"ecosystem": "npm"
},
{
"name": "function-bind",
"direct": false,
"version": "1.1.2",
"ecosystem": "npm"
},
{
"name": "gaxios",
"direct": false,
"version": "7.1.4",
"ecosystem": "npm"
},
{
"name": "gcp-metadata",
"direct": false,
"version": "8.1.2",
"ecosystem": "npm"
},
{
"name": "generative-bayesian-network",
"direct": false,
"version": "2.1.82",
"ecosystem": "npm"
},
{
"name": "get-east-asian-width",
"direct": false,
"version": "1.6.0",
"ecosystem": "npm"
},
{
"name": "github-from-package",
"direct": false,
"version": "0.0.0",
"ecosystem": "npm"
},
{
"name": "glob",
"direct": false,
"version": "13.0.6",
"ecosystem": "npm"
},
{
"name": "glob-parent",
"direct": false,
"version": "6.0.2",
"ecosystem": "npm"
},
{
"name": "global-agent",
"direct": false,
"version": "3.0.0",
"ecosystem": "npm"
},
{
"name": "global-directory",
"direct": false,
"version": "4.0.1",
"ecosystem": "npm"
},
{
"name": "globalthis",
"direct": false,
"version": "1.0.4",
"ecosystem": "npm"
},
{
"name": "google-auth-library",
"direct": false,
"version": "10.6.2",
"ecosystem": "npm"
},
{
"name": "google-logging-utils",
"direct": false,
"version": "1.1.3",
"ecosystem": "npm"
},
{
"name": "gopd",
"direct": false,
"version": "1.2.0",
"ecosystem": "npm"
},
{
"name": "graceful-fs",
"direct": false,
"version": "4.2.11",
"ecosystem": "npm"
},
{
"name": "guid-typescript",
"direct": false,
"version": "1.0.9",
"ecosystem": "npm"
},
{
"name": "has-flag",
"direct": false,
"version": "4.0.0",
"ecosystem": "npm"
},
{
"name": "has-property-descriptors",
"direct": false,
"version": "1.0.2",
"ecosystem": "npm"
},
{
"name": "hasown",
"direct": false,
"version": "2.0.3",
"ecosystem": "npm"
},
{
"name": "he",
"direct": false,
"version": "1.2.0",
"ecosystem": "npm"
},
{
"name": "header-generator",
"direct": false,
"version": "2.1.82",
"ecosystem": "npm"
},
{
"name": "highlight.js",
"direct": false,
"version": "10.7.3",
"ecosystem": "npm"
},
{
"name": "hosted-git-info",
"direct": false,
"version": "9.0.3",
"ecosystem": "npm"
},
{
"name": "html-encoding-sniffer",
"direct": false,
"version": "6.0.0",
"ecosystem": "npm"
},
{
"name": "html-escaper",
"direct": false,
"version": "2.0.2",
"ecosystem": "npm"
},
{
"name": "http-proxy-agent",
"direct": false,
"version": "7.0.2",
"ecosystem": "npm"
},
{
"name": "https-proxy-agent",
"direct": false,
"version": "7.0.6",
"ecosystem": "npm"
},
{
"name": "ieee754",
"direct": false,
"version": "1.2.1",
"ecosystem": "npm"
},
{
"name": "ignore",
"direct": false,
"version": "5.3.2",
"ecosystem": "npm"
},
{
"name": "ignore",
"direct": false,
"version": "7.0.5",
"ecosystem": "npm"
},
{
"name": "impit-darwin-arm64",
"direct": false,
"version": "0.13.0",
"ecosystem": "npm"
},
{
"name": "impit-darwin-x64",
"direct": false,
"version": "0.13.0",
"ecosystem": "npm"
},
{
"name": "impit-linux-arm64-gnu",
"direct": false,
"version": "0.13.0",
"ecosystem": "npm"
},
{
"name": "impit-linux-arm64-musl",
"direct": false,
"version": "0.13.0",
"ecosystem": "npm"
},
{
"name": "impit-linux-x64-gnu",
"direct": false,
"version": "0.13.0",
"ecosystem": "npm"
},
{
"name": "impit-linux-x64-musl",
"direct": false,
"version": "0.13.0",
"ecosystem": "npm"
},
{
"name": "impit-win32-arm64-msvc",
"direct": false,
"version": "0.13.0",
"ecosystem": "npm"
},
{
"name": "impit-win32-x64-msvc",
"direct": false,
"version": "0.13.0",
"ecosystem": "npm"
},
{
"name": "imurmurhash",
"direct": false,
"version": "0.1.4",
"ecosystem": "npm"
},
{
"name": "inherits",
"direct": false,
"version": "2.0.4",
"ecosystem": "npm"
},
{
"name": "ini",
"direct": false,
"version": "1.3.8",
"ecosystem": "npm"
},
{
"name": "ini",
"direct": false,
"version": "4.1.1",
"ecosystem": "npm"
},
{
"name": "interpret",
"direct": false,
"version": "3.1.1",
"ecosystem": "npm"
},
{
"name": "is-core-module",
"direct": false,
"version": "2.16.2",
"ecosystem": "npm"
},
{
"name": "is-extglob",
"direct": false,
"version": "2.1.1",
"ecosystem": "npm"
},
{
"name": "is-fullwidth-code-point",
"direct": false,
"version": "3.0.0",
"ecosystem": "npm"
},
{
"name": "is-glob",
"direct": false,
"version": "4.0.3",
"ecosystem": "npm"
},
{
"name": "is-installed-globally",
"direct": false,
"version": "1.0.0",
"ecosystem": "npm"
},
{
"name": "is-obj",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "is-path-inside",
"direct": false,
"version": "4.0.0",
"ecosystem": "npm"
},
{
"name": "is-potential-custom-element-name",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "isexe",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "istanbul-lib-coverage",
"direct": false,
"version": "3.2.2",
"ecosystem": "npm"
},
{
"name": "istanbul-lib-report",
"direct": false,
"version": "3.0.1",
"ecosystem": "npm"
},
{
"name": "istanbul-reports",
"direct": false,
"version": "3.2.0",
"ecosystem": "npm"
},
{
"name": "jiti",
"direct": false,
"version": "2.7.0",
"ecosystem": "npm"
},
{
"name": "js-tokens",
"direct": false,
"version": "10.0.0",
"ecosystem": "npm"
},
{
"name": "json-bigint",
"direct": false,
"version": "1.0.0",
"ecosystem": "npm"
},
{
"name": "json-bignum",
"direct": false,
"version": "0.0.3",
"ecosystem": "npm"
},
{
"name": "json-buffer",
"direct": false,
"version": "3.0.1",
"ecosystem": "npm"
},
{
"name": "json-schema-to-ts",
"direct": false,
"version": "3.1.1",
"ecosystem": "npm"
},
{
"name": "json-schema-traverse",
"direct": false,
"version": "0.4.1",
"ecosystem": "npm"
},
{
"name": "json-schema-traverse",
"direct": false,
"version": "1.0.0",
"ecosystem": "npm"
},
{
"name": "json-stable-stringify-without-jsonify",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "json-stringify-safe",
"direct": false,
"version": "5.0.1",
"ecosystem": "npm"
},
{
"name": "json5",
"direct": false,
"version": "2.2.3",
"ecosystem": "npm"
},
{
"name": "jwa",
"direct": false,
"version": "2.0.1",
"ecosystem": "npm"
},
{
"name": "jws",
"direct": false,
"version": "4.0.1",
"ecosystem": "npm"
},
{
"name": "keyv",
"direct": false,
"version": "4.5.4",
"ecosystem": "npm"
},
{
"name": "kleur",
"direct": false,
"version": "3.0.3",
"ecosystem": "npm"
},
{
"name": "kleur",
"direct": false,
"version": "4.1.5",
"ecosystem": "npm"
},
{
"name": "language-subtag-registry",
"direct": false,
"version": "0.3.23",
"ecosystem": "npm"
},
{
"name": "language-tags",
"direct": false,
"version": "2.1.0",
"ecosystem": "npm"
},
{
"name": "levn",
"direct": false,
"version": "0.4.1",
"ecosystem": "npm"
},
{
"name": "lightningcss",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-android-arm64",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-darwin-arm64",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-darwin-x64",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-freebsd-x64",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-linux-arm-gnueabihf",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-linux-arm64-gnu",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-linux-arm64-musl",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-linux-x64-gnu",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-linux-x64-musl",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-win32-arm64-msvc",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "lightningcss-win32-x64-msvc",
"direct": false,
"version": "1.32.0",
"ecosystem": "npm"
},
{
"name": "locate-path",
"direct": false,
"version": "6.0.0",
"ecosystem": "npm"
},
{
"name": "lodash.camelcase",
"direct": false,
"version": "4.3.0",
"ecosystem": "npm"
},
{
"name": "lodash.truncate",
"direct": false,
"version": "4.4.2",
"ecosystem": "npm"
},
{
"name": "long",
"direct": false,
"version": "5.3.2",
"ecosystem": "npm"
},
{
"name": "lru-cache",
"direct": false,
"version": "11.4.0",
"ecosystem": "npm"
},
{
"name": "lru-cache",
"direct": false,
"version": "11.5.1",
"ecosystem": "npm"
},
{
"name": "magic-string",
"direct": false,
"version": "0.30.21",
"ecosystem": "npm"
},
{
"name": "magicast",
"direct": false,
"version": "0.5.2",
"ecosystem": "npm"
},
{
"name": "make-dir",
"direct": false,
"version": "4.0.0",
"ecosystem": "npm"
},
{
"name": "marked",
"direct": false,
"version": "18.0.5",
"ecosystem": "npm"
},
{
"name": "matcher",
"direct": false,
"version": "3.0.0",
"ecosystem": "npm"
},
{
"name": "maxmind",
"direct": false,
"version": "5.0.6",
"ecosystem": "npm"
},
{
"name": "mdn-data",
"direct": false,
"version": "2.27.1",
"ecosystem": "npm"
},
{
"name": "meriyah",
"direct": false,
"version": "6.1.4",
"ecosystem": "npm"
},
{
"name": "mimic-response",
"direct": false,
"version": "3.1.0",
"ecosystem": "npm"
},
{
"name": "minimatch",
"direct": false,
"version": "10.2.5",
"ecosystem": "npm"
},
{
"name": "minimist",
"direct": false,
"version": "1.2.8",
"ecosystem": "npm"
},
{
"name": "minipass",
"direct": false,
"version": "7.1.3",
"ecosystem": "npm"
},
{
"name": "mkdirp-classic",
"direct": false,
"version": "0.5.3",
"ecosystem": "npm"
},
{
"name": "mmdb-lib",
"direct": false,
"version": "3.0.2",
"ecosystem": "npm"
},
{
"name": "ms",
"direct": false,
"version": "2.1.3",
"ecosystem": "npm"
},
{
"name": "nanoid",
"direct": false,
"version": "3.3.12",
"ecosystem": "npm"
},
{
"name": "napi-build-utils",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "natural-compare",
"direct": false,
"version": "1.4.0",
"ecosystem": "npm"
},
{
"name": "node-abi",
"direct": false,
"version": "3.89.0",
"ecosystem": "npm"
},
{
"name": "node-domexception",
"direct": false,
"version": "1.0.0",
"ecosystem": "npm"
},
{
"name": "node-fetch",
"direct": false,
"version": "3.3.2",
"ecosystem": "npm"
},
{
"name": "node-html-parser",
"direct": false,
"version": "6.1.13",
"ecosystem": "npm"
},
{
"name": "node-releases",
"direct": false,
"version": "2.0.37",
"ecosystem": "npm"
},
{
"name": "npm-check-updates",
"direct": false,
"version": "22.2.1",
"ecosystem": "npm"
},
{
"name": "nth-check",
"direct": false,
"version": "2.1.1",
"ecosystem": "npm"
},
{
"name": "object-keys",
"direct": false,
"version": "1.1.1",
"ecosystem": "npm"
},
{
"name": "obug",
"direct": false,
"version": "2.1.1",
"ecosystem": "npm"
},
{
"name": "once",
"direct": false,
"version": "1.4.0",
"ecosystem": "npm"
},
{
"name": "onnxruntime-common",
"direct": false,
"version": "1.24.3",
"ecosystem": "npm"
},
{
"name": "onnxruntime-node",
"direct": false,
"version": "1.24.3",
"ecosystem": "npm"
},
{
"name": "onnxruntime-web",
"direct": false,
"version": "1.24.3",
"ecosystem": "npm"
},
{
"name": "openai",
"direct": false,
"version": "6.26.0",
"ecosystem": "npm"
},
{
"name": "optionator",
"direct": false,
"version": "0.9.4",
"ecosystem": "npm"
},
{
"name": "ow",
"direct": false,
"version": "0.28.2",
"ecosystem": "npm"
},
{
"name": "p-limit",
"direct": false,
"version": "3.1.0",
"ecosystem": "npm"
},
{
"name": "p-locate",
"direct": false,
"version": "5.0.0",
"ecosystem": "npm"
},
{
"name": "p-retry",
"direct": false,
"version": "4.6.2",
"ecosystem": "npm"
},
{
"name": "parse5",
"direct": false,
"version": "8.0.1",
"ecosystem": "npm"
},
{
"name": "partial-json",
"direct": false,
"version": "0.1.7",
"ecosystem": "npm"
},
{
"name": "path-exists",
"direct": false,
"version": "4.0.0",
"ecosystem": "npm"
},
{
"name": "path-expression-matcher",
"direct": false,
"version": "1.5.0",
"ecosystem": "npm"
},
{
"name": "path-key",
"direct": false,
"version": "3.1.1",
"ecosystem": "npm"
},
{
"name": "path-parse",
"direct": false,
"version": "1.0.7",
"ecosystem": "npm"
},
{
"name": "path-scurry",
"direct": false,
"version": "2.0.2",
"ecosystem": "npm"
},
{
"name": "pathe",
"direct": false,
"version": "2.0.3",
"ecosystem": "npm"
},
{
"name": "picocolors",
"direct": false,
"version": "1.1.1",
"ecosystem": "npm"
},
{
"name": "picomatch",
"direct": false,
"version": "4.0.4",
"ecosystem": "npm"
},
{
"name": "platform",
"direct": false,
"version": "1.3.6",
"ecosystem": "npm"
},
{
"name": "postcss",
"direct": false,
"version": "8.5.15",
"ecosystem": "npm"
},
{
"name": "prebuild-install",
"direct": false,
"version": "7.1.3",
"ecosystem": "npm"
},
{
"name": "prelude-ls",
"direct": false,
"version": "1.2.1",
"ecosystem": "npm"
},
{
"name": "pretty-bytes",
"direct": false,
"version": "7.1.0",
"ecosystem": "npm"
},
{
"name": "prompts",
"direct": false,
"version": "2.4.2",
"ecosystem": "npm"
},
{
"name": "proper-lockfile",
"direct": false,
"version": "4.1.2",
"ecosystem": "npm"
},
{
"name": "protobufjs",
"direct": false,
"version": "7.6.4",
"ecosystem": "npm"
},
{
"name": "pump",
"direct": false,
"version": "3.0.4",
"ecosystem": "npm"
},
{
"name": "punycode",
"direct": false,
"version": "2.3.1",
"ecosystem": "npm"
},
{
"name": "rc",
"direct": false,
"version": "1.2.8",
"ecosystem": "npm"
},
{
"name": "readable-stream",
"direct": false,
"version": "3.6.2",
"ecosystem": "npm"
},
{
"name": "rechoir",
"direct": false,
"version": "0.8.0",
"ecosystem": "npm"
},
{
"name": "reflect-metadata",
"direct": false,
"version": "0.2.2",
"ecosystem": "npm"
},
{
"name": "regexp-tree",
"direct": false,
"version": "0.1.27",
"ecosystem": "npm"
},
{
"name": "require-from-string",
"direct": false,
"version": "2.0.2",
"ecosystem": "npm"
},
{
"name": "resolve",
"direct": false,
"version": "1.22.12",
"ecosystem": "npm"
},
{
"name": "retry",
"direct": false,
"version": "0.12.0",
"ecosystem": "npm"
},
{
"name": "retry",
"direct": false,
"version": "0.13.1",
"ecosystem": "npm"
},
{
"name": "roarr",
"direct": false,
"version": "2.15.4",
"ecosystem": "npm"
},
{
"name": "rolldown",
"direct": false,
"version": "1.0.3",
"ecosystem": "npm"
},
{
"name": "safe-buffer",
"direct": false,
"version": "5.2.1",
"ecosystem": "npm"
},
{
"name": "safe-regex",
"direct": false,
"version": "2.1.1",
"ecosystem": "npm"
},
{
"name": "sax",
"direct": false,
"version": "1.6.0",
"ecosystem": "npm"
},
{
"name": "saxes",
"direct": false,
"version": "6.0.0",
"ecosystem": "npm"
},
{
"name": "semver",
"direct": false,
"version": "7.8.0",
"ecosystem": "npm"
},
{
"name": "semver",
"direct": false,
"version": "7.8.1",
"ecosystem": "npm"
},
{
"name": "semver-compare",
"direct": false,
"version": "1.0.0",
"ecosystem": "npm"
},
{
"name": "serialize-error",
"direct": false,
"version": "7.0.1",
"ecosystem": "npm"
},
{
"name": "sharp",
"direct": false,
"version": "0.34.5",
"ecosystem": "npm"
},
{
"name": "shebang-command",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "shebang-regex",
"direct": false,
"version": "3.0.0",
"ecosystem": "npm"
},
{
"name": "siginfo",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "signal-exit",
"direct": false,
"version": "3.0.7",
"ecosystem": "npm"
},
{
"name": "simple-concat",
"direct": false,
"version": "1.0.1",
"ecosystem": "npm"
},
{
"name": "simple-get",
"direct": false,
"version": "4.0.1",
"ecosystem": "npm"
},
{
"name": "sisteransi",
"direct": false,
"version": "1.0.5",
"ecosystem": "npm"
},
{
"name": "slice-ansi",
"direct": false,
"version": "4.0.0",
"ecosystem": "npm"
},
{
"name": "source-map-js",
"direct": false,
"version": "1.2.1",
"ecosystem": "npm"
},
{
"name": "sprintf-js",
"direct": false,
"version": "1.1.3",
"ecosystem": "npm"
},
{
"name": "stackback",
"direct": false,
"version": "0.0.2",
"ecosystem": "npm"
},
{
"name": "std-env",
"direct": false,
"version": "4.0.0",
"ecosystem": "npm"
},
{
"name": "string-width",
"direct": false,
"version": "4.2.3",
"ecosystem": "npm"
},
{
"name": "string_decoder",
"direct": false,
"version": "1.3.0",
"ecosystem": "npm"
},
{
"name": "strip-ansi",
"direct": false,
"version": "6.0.1",
"ecosystem": "npm"
},
{
"name": "strip-bom",
"direct": false,
"version": "3.0.0",
"ecosystem": "npm"
},
{
"name": "strip-json-comments",
"direct": false,
"version": "2.0.1",
"ecosystem": "npm"
},
{
"name": "strnum",
"direct": false,
"version": "2.3.0",
"ecosystem": "npm"
},
{
"name": "supports-color",
"direct": false,
"version": "7.2.0",
"ecosystem": "npm"
},
{
"name": "supports-preserve-symlinks-flag",
"direct": false,
"version": "1.0.0",
"ecosystem": "npm"
},
{
"name": "symbol-tree",
"direct": false,
"version": "3.2.4",
"ecosystem": "npm"
},
{
"name": "table",
"direct": false,
"version": "6.9.0",
"ecosystem": "npm"
},
{
"name": "table-layout",
"direct": false,
"version": "4.1.1",
"ecosystem": "npm"
},
{
"name": "tapable",
"direct": false,
"version": "2.3.3",
"ecosystem": "npm"
},
{
"name": "tar-fs",
"direct": false,
"version": "2.1.4",
"ecosystem": "npm"
},
{
"name": "tar-stream",
"direct": false,
"version": "2.2.0",
"ecosystem": "npm"
},
{
"name": "tiny-lru",
"direct": false,
"version": "13.0.0",
"ecosystem": "npm"
},
{
"name": "tinybench",
"direct": false,
"version": "2.9.0",
"ecosystem": "npm"
},
{
"name": "tinyexec",
"direct": false,
"version": "1.0.4",
"ecosystem": "npm"
},
{
"name": "tinyglobby",
"direct": false,
"version": "0.2.17",
"ecosystem": "npm"
},
{
"name": "tinyrainbow",
"direct": false,
"version": "3.1.0",
"ecosystem": "npm"
},
{
"name": "tldts",
"direct": false,
"version": "7.4.4",
"ecosystem": "npm"
},
{
"name": "tldts-core",
"direct": false,
"version": "7.4.4",
"ecosystem": "npm"
},
{
"name": "tough-cookie",
"direct": false,
"version": "6.0.1",
"ecosystem": "npm"
},
{
"name": "tr46",
"direct": false,
"version": "6.0.0",
"ecosystem": "npm"
},
{
"name": "ts-algebra",
"direct": false,
"version": "2.0.0",
"ecosystem": "npm"
},
{
"name": "ts-api-utils",
"direct": false,
"version": "2.5.0",
"ecosystem": "npm"
},
{
"name": "tsconfig-paths",
"direct": false,
"version": "4.2.0",
"ecosystem": "npm"
},
{
"name": "tsconfig-paths-webpack-plugin",
"direct": false,
"version": "4.2.0",
"ecosystem": "npm"
},
{
"name": "tslib",
"direct": false,
"version": "2.8.1",
"ecosystem": "npm"
},
{
"name": "tunnel-agent",
"direct": false,
"version": "0.6.0",
"ecosystem": "npm"
},
{
"name": "type-check",
"direct": false,
"version": "0.4.0",
"ecosystem": "npm"
},
{
"name": "type-fest",
"direct": false,
"version": "0.13.1",
"ecosystem": "npm"
},
{
"name": "typescript",
"direct": false,
"version": "6.0.3",
"ecosystem": "npm"
},
{
"name": "typical",
"direct": false,
"version": "7.3.0",
"ecosystem": "npm"
},
{
"name": "ua-parser-js",
"direct": false,
"version": "1.0.41",
"ecosystem": "npm"
},
{
"name": "undici-types",
"direct": false,
"version": "6.21.0",
"ecosystem": "npm"
},
{
"name": "undici-types",
"direct": false,
"version": "7.16.0",
"ecosystem": "npm"
},
{
"name": "undici-types",
"direct": false,
"version": "7.18.2",
"ecosystem": "npm"
},
{
"name": "undici-types",
"direct": false,
"version": "7.28.0",
"ecosystem": "npm"
},
{
"name": "update-browserslist-db",
"direct": false,
"version": "1.2.3",
"ecosystem": "npm"
},
{
"name": "uri-js",
"direct": false,
"version": "4.4.1",
"ecosystem": "npm"
},
{
"name": "util-deprecate",
"direct": false,
"version": "1.0.2",
"ecosystem": "npm"
},
{
"name": "vali-date",
"direct": false,
"version": "1.0.0",
"ecosystem": "npm"
},
{
"name": "vite",
"direct": false,
"version": "8.0.16",
"ecosystem": "npm"
},
{
"name": "vitest",
"direct": false,
"version": "4.1.7",
"ecosystem": "npm"
},
{
"name": "w3c-xmlserializer",
"direct": false,
"version": "5.0.0",
"ecosystem": "npm"
},
{
"name": "watskeburt",
"direct": false,
"version": "5.0.3",
"ecosystem": "npm"
},
{
"name": "web-streams-polyfill",
"direct": false,
"version": "3.3.3",
"ecosystem": "npm"
},
{
"name": "webgpu",
"direct": false,
"version": "0.4.0",
"ecosystem": "npm"
},
{
"name": "webidl-conversions",
"direct": false,
"version": "8.0.1",
"ecosystem": "npm"
},
{
"name": "whatwg-mimetype",
"direct": false,
"version": "5.0.0",
"ecosystem": "npm"
},
{
"name": "whatwg-url",
"direct": false,
"version": "16.0.1",
"ecosystem": "npm"
},
{
"name": "which",
"direct": false,
"version": "2.0.2",
"ecosystem": "npm"
},
{
"name": "why-is-node-running",
"direct": false,
"version": "2.3.0",
"ecosystem": "npm"
},
{
"name": "word-wrap",
"direct": false,
"version": "1.2.5",
"ecosystem": "npm"
},
{
"name": "wordwrapjs",
"direct": false,
"version": "5.1.1",
"ecosystem": "npm"
},
{
"name": "wrappy",
"direct": false,
"version": "1.0.2",
"ecosystem": "npm"
},
{
"name": "ws",
"direct": false,
"version": "8.21.0",
"ecosystem": "npm"
},
{
"name": "xml-name-validator",
"direct": false,
"version": "5.0.0",
"ecosystem": "npm"
},
{
"name": "xml-naming",
"direct": false,
"version": "0.1.0",
"ecosystem": "npm"
},
{
"name": "xml2js",
"direct": false,
"version": "0.6.2",
"ecosystem": "npm"
},
{
"name": "xmlbuilder",
"direct": false,
"version": "11.0.1",
"ecosystem": "npm"
},
{
"name": "xmlchars",
"direct": false,
"version": "2.2.0",
"ecosystem": "npm"
},
{
"name": "yaml",
"direct": false,
"version": "2.9.0",
"ecosystem": "npm"
},
{
"name": "yocto-queue",
"direct": false,
"version": "0.1.0",
"ecosystem": "npm"
},
{
"name": "zod",
"direct": false,
"version": "3.25.76",
"ecosystem": "npm"
},
{
"name": "zod",
"direct": false,
"version": "4.3.6",
"ecosystem": "npm"
},
{
"name": "zod-to-json-schema",
"direct": false,
"version": "3.25.2",
"ecosystem": "npm"
}
],
"collected": true,
"truncated": false,
"total_count": 629,
"direct_count": 21,
"indirect_count": 608
}
},
"maintainership": {
"issues": {
"open_prs": 0,
"merged_prs": 5,
"open_issues": 0,
"closed_ratio": null,
"closed_issues": 0,
"closed_unmerged_prs": 2
},
"bus_factor": 1,
"bot_contributors": 1,
"top_contributors": [
{
"type": "User",
"login": "Lincoln504",
"commits": 1107,
"avatar_url": "https://avatars.githubusercontent.com/u/56658553?v=4"
},
{
"type": "User",
"login": "JustFady",
"commits": 4,
"avatar_url": "https://avatars.githubusercontent.com/u/62950351?v=4"
}
],
"contributors_sampled": 2,
"top_contributor_share": 0.996
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"ci.yml",
"release.yml"
],
"has_docs_dir": true,
"linter_configs": [
"eslint.config.js"
],
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"package-lock.json"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 0,
"reason": "branch protection not enabled on development/release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": null,
"reason": "no pull request found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/30 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 0,
"reason": "project has 0 contributing companies or organizations -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 0,
"reason": "no update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": null,
"reason": "packaging workflow not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 2,
"reason": "dependency not pinned by hash detected -- score normalized to 2",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 10,
"reason": "SAST tool detected: CodeQL",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 0,
"reason": "security policy file not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 10,
"reason": "GitHub workflow tokens follow principle of least privilege",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 4,
"reason": "6 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "873f305df196e6506600fd2443a9452435c86c86",
"ran_at": "2026-07-22T19:55:47Z",
"aggregate_score": 4.9,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": false,
"has_dependabot_config": false
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-17T15:14:29Z",
"oldest_open_prs": [],
"last_merged_pr_at": "2026-05-05T23:04:40Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": []
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/Lincoln504/pi-research",
"host": "github.com",
"name": "pi-research",
"owner": "Lincoln504"
},
"metrics": {
"overall": {
"key": "overall",
"band": "moderate",
"name": "Overall health",
"note": null,
"notes": [],
"value": 60,
"inputs": {
"security": 59,
"vitality": 79,
"community": 40,
"governance": 45,
"engineering": 74
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 79,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "good",
"name": "Development activity",
"note": null,
"notes": [],
"value": 75,
"inputs": {
"commits_last_year": 1196,
"human_commit_share": 0.91,
"days_since_last_push": 5,
"active_weeks_last_year": 16
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 5 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 5
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "16/52 weeks with commits",
"points": 11.1,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 16
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "1196 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 1196
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "good",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 84,
"inputs": {
"releases_count": 1,
"latest_release_tag": "v1.0.8",
"releases_from_tags": false,
"days_since_latest_release": 5,
"mean_days_between_releases": null
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "1 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 1
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 5 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 5
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "cadence unknown (single release)",
"points": 12.6,
"status": "partial",
"details": [
{
"code": "release_cadence_unknown",
"params": {}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "repository_too_young",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "at_risk",
"name": "Community & Adoption",
"value": 40,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "critical",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 21,
"inputs": {
"forks": 2,
"stars": 20,
"watchers": 0,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "20 stars",
"points": 20.7,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 20
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "2 forks",
"points": 0,
"status": "missed",
"details": [
{
"code": "forks",
"params": {
"count": 2
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "0 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 0
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "moderate",
"name": "Community health",
"note": null,
"notes": [],
"value": 50,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": false,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (MIT)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "MIT"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
},
{
"key": "ecosystem_adoption",
"band": "moderate",
"name": "Ecosystem adoption (downloads)",
"note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"registry_dependents"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 55,
"inputs": {
"packages": [
"@lincoln504/pi-research"
],
"dependents": null,
"ecosystems": "npm",
"total_downloads": null,
"monthly_downloads": 2031
},
"components": [
{
"key": "monthly_downloads",
"name": "Monthly downloads",
"detail": "2,031 downloads/month across npm",
"points": 44.1,
"status": "partial",
"details": [
{
"code": "downloads_monthly",
"params": {
"count": 2031,
"ecosystems": "npm"
}
}
],
"max_points": 80
},
{
"key": "registry_dependents",
"name": "Registry dependents",
"detail": "not reported by this ecosystem",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_reported_by_this_ecosystem",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "at_risk",
"name": "Sustainability & Governance",
"value": 45,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 12,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 2,
"top_contributor_share": 0.996
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 100% of commits",
"points": 0.1,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 100
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "2 contributors",
"points": 2.7,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 2
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 0 contributing companies or organizations -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "moderate",
"name": "Issue & PR responsiveness",
"note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"issue_resolution"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 51,
"inputs": {
"merged_prs": 5,
"open_issues": 0,
"closed_issues": 0,
"issue_closed_ratio": null,
"closed_unmerged_prs": 2
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "no issues or no data",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_issues_or_data",
"params": {}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "5/7 decided PRs merged",
"points": 27.3,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 5,
"decided": 7
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "at_risk",
"name": "Ownership & stewardship",
"note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"verified_domain"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 35,
"inputs": {
"followers": 1,
"owner_type": "User",
"is_verified": null,
"owner_login": "Lincoln504",
"public_repos": 2,
"account_age_days": 2470
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "personal (user) account",
"points": 10,
"status": "partial",
"details": [
{
"code": "owner_personal",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": "not applicable to user accounts",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_applicable_to_user_accounts",
"params": {}
}
],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "1 followers of Lincoln504",
"points": 2.2,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 1,
"login": "Lincoln504"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "2 public repos, account ~6 yr old",
"points": 15.5,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 2
}
},
{
"code": "account_age_years",
"params": {
"years": 6
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"@lincoln504/pi-research"
],
"ecosystems": "npm",
"any_deprecated": false,
"min_days_since_publish": 5
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on npm",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "npm"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 5 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 5
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "21 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 21
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "good",
"name": "Engineering Quality",
"value": 74,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "good",
"name": "Engineering practices",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_ci_tests"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 80,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "2 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 2
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": "eslint.config.js",
"points": 16,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "eslint.config.js"
}
}
],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "no pull request found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "moderate",
"name": "Documentation",
"note": null,
"notes": [],
"value": 65,
"inputs": {
"topics": [],
"has_wiki": false,
"homepage": null,
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "moderate",
"name": "Security",
"value": 59,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "at_risk",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): CI-Tests, Packaging, Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"ci_tests",
"packaging",
"signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 49,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 15,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 3,
"scorecard_aggregate": 4.9
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection not enabled on development/release branches",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "no pull request found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 0 contributing companies or organizations -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "no update tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow not detected",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 2",
"points": 1,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool detected: CodeQL",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file not detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "GitHub workflow tokens follow principle of least privilege",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "6 existing vulnerabilities detected",
"points": 3,
"status": "partial",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "excellent",
"name": "Dependency advisories",
"note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 629 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"indirect_dependencies_free_of_known_advisories",
"no_advisories_left_outstanding"
]
}
},
{
"code": "weights_renormalized",
"params": {}
},
{
"code": "advisories_scope_repository",
"params": {
"assessed": 629
}
},
{
"code": "advisories_repo_graph_caveat",
"params": {}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 100,
"inputs": {
"source": "osv",
"advisories": 6,
"affected_packages": 5,
"assessed_packages": 629,
"unassessed_packages": 0,
"affected_by_severity": "high 4, moderate 1",
"direct_affected_packages": 0
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "no direct dependency carries a known advisory",
"points": 35,
"status": "met",
"details": [
{
"code": "no_direct_advisories",
"params": {}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "transitive set not separable from development and test dependencies in this scope",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_scope_not_separable",
"params": {}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "no advisory carries a publication date",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_no_publication_date",
"params": {}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "excellent",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 629,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "moderate",
"name": "AI Readiness",
"value": 63,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "at_risk",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 0.967,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "no CLAUDE.md / AGENTS.md / editor rules",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_instructions",
"params": {}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "88 of 91 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 88,
"sampled": 91
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "moderate",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 66,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"package-lock.json"
],
"has_dockerfile": false,
"typed_language": true,
"bootstrap_files": [],
"has_devcontainer": false,
"has_linter_config": true,
"typecheck_configs": [
"tsconfig.json"
],
"agent_commit_share": 0.28,
"toolchain_manifests": [],
"dependency_bot_commit_share": 0
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": "eslint.config.js",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "eslint.config.js"
}
}
],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "tsconfig.json",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "tsconfig.json"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "28 of the last 100 commits agent-authored or agent-credited",
"points": 10,
"status": "met",
"details": [
{
"code": "agent_authored_commits",
"params": {
"count": 28,
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "no automated dependency updates observed",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_dependency_automation",
"params": {}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 2",
"points": 2,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"primary_language": "TypeScript",
"largest_source_bytes": 57491,
"source_files_sampled": 357,
"oversized_source_files": 0
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "TypeScript (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "TypeScript"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "0/357 source files over 60KB",
"points": 55,
"status": "met",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 357,
"oversized": 0
}
}
],
"max_points": 55
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
"deps.dev does not index npm:@lincoln504/pi-research@1.0.8; advisories assessed against the repository dependency graph instead"
],
"report_type": "repository",
"generated_at": "2026-07-22T19:55:54.501146Z",
"schema_version": "0.26.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/l/Lincoln504/pi-research.svg",
"full_name": "Lincoln504/pi-research",
"license_state": "standard",
"license_spdx": "MIT"
}