, which accepts ANY workflow in the opuspopuli\nrepo that ever obtained a Fulcio cert — over-broad. Pin it to the actual\npublishing workflow so verify only trusts images signed by it.\n\n- Pin the workflow FILE: `.../release\\.\n[…]\ncts a different workflow\n(ci.yml), a spoofed owner/repo, and a tag ref.\n\nAdvisory-only for now (verify); no bootstrap behavior change. Refs #34\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(cosign): ref-pin the signature identity to release.yml", "author_name": "Rodney Gagnon", "author_login": null, "committed_at": "2026-07-08T03:52:54Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "52fa99184f84fd45a58a4e4bf80833ce99c149a9", "body": "…--components--create-op-node\n\nchore(main): release 0.10.16", "is_bot": false, "headline": "Merge pull request #69 from OpusPopuli/release-please--branches--main…", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-08T03:20:50Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "6e36b8e536d959d76b58eaff694b39b8d4d0232e", "body": null, "is_bot": false, "headline": "chore(main): release 0.10.16", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-08T03:18:54Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "2a1d8efe9e348f30b4d3874c6e99945faaef17b1", "body": "fix(init): seed repo secrets via Octokit + libsodium under the PAT", "is_bot": false, "headline": "Merge pull request #68 from OpusPopuli/fix/seed-secrets-via-octokit-32", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-08T03:18:39Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "ec084b945d4c9010b16170eee5d8043402602c07", "body": "Issue #32: repo-secret seeding shelled out to `gh secret set` (ambient gh\nCLI auth), while every sibling init call used the explicit --gh-token PAT\nvia Octokit. A PAT identity that differed from the gh login seeded to the\nwrong account, and the \"PAT-only, may not have gh\" escape hatch the doc\nclaime\n[…]\necryptable (and plaintext-free), public-key-fetch failure,\nmid-batch PUT failure with correct seeded/pending split, malformed slug.\n\nCloses #32\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(init): seed repo secrets via Octokit + libsodium under the PAT", "author_name": "Rodney Gagnon", "author_login": null, "committed_at": "2026-07-08T03:16:56Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "40d0d20b0d98da4211c0019629a2b3396c1d6a20", "body": "…--components--create-op-node\n\nchore(main): release 0.10.15", "is_bot": false, "headline": "Merge pull request #67 from OpusPopuli/release-please--branches--main…", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-08T02:52:16Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "63cbac754e1e77e1809b540ce7613c9a975eeb17", "body": null, "is_bot": false, "headline": "chore(main): release 0.10.15", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-08T02:51:17Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "291ad49d5175078e3a0889e0d19f802df650c186", "body": "…ep-35\n\nfix(polling): check workspace before sleeping in the discovery loop", "is_bot": false, "headline": "Merge pull request #66 from OpusPopuli/fix/discovery-check-before-sle…", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-08T02:51:04Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "4d0da6456bb96fbf78875c4e19e91a2c3aa2e6c1", "body": "waitForApply's discovery loop slept a full poll interval before its first\nfindWorkspace call, so a run that already existed was found one interval\nlate, and with pollMs >= discoveryMs the budget could be spent before a\nuseful check. Move the sleep to the end of the loop body (check, then\nsleep): fin\n[…]\n t=0 without\nsleeping) and the pollMs >= discoveryMs edge case. All existing discovery /\ntimeout / resilience tests pass unchanged.\n\nCloses #35\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(polling): check workspace before sleeping in the discovery loop", "author_name": "Rodney Gagnon", "author_login": null, "committed_at": "2026-07-08T02:49:59Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "932aa74ab008ffca67217374c09b121035eb0e2f", "body": "…--components--create-op-node\n\nchore(main): release 0.10.14", "is_bot": false, "headline": "Merge pull request #65 from OpusPopuli/release-please--branches--main…", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-08T02:42:01Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "4fd8b3855e648ec59982188a489fc8f1cbb9ad95", "body": null, "is_bot": false, "headline": "chore(main): release 0.10.14", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-08T02:40:51Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "52e8fb1b7a6fa6212d3c7d0d4d89e7e5ac86ff87", "body": "fix(ollama): add request timeouts to health + warm probes", "is_bot": false, "headline": "Merge pull request #64 from OpusPopuli/fix/network-timeouts-ollama-31", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-08T02:40:33Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "8d1ff58e5fa2ab7f91ce2310416b340f9b597aac", "body": "Final slice of #31 (Ollama). Both checkOllamaHealth and warmModel already\nhad try/catch (Ollama never crashed), but their fetch calls had no\ntimeout, so a hung daemon (accepts the connection, never responds) would\nstall bootstrap forever.\n\n- checkOllamaHealth: AbortController + 5s timeout — a metada\n[…]\nboth timeouts via fake timers + an abort-aware fetch stub, plus a\nnon-timeout warm failure case so both catch branches are covered.\n\nCloses #31\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(ollama): add request timeouts to health + warm probes", "author_name": "Rodney Gagnon", "author_login": null, "committed_at": "2026-07-08T02:39:07Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "a0094db32a45ba9dd2cae7d03383beaa06c46851", "body": "…--components--create-op-node\n\nchore(main): release 0.10.13", "is_bot": false, "headline": "Merge pull request #63 from OpusPopuli/release-please--branches--main…", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-08T02:30:49Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "ba48de76b3fa61f91be292fbb9d7be5c7c90b9d3", "body": null, "is_bot": false, "headline": "chore(main): release 0.10.13", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-08T02:29:50Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "b4aa09632481f61a77572205eed2fecdd20fa210", "body": "…e-31\n\nfix(cloudflare): add request timeout + degrade network failures gracefully", "is_bot": false, "headline": "Merge pull request #62 from OpusPopuli/fix/network-timeouts-cloudflar…", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-08T02:29:35Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "3075c6a67a6ac485819af31d6eb00ee250a7e17a", "body": "…fully\n\nSecond slice of #31 (Cloudflare), mirroring the TFC fix. The Cloudflare\n`get` helper had no timeout and only wrapped `.json()` in try/catch, so a\nstalled connection could hang `init` (probeCloudflareToken makes 6\nsequential calls) and a transient fetch throw could reject out of the\nwizard.\n\n\n[…]\net to a\nnetwork-error message) + added probeCloudflareToken network-error and\ntimeout-abort (fake timers) cases.\n\nOllama is Subtask 3. Refs #31\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(cloudflare): add request timeout + degrade network failures grace…", "author_name": "Rodney Gagnon", "author_login": null, "committed_at": "2026-07-08T02:26:51Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "7c3840742961a87a4281a93c87bb6bc311c9bd37", "body": "…--components--create-op-node\n\nchore(main): release 0.10.12", "is_bot": false, "headline": "Merge pull request #61 from OpusPopuli/release-please--branches--main…", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-08T01:19:30Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "123314fa53c96fb08261d9c388da48ef11f0c6c3", "body": null, "is_bot": false, "headline": "chore(main): release 0.10.12", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-08T00:53:37Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "7159518eaf98aea1f67b460ff7a472a4ac9f40c2", "body": "fix(tfc): add request timeouts + degrade network failures gracefully", "is_bot": false, "headline": "Merge pull request #60 from OpusPopuli/fix/network-timeouts-31", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-08T00:53:22Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "b9a0aa0cfa043ddc5fece473412905e090cc4634", "body": "First slice of #31 (TFC). Native `fetch` has no default timeout and the\nTFC helpers had no try/catch around the fetch itself, so a stalled\nconnection could hang `init` indefinitely and a transient network throw\ncould reject out of the ~10-minute apply-wait and crash the wizard.\n\n- constants.ts: add \n[…]\n tracks the pre-existing output-missing misdiagnosis on a\ntransient final-output-fetch failure. Cloudflare + Ollama are Subtasks 2/3.\n\nRefs #31\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(tfc): add request timeouts + degrade network failures gracefully", "author_name": "Rodney Gagnon", "author_login": null, "committed_at": "2026-07-08T00:51:36Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "8ee67ee7914d75d74f118f4dc770377fac74026b", "body": "…--components--create-op-node\n\nchore(main): release 0.10.11", "is_bot": false, "headline": "Merge pull request #58 from OpusPopuli/release-please--branches--main…", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-08T00:03:01Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "419a478f2e474223b8a3471d4d898738e3fa8a4c", "body": null, "is_bot": false, "headline": "chore(main): release 0.10.11", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-08T00:01:26Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "5d5913cdbd76c05779b9ef916745c44a73871186", "body": "fix(bootstrap): align llm-model docs + picker hints with actual defaults", "is_bot": false, "headline": "Merge pull request #57 from OpusPopuli/fix/llm-default-consistency-33", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-08T00:01:11Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "c1a24998464064eb0a1bf96483c9446fd1b4077c", "body": "Issue #33 asked to verify the default Ollama tag `qwen3.5:9b`. It is valid\nand pullable (confirmed against the Ollama registry manifest + the official\nQwen3.5 release announcement) — Qwen3.5 shipped after the reviewer's\nknowledge cutoff, and their review environment had the registry blocked,\nwhich i\n[…]\n36–48 GB\" hint (48 GB actually pre-selects\n 32b) to \"\u003c 48 GB\".\n\nNo behavior change; bootstrap.test.ts doesn't assert on hint text.\n\nCloses #33\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(bootstrap): align llm-model docs + picker hints with actual defaults", "author_name": "Rodney Gagnon", "author_login": null, "committed_at": "2026-07-07T23:28:33Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "9f6bf9282926335cb98c6379daae33dad19a3640", "body": "ci(lint): enforce the sonar pass in CI and prepublishOnly", "is_bot": false, "headline": "Merge pull request #56 from OpusPopuli/ci/enforce-sonar-gate-37", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-07T04:00:03Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "cb02cec37dd0964cad2102d0935cbb54d71e5fd4", "body": "Final step of the #37 burndown. All cognitive-complexity findings are\ncleared (58 -> 0), so the second ESLint pass is now turned on as a\nblocking gate:\n\n- ci.yml: add a `Lint (sonar)` step after `Lint (eslint)`\n- package.json: restore `pnpm lint:sonar` to the prepublishOnly chain\n- eslint.sonar.conf\n[…]\nI\" deferral note\n\nThe two-pass ESLint setup (base + sonarjs cognitive-complexity \u003c= 15) now\nmirrors @opuspopuli/regions end to end.\n\nCloses #37\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "ci(lint): enforce the sonar pass in CI and prepublishOnly", "author_name": "Rodney Gagnon", "author_login": null, "committed_at": "2026-07-07T03:58:44Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "23f978ec07257a1b55682d42d6e50a707e424849", "body": "…--components--create-op-node\n\nchore(main): release 0.10.10", "is_bot": false, "headline": "Merge pull request #55 from OpusPopuli/release-please--branches--main…", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-07T03:55:43Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "aabf289e0b6251b091d02c1a03d33a20428a5db7", "body": null, "is_bot": false, "headline": "chore(main): release 0.10.10", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-07T03:55:07Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "3b8b5337d8269729cfb173d18c9bd8c12f9596f0", "body": "refactor(lib): extract helpers to clear remaining complexity findings", "is_bot": false, "headline": "Merge pull request #54 from OpusPopuli/refactor/sonar-lib-cc-37", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-07T03:54:47Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "b5e61671dd4779afe6733f920b7aefb3a3c14a06", "body": "Eighth slice of the #37 burndown — clears the last 7 cognitive-complexity\nfindings across the lib + region command. No behavior change.\n\n- lib/region.ts validateRegionConfig (22): split into 4 sub-validators;\n issue-message order preserved via spread\n- lib/docker.ts waitForHealthy (16) + assessHeal\n[…]\ns, guarding the extractions.\n\nWith this, `pnpm lint:sonar` is green (0 findings) — the CI gate flip is\nthe only remaining step (#37).\n\nRefs #37\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "refactor(lib): extract helpers to clear remaining complexity findings", "author_name": "Rodney Gagnon", "author_login": null, "committed_at": "2026-07-07T03:53:08Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "71f818f11dbc8566d2582b4bb6e20d32dc62c9e7", "body": "…--components--create-op-node\n\nchore(main): release 0.10.9", "is_bot": false, "headline": "Merge pull request #53 from OpusPopuli/release-please--branches--main…", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-07T00:00:20Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "4a7547e55666d8817803b867ea34926d0481a59a", "body": null, "is_bot": false, "headline": "chore(main): release 0.10.9", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-06T22:52:59Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "202b7f926de09f76c6725e36dd55461504328670", "body": "refactor(verify): extract phase helpers to cut handler complexity", "is_bot": false, "headline": "Merge pull request #52 from OpusPopuli/refactor/sonar-verify-cc-37", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-06T22:52:44Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "ea4db7d1b5c825f2321729e16622af430076e67a", "body": "Seventh slice of the #37 burndown — verify had two cognitive-complexity\nfindings: runVerify (28) and the `.action` handler (28). Extract each into\n\u003c=15-CC helpers. No behavior change.\n\nrunVerify -> verifyTlsPhase / verifyHealthPhase / verifyGraphqlPhase /\nverifyCloudflarePhase / verifyCosignPhase. E\n[…]\nhe 17\nrunVerify cases; the action helpers all mix resolution with\np.cancel/process.exit, so there is no fully-pure seam to unit-test.\n\nRefs #37\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "refactor(verify): extract phase helpers to cut handler complexity", "author_name": "Rodney Gagnon", "author_login": null, "committed_at": "2026-07-06T20:01:13Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "bb08a88b0d70a998e38476abf900d9d73ee19d17", "body": "…--components--create-op-node\n\nchore(main): release 0.10.8", "is_bot": false, "headline": "Merge pull request #51 from OpusPopuli/release-please--branches--main…", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-06T15:39:13Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "4b14f4f60e3f824adc27519f0401504c4667dd96", "body": null, "is_bot": false, "headline": "chore(main): release 0.10.8", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-06T15:35:48Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "dadb350bd5bc4cdbd6f03840e07ab58b58331015", "body": "refactor(reset): extract phase helpers to cut handler complexity", "is_bot": false, "headline": "Merge pull request #50 from OpusPopuli/refactor/sonar-reset-cc-37", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-06T15:35:29Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "42804295f4bdd0b9c3e509ad759b3afcbf5628d8", "body": "Sixth slice of the #37 burndown — reset had two cognitive-complexity\nfindings: runReset (36) and the `.action` handler (50). Extract each into\n\u003c=15-CC helpers. No behavior change.\n\nrunReset -> resetStopStackPhase / resetLaunchAgentPhase /\nresetDockerLogoutPhase, each returning a ResetPhase; runReset\n[…]\n default) — mirrors the buildComposeEnv\nprecedent. Full suite 388 green, incl. the 21 existing runReset cases\n(onPhase order intact).\n\nRefs #37\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "refactor(reset): extract phase helpers to cut handler complexity", "author_name": "Rodney Gagnon", "author_login": null, "committed_at": "2026-07-06T14:55:17Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "f61ce1912e082908843633d5c73fe9c2c38f2bca", "body": "…--components--create-op-node\n\nchore(main): release 0.10.7", "is_bot": false, "headline": "Merge pull request #49 from OpusPopuli/release-please--branches--main…", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-06T00:24:54Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "c0d1c11fa1475db080d411de1d9575dd03047242", "body": null, "is_bot": false, "headline": "chore(main): release 0.10.7", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-06T00:23:39Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "cc86886ee7e3df0ee67aacf6287e784a1daba1b9", "body": "refactor(init): extract phase helpers to cut handler complexity", "is_bot": false, "headline": "Merge pull request #48 from OpusPopuli/refactor/sonar-init-cc-37", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-06T00:23:24Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "20b3dba367df1fad265e182dba8417d5b8cee619", "body": "Fifth slice of the #37 burndown — the init `.action` handler was\ncognitive-complexity 71. Extract each phase into its own \u003c=15-CC helper so\nthe handler becomes a ~45-line orchestrator. No behavior change: the\ninteractive prompts, spinners, and process.exit calls are relocated\nverbatim, restructured \n[…]\n interactive I/O; the existing\nsuite already covers the pure seams (summarizePhases,\nlistIgnoredLocalOnlyFlags), which are untouched.\n\nRefs #37\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "refactor(init): extract phase helpers to cut handler complexity", "author_name": "Rodney Gagnon", "author_login": null, "committed_at": "2026-07-06T00:16:26Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "0d85c1fc0e2e5770a4380dbdefb6b6ae4a4e468b", "body": "…--components--create-op-node\n\nchore(main): release 0.10.6", "is_bot": false, "headline": "Merge pull request #47 from OpusPopuli/release-please--branches--main…", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-05T23:52:41Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "64738945053ff60d69af19680a56d03bcc15698e", "body": null, "is_bot": false, "headline": "chore(main): release 0.10.6", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-05T23:51:59Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "d5799dfba567ffa36536f111921e083835407845", "body": "refactor(bootstrap): extract phase helpers to cut handler complexity", "is_bot": false, "headline": "Merge pull request #46 from OpusPopuli/refactor/sonar-bootstrap-cc-37", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-05T23:51:44Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "407caf434a7778ccefa9bb75d625d6f289579274", "body": "Fourth slice of the #37 burndown — the bootstrap `.action` handler was\ncognitive-complexity 85. Extract each phase into its own \u003c=15-CC helper so\nthe handler becomes a ~17-line orchestrator. No behavior change: the\ninteractive prompts, spinners, and process.exit calls are relocated\nverbatim; a Colle\n[…]\nET fallback). The\ninteractive orchestration has no unit tests (it never did) — verified via\ntypecheck, build, and `bootstrap --help`.\n\nRefs #37\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "refactor(bootstrap): extract phase helpers to cut handler complexity", "author_name": "Rodney Gagnon", "author_login": null, "committed_at": "2026-07-05T23:48:24Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "3aba80827900f83899d9a7eb918704164cc6f626", "body": "…--components--create-op-node\n\nchore(main): release 0.10.5", "is_bot": false, "headline": "Merge pull request #45 from OpusPopuli/release-please--branches--main…", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-05T23:18:38Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "4abdd65a1921f674836a17ba8ee11a0496070957", "body": null, "is_bot": false, "headline": "chore(main): release 0.10.5", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-05T23:18:04Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "9b5789ca38ad9bb28afd0ac4e0e13d3944326557", "body": "fix(lint): rewrite super-linear regexes in src", "is_bot": false, "headline": "Merge pull request #44 from OpusPopuli/fix/sonar-regex-backtracking-37", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-05T23:17:51Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "54ab5be40c42cfadd58e07c2824f9737bc81d6c0", "body": null, "is_bot": false, "headline": "Merge branch 'main' into fix/sonar-regex-backtracking-37", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-05T23:17:10Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "ff66176ac4b5e8252380d3afd97c808bb3e7172c", "body": "…--components--create-op-node\n\nchore(main): release 0.10.4", "is_bot": false, "headline": "Merge pull request #43 from OpusPopuli/release-please--branches--main…", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-05T23:16:51Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "84e957343b8afc0a374604a008f6387b4a2e1a14", "body": "Third slice of the #37 burndown — clears the 4 super-linear-regex\nfindings in `src/`, leaving only the 13 cognitive-complexity refactors.\nEach rewrite is backtracking-free and behavior-preserving for real\ninputs, with characterization tests locking the equivalence.\n\n- bootstrap.ts estimatedPullTime:\n[…]\n05b\nsizes) and the slugify edge trim; the existing generatePostgresPassword\n\"no + / =\" assertion already covers the base64url change.\n\nRefs #37\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(lint): rewrite super-linear regexes in src", "author_name": "Rodney Gagnon", "author_login": null, "committed_at": "2026-07-05T23:15:59Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "4e0e0fada6cd3fb476d74c40477b47e7cd54ea7b", "body": null, "is_bot": false, "headline": "chore(main): release 0.10.4", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-05T23:04:09Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "68e892131c6260d7626292ed1f1cdefb45573047", "body": "refactor(lint): clear cheap sonar findings in src", "is_bot": false, "headline": "Merge pull request #42 from OpusPopuli/refactor/sonar-cheap-src-37", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-05T23:03:53Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "845f7fee4ecf763fdbbb5c561245dd788c009932", "body": null, "is_bot": false, "headline": "Merge branch 'main' into refactor/sonar-cheap-src-37", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-05T23:03:17Z", "body_truncated": false, "is_coding_agent": false }, { "oid": "e9cd70224a103a688a2f0e9e4c44232de2b4c926", "body": "test(lint): clear sonar findings in the test suite", "is_bot": false, "headline": "Merge pull request #40 from OpusPopuli/test/sonar-test-findings-37", "author_name": "Rodney Gagnon", "author_login": "rodneygagnon", "committed_at": "2026-07-05T23:03:02Z", "body_truncated": false, "is_coding_agent": false } ], "releases_count": 35, "commits_last_year": 187, "latest_release_at": "2026-07-19T16:13:33Z", "latest_release_tag": "v0.16.0", "releases_from_tags": false, "days_since_last_push": 5, "active_weeks_last_year": 5, "days_since_latest_release": 5, "mean_days_between_releases": 0.9 }, "community": { "has_readme": true, "has_license": true, "has_description": true, "has_contributing": false, "health_percentage": 50, "has_issue_template": false, "has_code_of_conduct": false, "has_pull_request_template": false }, "ecosystem": { "packages": [ { "name": "create-op-node", "exists": true, "license": "AGPL-3.0-or-later", "keywords": [ "opuspopuli", "civic-tech", "federation", "cli", "bootstrap", "mac-studio", "cloudflare-tunnel" ], "ecosystem": "npm", "matches_repo": true, "registry_url": "https://www.npmjs.com/package/create-op-node", "is_deprecated": false, "latest_version": "0.16.0", "repository_url": "https://github.com/OpusPopuli/create-op-node", "versions_count": 44, "total_downloads": null, "dependents_count": null, "deprecation_note": null, "maintainers_count": 1, "monthly_downloads": 5028, "first_published_at": "2026-06-18T01:59:12.555000Z", "latest_published_at": "2026-07-19T16:14:23.712000Z", "latest_version_yanked": null, "days_since_latest_publish": 5 } ] }, "popularity": { "forks": 1, "stars": 0, "watchers": 0, "fork_history": { "days": [ { "date": "2026-07-11", "count": 1 } ], "complete": true, "collected": 1, "total_forks": 1 }, "star_history": { "days": [], "complete": true, "collected": 0, "total_stars": 0, "collected_at": null }, "open_issues_and_prs": 1 }, "ai_readiness": { "has_nix": false, "example_dirs": [], "has_llms_txt": false, "has_dockerfile": false, "has_mcp_signal": false, "bootstrap_files": [], "api_schema_files": [], "has_devcontainer": false, "typecheck_configs": [ "tsconfig.json" ], "toolchain_manifests": [], "largest_source_bytes": 78214, "source_files_sampled": 58, "oversized_source_files": 1, "agent_instruction_files": [], "agent_instruction_max_bytes": null }, "dependencies": { "manifests": [ "package.json" ], "advisories": { "error": null, "scope": "published_package", "source": "osv", "findings": [], "collected": true, "malicious": [], "truncated": false, "by_severity": {}, "advisory_count": 0, "affected_count": 0, "assessed_count": 88, "malicious_count": 0, "assessed_package": "npm:create-op-node@0.16.0", "unassessed_count": 0, "direct_affected_count": 0 }, "ecosystems": [ "npm" ], "dependencies": [ { "name": "@cfworker/json-schema", "manifest": "package.json", "ecosystem": "npm", "version_constraint": "^4.1.1" }, { "name": "@clack/prompts", "manifest": "package.json", "ecosystem": "npm", "version_constraint": "^0.9.0" }, { "name": "@octokit/rest", "manifest": "package.json", "ecosystem": "npm", "version_constraint": "^22.0.0" }, { "name": "cloudflare", "manifest": "package.json", "ecosystem": "npm", "version_constraint": "^4.0.0" }, { "name": "commander", "manifest": "package.json", "ecosystem": "npm", "version_constraint": "^13.1.0" }, { "name": "execa", "manifest": "package.json", "ecosystem": "npm", "version_constraint": "^9.5.2" }, { "name": "libsodium-wrappers", "manifest": "package.json", "ecosystem": "npm", "version_constraint": "^0.8.4" }, { "name": "picocolors", "manifest": "package.json", "ecosystem": "npm", "version_constraint": "^1.1.1" }, { "name": "zod", "manifest": "package.json", "ecosystem": "npm", "version_constraint": "^3.24.1" } ], "all_dependencies": { "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository", "source": null, "packages": [], "collected": false, "truncated": false, "total_count": null, "direct_count": null, "indirect_count": null } }, "maintainership": { "issues": { "open_prs": 0, "merged_prs": 90, "open_issues": 1, "closed_ratio": 0.955, "closed_issues": 21, "closed_unmerged_prs": 2 }, "bus_factor": 1, "bot_contributors": 1, "top_contributors": [ { "type": "User", "login": "rodneygagnon", "commits": 120, "avatar_url": "https://avatars.githubusercontent.com/u/43381472?v=4" }, { "type": "User", "login": "claude", "commits": 2, "avatar_url": "https://avatars.githubusercontent.com/u/81847?v=4" } ], "contributors_sampled": 2, "top_contributor_share": 0.984 }, "quality_signals": { "has_ci": true, "has_tests": true, "ci_workflows": [ "ci.yml", "publish.yml", "release-please.yml" ], "has_docs_dir": false, "linter_configs": [ "eslint.config.mjs" ], "has_editorconfig": false, "has_linter_config": true, "has_precommit_config": false }, "security_signals": { "lockfiles": [ "pnpm-lock.yaml" ], "scorecard": { "checks": [ { "name": "Binary-Artifacts", "score": 10, "reason": "no binaries found in the repo", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts" }, { "name": "Branch-Protection", "score": null, "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection" }, { "name": "CI-Tests", "score": 10, "reason": "25 out of 25 merged PRs checked by a CI test -- score normalized to 10", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests" }, { "name": "CII-Best-Practices", "score": 0, "reason": "no effort to earn an OpenSSF best practices badge detected", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices" }, { "name": "Code-Review", "score": 0, "reason": "Found 0/25 approved changesets -- score normalized to 0", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review" }, { "name": "Contributors", "score": 0, "reason": "project has 0 contributing companies or organizations -- score normalized to 0", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors" }, { "name": "Dangerous-Workflow", "score": 10, "reason": "no dangerous workflow patterns detected", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow" }, { "name": "Dependency-Update-Tool", "score": 0, "reason": "no update tool detected", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool" }, { "name": "Fuzzing", "score": 0, "reason": "project is not fuzzed", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing" }, { "name": "License", "score": 10, "reason": "license file detected", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license" }, { "name": "Maintained", "score": 0, "reason": "project was created within the last 90 days. Please review its contents carefully", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained" }, { "name": "Packaging", "score": 10, "reason": "packaging workflow detected", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging" }, { "name": "Pinned-Dependencies", "score": 7, "reason": "dependency not pinned by hash detected -- score normalized to 7", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies" }, { "name": "SAST", "score": 0, "reason": "SAST tool is not run on all commits -- score normalized to 0", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast" }, { "name": "Security-Policy", "score": 0, "reason": "security policy file not detected", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy" }, { "name": "Signed-Releases", "score": null, "reason": "no releases found", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases" }, { "name": "Token-Permissions", "score": 0, "reason": "detected GitHub workflow tokens with excessive permissions", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions" }, { "name": "Vulnerabilities", "score": 5, "reason": "5 existing vulnerabilities detected", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities" } ], "commit": "0edf6c903b9ada6a3973490465ce0de02856fc09", "ran_at": "2026-07-25T14:28:41Z", "aggregate_score": 3.9, "scorecard_version": "v5.5.0" }, "has_codeql_workflow": false, "has_security_policy": false, "has_dependabot_config": false }, "contribution_flow": { "collected": true, "ci_last_run_at": "2026-07-19T16:14:28Z", "oldest_open_prs": [], "last_merged_pr_at": "2026-07-19T16:13:23Z", "ci_last_conclusion": "SUCCESS", "oldest_open_issues": [ { "number": 114, "created_at": "2026-07-19T16:26:12Z", "last_comment_at": null, "last_comment_author": null } ] } }, "config": { "disabled_metrics": [], "disabled_categories": [], "disabled_components": {} }, "source": { "url": "https://github.com/OpusPopuli/create-op-node", "host": "github.com", "name": "create-op-node", "owner": "OpusPopuli" }, "metrics": { "overall": { "key": "overall", "band": "moderate", "name": "Overall health", "note": null, "notes": [], "value": 58, "inputs": { "security": 51, "vitality": 75, "community": 33, "governance": 54, "engineering": 70 }, "components": [] }, "categories": [ { "key": "vitality", "band": "good", "name": "Vitality", "value": 75, "weight": 0.22, "metrics": [ { "key": "development_activity", "band": "moderate", "name": "Development activity", "note": null, "notes": [], "value": 58, "inputs": { "commits_last_year": 187, "human_commit_share": 1, "days_since_last_push": 5, "active_weeks_last_year": 5 }, "components": [ { "key": "push_recency", "name": "Push recency", "detail": "last push 5 days ago", "points": 36, "status": "met", "details": [ { "code": "push_recency", "params": { "days": 5 } } ], "max_points": 36 }, { "key": "commit_cadence", "name": "Commit cadence", "detail": "5/52 weeks with commits", "points": 3.5, "status": "partial", "details": [ { "code": "commit_cadence_weeks", "params": { "weeks": 5 } } ], "max_points": 36 }, { "key": "commit_volume", "name": "Commit volume", "detail": "187 commits in the last year", "points": 18, "status": "met", "details": [ { "code": "commits_last_year", "params": { "count": 187 } } ], "max_points": 18 }, { "key": "openssf_scorecard_maintained", "name": "OpenSSF Scorecard: Maintained", "detail": "project was created within the last 90 days. Please review its contents carefully", "points": 0, "status": "missed", "details": [], "max_points": 10 } ] }, { "key": "release_discipline", "band": "excellent", "name": "Release discipline", "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.", "notes": [ { "code": "excluded_no_data", "params": { "components": [ "openssf_scorecard_signed_releases" ] } }, { "code": "weights_renormalized", "params": {} } ], "value": 100, "inputs": { "releases_count": 35, "latest_release_tag": "v0.16.0", "releases_from_tags": false, "days_since_latest_release": 5, "mean_days_between_releases": 0.9 }, "components": [ { "key": "ships_releases", "name": "Ships releases", "detail": "35 releases published", "points": 27, "status": "met", "details": [ { "code": "releases_published", "params": { "count": 35 } } ], "max_points": 27 }, { "key": "release_recency", "name": "Release recency", "detail": "latest release 5 days ago", "points": 36, "status": "met", "details": [ { "code": "release_recency", "params": { "days": 5 } } ], "max_points": 36 }, { "key": "release_cadence", "name": "Release cadence", "detail": "a release every ~0.9 days", "points": 27, "status": "met", "details": [ { "code": "release_cadence", "params": { "gap": 0.9 } } ], "max_points": 27 }, { "key": "openssf_scorecard_signed_releases", "name": "OpenSSF Scorecard: Signed-Releases", "detail": "no releases found", "points": 0, "status": "excluded", "details": [ { "code": "no_data", "params": {} } ], "max_points": 10 } ] }, { "key": "abandonment", "band": "excellent", "name": "Abandonment", "note": null, "notes": [], "value": 100, "inputs": { "cap": null, "state": "unverified", "guards": [], "signals": [], "red_flag": false, "multiplier_pct": 100, "declared_reason": null, "unverified_reason": "repository_too_young", "unanswered_open_prs": null, "unanswered_open_issues": null, "days_since_last_merged_pr": null, "days_since_last_human_commit": null, "days_since_last_human_commit_is_floor": false }, "components": [ { "key": "project_is_still_maintained", "name": "Project is still maintained", "detail": "maintenance record not established from the collected data", "points": 100, "status": "met", "details": [ { "code": "abandonment_unverified", "params": {} } ], "max_points": 100 } ] } ], "description": "Is the project alive — is code being written and are releases shipping?" }, { "key": "community", "band": "at_risk", "name": "Community & Adoption", "value": 33, "weight": 0.18, "metrics": [ { "key": "popularity", "band": "critical", "name": "Popularity & adoption", "note": null, "notes": [], "value": 1, "inputs": { "forks": 1, "stars": 0, "watchers": 0, "growth_state": "unverified", "growth_factor_pct": 100, "growth_unverified_reason": "no_history" }, "components": [ { "key": "stars", "name": "Stars", "detail": "0 stars", "points": 0, "status": "missed", "details": [ { "code": "stars", "params": { "count": 0 } } ], "max_points": 60 }, { "key": "forks", "name": "Forks", "detail": "1 forks", "points": 0, "status": "missed", "details": [ { "code": "forks", "params": { "count": 1 } } ], "max_points": 25 }, { "key": "watchers", "name": "Watchers", "detail": "0 watchers", "points": 0, "status": "missed", "details": [ { "code": "watchers", "params": { "count": 0 } } ], "max_points": 15 } ] }, { "key": "community_health", "band": "moderate", "name": "Community health", "note": null, "notes": [], "value": 50, "inputs": { "has_readme": true, "has_license": true, "has_contributing": false, "has_issue_template": false, "has_code_of_conduct": false, "has_pull_request_template": false }, "components": [ { "key": "readme", "name": "README", "detail": null, "points": 22.5, "status": "met", "details": [], "max_points": 22.5 }, { "key": "license", "name": "License", "detail": "recognized license (AGPL-3.0)", "points": 22.5, "status": "met", "details": [ { "code": "license_standard", "params": {} }, { "code": "license_spdx", "params": { "spdx": "AGPL-3.0" } } ], "max_points": 22.5 }, { "key": "contributing_guide", "name": "CONTRIBUTING guide", "detail": null, "points": 0, "status": "missed", "details": [], "max_points": 18 }, { "key": "code_of_conduct", "name": "Code of conduct", "detail": null, "points": 0, "status": "missed", "details": [], "max_points": 13.5 }, { "key": "issue_template", "name": "Issue template", "detail": null, "points": 0, "status": "missed", "details": [], "max_points": 7.2 }, { "key": "pr_template", "name": "PR template", "detail": null, "points": 0, "status": "missed", "details": [], "max_points": 6.3 } ] }, { "key": "ecosystem_adoption", "band": "moderate", "name": "Ecosystem adoption (downloads)", "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.", "notes": [ { "code": "excluded_no_data", "params": { "components": [ "registry_dependents" ] } }, { "code": "weights_renormalized", "params": {} } ], "value": 62, "inputs": { "packages": [ "create-op-node" ], "dependents": null, "ecosystems": "npm", "total_downloads": null, "monthly_downloads": 5028 }, "components": [ { "key": "monthly_downloads", "name": "Monthly downloads", "detail": "5,028 downloads/month across npm", "points": 49.4, "status": "partial", "details": [ { "code": "downloads_monthly", "params": { "count": 5028, "ecosystems": "npm" } } ], "max_points": 80 }, { "key": "registry_dependents", "name": "Registry dependents", "detail": "not reported by this ecosystem", "points": 0, "status": "excluded", "details": [ { "code": "not_reported_by_this_ecosystem", "params": {} } ], "max_points": 20 } ] } ], "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?" }, { "key": "governance", "band": "moderate", "name": "Sustainability & Governance", "value": 54, "weight": 0.24, "metrics": [ { "key": "maintainer_resilience", "band": "critical", "name": "Maintainer resilience (bus factor)", "note": null, "notes": [], "value": 12, "inputs": { "bus_factor": 1, "contributors_sampled": 2, "top_contributor_share": 0.984 }, "components": [ { "key": "bus_factor", "name": "Bus factor", "detail": "1 contributor(s) cover half of all commits", "points": 9, "status": "partial", "details": [ { "code": "bus_factor", "params": { "count": 1 } } ], "max_points": 54 }, { "key": "commit_distribution", "name": "Commit distribution", "detail": "top contributor authored 98% of commits", "points": 0.4, "status": "partial", "details": [ { "code": "top_contributor_share", "params": { "share": 98 } } ], "max_points": 22.5 }, { "key": "contributor_breadth", "name": "Contributor breadth", "detail": "2 contributors", "points": 2.7, "status": "partial", "details": [ { "code": "contributors_sampled", "params": { "count": 2 } } ], "max_points": 13.5 }, { "key": "openssf_scorecard_contributors", "name": "OpenSSF Scorecard: Contributors", "detail": "project has 0 contributing companies or organizations -- score normalized to 0", "points": 0, "status": "missed", "details": [], "max_points": 10 } ] }, { "key": "responsiveness", "band": "good", "name": "Issue & PR responsiveness", "note": null, "notes": [], "value": 82, "inputs": { "merged_prs": 90, "open_issues": 1, "closed_issues": 21, "issue_closed_ratio": 0.955, "closed_unmerged_prs": 2 }, "components": [ { "key": "issue_resolution", "name": "Issue resolution", "detail": "96% of issues closed", "points": 44.6, "status": "partial", "details": [ { "code": "issues_closed_share", "params": { "share": 96 } } ], "max_points": 46.75 }, { "key": "pr_acceptance", "name": "PR acceptance", "detail": "90/92 decided PRs merged", "points": 37.4, "status": "partial", "details": [ { "code": "decided_prs_merged", "params": { "merged": 90, "decided": 92 } } ], "max_points": 38.25 }, { "key": "openssf_scorecard_code_review", "name": "OpenSSF Scorecard: Code-Review", "detail": "Found 0/25 approved changesets -- score normalized to 0", "points": 0, "status": "missed", "details": [], "max_points": 15 } ] }, { "key": "stewardship", "band": "at_risk", "name": "Ownership & stewardship", "note": null, "notes": [], "value": 38, "inputs": { "followers": 0, "owner_type": "Organization", "is_verified": null, "owner_login": "OpusPopuli", "public_repos": 7, "account_age_days": 216 }, "components": [ { "key": "ownership_backing", "name": "Ownership backing", "detail": "organization-owned", "points": 30, "status": "met", "details": [ { "code": "owner_organization", "params": {} } ], "max_points": 30 }, { "key": "verified_domain", "name": "Verified domain", "detail": null, "points": 0, "status": "missed", "details": [], "max_points": 20 }, { "key": "owner_reach", "name": "Owner reach", "detail": "0 followers of OpusPopuli", "points": 0, "status": "missed", "details": [ { "code": "owner_followers", "params": { "count": 0, "login": "OpusPopuli" } } ], "max_points": 25 }, { "key": "track_record", "name": "Track record", "detail": "7 public repos, account ~0 yr old", "points": 7.8, "status": "partial", "details": [ { "code": "public_repos", "params": { "count": 7 } }, { "code": "account_age_years", "params": { "years": 0 } } ], "max_points": 25 } ] }, { "key": "package_maintenance", "band": "excellent", "name": "Package maintenance", "note": null, "notes": [], "value": 100, "inputs": { "packages": [ "create-op-node" ], "ecosystems": "npm", "any_deprecated": false, "min_days_since_publish": 5 }, "components": [ { "key": "published_resolvable", "name": "Published & resolvable", "detail": "1 package(s) on npm", "points": 25, "status": "met", "details": [ { "code": "packages_published", "params": { "count": 1, "ecosystems": "npm" } } ], "max_points": 25 }, { "key": "publish_recency", "name": "Publish recency", "detail": "latest publish 5 days ago", "points": 35, "status": "met", "details": [ { "code": "publish_recency", "params": { "days": 5 } } ], "max_points": 35 }, { "key": "version_history", "name": "Version history", "detail": "44 published versions", "points": 20, "status": "met", "details": [ { "code": "published_versions", "params": { "count": 44 } } ], "max_points": 20 }, { "key": "not_deprecated", "name": "Not deprecated", "detail": "active, not deprecated or yanked", "points": 20, "status": "met", "details": [ { "code": "package_not_deprecated", "params": {} } ], "max_points": 20 } ] } ], "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?" }, { "key": "engineering", "band": "good", "name": "Engineering Quality", "value": 70, "weight": 0.2, "metrics": [ { "key": "engineering_practices", "band": "good", "name": "Engineering practices", "note": null, "notes": [], "value": 84, "inputs": { "has_ci": true, "has_tests": true, "has_editorconfig": false, "has_linter_config": true, "has_precommit_config": false }, "components": [ { "key": "ci_workflows", "name": "CI workflows", "detail": "3 workflow(s)", "points": 24, "status": "met", "details": [ { "code": "ci_workflows", "params": { "count": 3 } } ], "max_points": 24 }, { "key": "tests_present", "name": "Tests present", "detail": null, "points": 24, "status": "met", "details": [], "max_points": 24 }, { "key": "linter_config", "name": "Linter config", "detail": "eslint.config.mjs", "points": 16, "status": "met", "details": [ { "code": "file_list", "params": { "files": "eslint.config.mjs" } } ], "max_points": 16 }, { "key": "pre_commit_hooks", "name": "Pre-commit hooks", "detail": null, "points": 0, "status": "missed", "details": [], "max_points": 9.6 }, { "key": "editorconfig", "name": ".editorconfig", "detail": null, "points": 0, "status": "missed", "details": [], "max_points": 6.4 }, { "key": "openssf_scorecard_ci_tests", "name": "OpenSSF Scorecard: CI-Tests", "detail": "25 out of 25 merged PRs checked by a CI test -- score normalized to 10", "points": 20, "status": "met", "details": [], "max_points": 20 } ] }, { "key": "documentation", "band": "moderate", "name": "Documentation", "note": null, "notes": [], "value": 50, "inputs": { "topics": [], "has_wiki": true, "homepage": null, "has_readme": true, "has_docs_dir": false, "has_description": true }, "components": [ { "key": "readme", "name": "README", "detail": null, "points": 30, "status": "met", "details": [], "max_points": 30 }, { "key": "documentation_directory", "name": "Documentation directory", "detail": null, "points": 0, "status": "missed", "details": [], "max_points": 25 }, { "key": "documentation_homepage_site", "name": "Documentation / homepage site", "detail": null, "points": 0, "status": "missed", "details": [], "max_points": 15 }, { "key": "repository_description", "name": "Repository description", "detail": null, "points": 10, "status": "met", "details": [], "max_points": 10 }, { "key": "topics", "name": "Topics", "detail": null, "points": 0, "status": "missed", "details": [], "max_points": 10 }, { "key": "wiki", "name": "Wiki", "detail": null, "points": 10, "status": "met", "details": [], "max_points": 10 } ] } ], "description": "Are baseline engineering and documentation practices in place?" }, { "key": "security", "band": "moderate", "name": "Security", "value": 51, "weight": 0.16, "metrics": [ { "key": "security_posture", "band": "at_risk", "name": "Security posture", "note": "Excluded from scoring (no data or not applicable): Branch-Protection, Signed-Releases. Remaining weights renormalized.", "notes": [ { "code": "excluded_no_data", "params": { "components": [ "branch_protection", "signed_releases" ] } }, { "code": "weights_renormalized", "params": {} } ], "value": 39, "inputs": { "source": "openssf_scorecard", "checks_evaluated": 16, "scorecard_version": "v5.5.0", "checks_inconclusive": 2, "scorecard_aggregate": 3.9 }, "components": [ { "key": "binary_artifacts", "name": "Binary-Artifacts", "detail": "no binaries found in the repo", "points": 7.5, "status": "met", "details": [], "max_points": 7.5 }, { "key": "branch_protection", "name": "Branch-Protection", "detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md", "points": 0, "status": "excluded", "details": [ { "code": "no_data", "params": {} } ], "max_points": 7.5 }, { "key": "ci_tests", "name": "CI-Tests", "detail": "25 out of 25 merged PRs checked by a CI test -- score normalized to 10", "points": 2.5, "status": "met", "details": [], "max_points": 2.5 }, { "key": "cii_best_practices", "name": "CII-Best-Practices", "detail": "no effort to earn an OpenSSF best practices badge detected", "points": 0, "status": "missed", "details": [], "max_points": 2.5 }, { "key": "code_review", "name": "Code-Review", "detail": "Found 0/25 approved changesets -- score normalized to 0", "points": 0, "status": "missed", "details": [], "max_points": 7.5 }, { "key": "contributors", "name": "Contributors", "detail": "project has 0 contributing companies or organizations -- score normalized to 0", "points": 0, "status": "missed", "details": [], "max_points": 2.5 }, { "key": "dangerous_workflow", "name": "Dangerous-Workflow", "detail": "no dangerous workflow patterns detected", "points": 10, "status": "met", "details": [], "max_points": 10 }, { "key": "dependency_update_tool", "name": "Dependency-Update-Tool", "detail": "no update tool detected", "points": 0, "status": "missed", "details": [], "max_points": 7.5 }, { "key": "fuzzing", "name": "Fuzzing", "detail": "project is not fuzzed", "points": 0, "status": "missed", "details": [], "max_points": 5 }, { "key": "license", "name": "License", "detail": "license file detected", "points": 2.5, "status": "met", "details": [], "max_points": 2.5 }, { "key": "maintained", "name": "Maintained", "detail": "project was created within the last 90 days. Please review its contents carefully", "points": 0, "status": "missed", "details": [], "max_points": 7.5 }, { "key": "packaging", "name": "Packaging", "detail": "packaging workflow detected", "points": 5, "status": "met", "details": [], "max_points": 5 }, { "key": "pinned_dependencies", "name": "Pinned-Dependencies", "detail": "dependency not pinned by hash detected -- score normalized to 7", "points": 3.5, "status": "partial", "details": [], "max_points": 5 }, { "key": "sast", "name": "SAST", "detail": "SAST tool is not run on all commits -- score normalized to 0", "points": 0, "status": "missed", "details": [], "max_points": 5 }, { "key": "security_policy", "name": "Security-Policy", "detail": "security policy file not detected", "points": 0, "status": "missed", "details": [], "max_points": 5 }, { "key": "signed_releases", "name": "Signed-Releases", "detail": "no releases found", "points": 0, "status": "excluded", "details": [ { "code": "no_data", "params": {} } ], "max_points": 7.5 }, { "key": "token_permissions", "name": "Token-Permissions", "detail": "detected GitHub workflow tokens with excessive permissions", "points": 0, "status": "missed", "details": [], "max_points": 7.5 }, { "key": "vulnerabilities", "name": "Vulnerabilities", "detail": "5 existing vulnerabilities detected", "points": 3.8, "status": "partial", "details": [], "max_points": 7.5 } ] }, { "key": "dependency_advisories", "band": "excellent", "name": "Dependency advisories", "note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:create-op-node@0.16.0 runtime dependency closure — what installing the published package pulls in — 88 packages. Reachability is not analyzed.", "notes": [ { "code": "excluded_no_data", "params": { "components": [ "no_advisories_left_outstanding" ] } }, { "code": "weights_renormalized", "params": {} }, { "code": "advisories_scope_published", "params": { "package": "npm:create-op-node@0.16.0", "assessed": 88 } }, { "code": "advisories_reachability", "params": {} } ], "value": 100, "inputs": { "source": "osv", "advisories": 0, "affected_packages": 0, "assessed_packages": 88, "unassessed_packages": 0, "affected_by_severity": "none", "direct_affected_packages": 0 }, "components": [ { "key": "direct_dependencies_free_of_known_advisories", "name": "Direct dependencies free of known advisories", "detail": "no direct dependency carries a known advisory", "points": 35, "status": "met", "details": [ { "code": "no_direct_advisories", "params": {} } ], "max_points": 35 }, { "key": "indirect_dependencies_free_of_known_advisories", "name": "Indirect dependencies free of known advisories", "detail": "no indirect dependency carries a known advisory", "points": 25, "status": "met", "details": [ { "code": "no_indirect_advisories", "params": {} } ], "max_points": 25 }, { "key": "no_advisories_left_outstanding", "name": "No advisories left outstanding", "detail": "no advisory carries a publication date", "points": 0, "status": "excluded", "details": [ { "code": "advisories_no_publication_date", "params": {} } ], "max_points": 40 } ] }, { "key": "malicious_dependencies", "band": "excellent", "name": "Malicious dependencies", "note": null, "notes": [], "value": 100, "inputs": { "source": "osv", "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored", "packages": [], "red_flag": false, "assessed_packages": 88, "malicious_packages": 0, "direct_malicious_packages": 0, "withdrawn_malicious_packages": 0, "installable_malicious_packages": 0 }, "components": [ { "key": "no_dependency_reported_as_a_malicious_package", "name": "No dependency reported as a malicious package", "detail": "no dependency is reported as a malicious package", "points": 100, "status": "met", "details": [ { "code": "no_malicious_dependencies", "params": {} } ], "max_points": 100 } ] }, { "key": "high_risk_jurisdiction_exposure", "band": "excellent", "name": "High-Risk Jurisdiction Exposure", "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.", "notes": [ { "code": "jurisdiction_evidence_limits", "params": {} } ], "value": 100, "inputs": { "meaning": "self-published location evidence; not nationality or citizenship", "red_flag": false, "exposures": [], "policy_countries": [ "Russia", "Iran", "North Korea" ], "review_only_matches": 0, "assessed_self_published_locations": 2 }, "components": [ { "key": "policy_exposure_multiplier", "name": "Policy exposure multiplier", "detail": "no confirmed policy-scope location match", "points": 100, "status": "met", "details": [ { "code": "jurisdiction_no_match", "params": {} } ], "max_points": 100 } ] } ], "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?" }, { "key": "ai_readiness", "band": "moderate", "name": "AI Readiness", "value": 65, "weight": 0, "metrics": [ { "key": "ai_agent_context", "band": "at_risk", "name": "Agent context & guidance", "note": null, "notes": [], "value": 40, "inputs": { "has_llms_txt": false, "legible_history_share": 0.98, "agent_instruction_files": [], "agent_instruction_max_bytes": null }, "components": [ { "key": "agent_instructions", "name": "Agent instructions", "detail": "no CLAUDE.md / AGENTS.md / editor rules", "points": 0, "status": "missed", "details": [ { "code": "no_agent_instructions", "params": {} } ], "max_points": 45 }, { "key": "machine_readable_docs_llms_txt", "name": "Machine-readable docs (llms.txt)", "detail": null, "points": 0, "status": "missed", "details": [], "max_points": 15 }, { "key": "legible_commit_history", "name": "Legible commit history", "detail": "98 of 100 human commits state their intent (structured subject or explanatory body)", "points": 40, "status": "met", "details": [ { "code": "legible_history", "params": { "legible": 98, "sampled": 100 } } ], "max_points": 40 } ] }, { "key": "ai_verify_loop", "band": "good", "name": "Verify loop (build / test / typecheck)", "note": null, "notes": [], "value": 71, "inputs": { "has_nix": false, "has_tests": true, "lockfiles": [ "pnpm-lock.yaml" ], "has_dockerfile": false, "typed_language": true, "bootstrap_files": [], "has_devcontainer": false, "has_linter_config": true, "typecheck_configs": [ "tsconfig.json" ], "agent_commit_share": 0.29, "toolchain_manifests": [], "dependency_bot_commit_share": 0 }, "components": [ { "key": "one_command_bootstrap", "name": "One-command bootstrap", "detail": null, "points": 0, "status": "missed", "details": [], "max_points": 18 }, { "key": "automated_tests", "name": "Automated tests", "detail": null, "points": 22, "status": "met", "details": [], "max_points": 22 }, { "key": "lint_format_config", "name": "Lint / format config", "detail": "eslint.config.mjs", "points": 11, "status": "met", "details": [ { "code": "file_list", "params": { "files": "eslint.config.mjs" } } ], "max_points": 11 }, { "key": "static_type_checking", "name": "Static type checking", "detail": "tsconfig.json", "points": 11, "status": "met", "details": [ { "code": "file_list", "params": { "files": "tsconfig.json" } } ], "max_points": 11 }, { "key": "reproducible_environment", "name": "Reproducible environment", "detail": "lockfile", "points": 10, "status": "met", "details": [ { "code": "file_list", "params": { "files": "lockfile" } } ], "max_points": 10 }, { "key": "demonstrated_agent_practice", "name": "Demonstrated agent practice", "detail": "29 of the last 100 commits agent-authored or agent-credited", "points": 10, "status": "met", "details": [ { "code": "agent_authored_commits", "params": { "count": 29, "sampled": 100 } } ], "max_points": 10 }, { "key": "automated_maintenance", "name": "Automated maintenance", "detail": "no automated dependency updates observed", "points": 0, "status": "missed", "details": [ { "code": "no_dependency_automation", "params": {} } ], "max_points": 8 }, { "key": "openssf_scorecard_pinned_dependencies", "name": "OpenSSF Scorecard: Pinned-Dependencies", "detail": "dependency not pinned by hash detected -- score normalized to 7", "points": 7, "status": "partial", "details": [], "max_points": 10 } ] }, { "key": "ai_code_legibility", "band": "excellent", "name": "Code legibility for models", "note": null, "notes": [], "value": 99, "inputs": { "primary_language": "TypeScript", "largest_source_bytes": 78214, "source_files_sampled": 58, "oversized_source_files": 1 }, "components": [ { "key": "type_checkable_code", "name": "Type-checkable code", "detail": "TypeScript (statically typed)", "points": 45, "status": "met", "details": [ { "code": "statically_typed_language", "params": { "language": "TypeScript" } } ], "max_points": 45 }, { "key": "manageable_file_sizes", "name": "Manageable file sizes", "detail": "1/58 source files over 60KB", "points": 54.1, "status": "partial", "details": [ { "code": "oversized_source_files", "params": { "kb": 60, "sampled": 58, "oversized": 1 } } ], "max_points": 55 } ] } ], "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score." } ], "metrics_version": "1.13.0" }, "warnings": [ "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository" ], "report_type": "repository", "generated_at": "2026-07-25T14:28:58.849025Z", "schema_version": "0.27.0", "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/o/OpusPopuli/create-op-node.svg", "full_name": "OpusPopuli/create-op-node", "license_state": "standard", "license_spdx": "AGPL-3.0" }, "repoMeta": null, "notFound": false, "related": [ { "id": 139, "full_name": "apache/superset", "url": "https://github.com/apache/superset", "description": "Apache Superset is a Data Visualization and Data Exploration Platform", "ecosystem": "npm", "ecosystems": [ "npm", "pypi" ], "primary_language": "TypeScript", "languages": [ "TypeScript", "Python", "Jupyter Notebook" ], "topics": [ "superset", "apache", "apache-superset", "data-visualization", "data-viz", "analytics", "business-intelligence", "data-science", "data-engineering", "asf", "bi", "business-analytics", "data-analytics", "data-analysis", "python", "react", "sql-editor", "flask", "extensions", "visualization", "embed", "embedded", "sdk", "iframe", "dashboard", "chart", "cli", "development-tools" ], "license_spdx": "Apache-2.0", "license_state": "standard", "stars": 73846, "forks": 17889, "watchers": 1535, "monthly_downloads": 1098754, "latest_score": 97, "latest_band": "excellent", "latest_scanned_at": "2026-07-15T20:41:37.957488Z", "has_high_risk_jurisdiction_exposure": false, "has_malicious_dependency": false, "growth_authenticity": "unverified", "abandonment_state": "unverified", "red_flags": [], "badge_url": "" }, { "id": 14587, "full_name": "angular/angular-cli", "url": "https://github.com/angular/angular-cli", "description": "CLI tool for Angular", "ecosystem": "npm", "ecosystems": [ "npm" ], "primary_language": "TypeScript", "languages": [ "TypeScript" ], "topics": [ "angular", "cli", "angular-cli", "typescript" ], "license_spdx": "MIT", "license_state": "standard", "stars": 27021, "forks": 11859, "watchers": 966, "monthly_downloads": null, "latest_score": 90, "latest_band": "excellent", "latest_scanned_at": "2026-07-17T10:03:23.149200Z", "has_high_risk_jurisdiction_exposure": false, "has_malicious_dependency": false, "growth_authenticity": "unverified", "abandonment_state": "unverified", "red_flags": [], "badge_url": "" }, { "id": 28919, "full_name": "decidim/decidim", "url": "https://github.com/decidim/decidim", "description": "The participatory democracy framework. A generator and multiple gems made with Ruby on Rails", "ecosystem": "rubygems", "ecosystems": [ "rubygems", "npm" ], "primary_language": "Ruby", "languages": [ "Ruby", "HTML" ], "topics": [ "decidim", "democracy", "community", "government", "civic-tech", "civictech", "ideation", "collective-intelligence", "participation", "citizen-participation", "govtech", "stakeholder-engagement", "digital-public-goods", "digital-public-infrastructure", "dpg" ], "license_spdx": "AGPL-3.0", "license_state": "standard", "stars": 1791, "forks": 474, "watchers": 54, "monthly_downloads": null, "latest_score": 89, "latest_band": "excellent", "latest_scanned_at": "2026-07-20T16:15:15.791801Z", "has_high_risk_jurisdiction_exposure": false, "has_malicious_dependency": false, "growth_authenticity": "unverified", "abandonment_state": "unverified", "red_flags": [], "badge_url": "" }, { "id": 46, "full_name": "OpenHands/OpenHands", "url": "https://github.com/OpenHands/OpenHands", "description": "🙌 OpenHands: AI-Driven Development", "ecosystem": "npm", "ecosystems": [ "npm", "pypi" ], "primary_language": "Python", "languages": [], "topics": [ "agent", "artificial-intelligence", "chatgpt", "claude-ai", "cli", "developer-tools", "gpt", "llm", "openai" ], "license_spdx": null, "license_state": "custom", "stars": 80575, "forks": 10284, "watchers": 469, "monthly_downloads": 5176863, "latest_score": 87, "latest_band": "excellent", "latest_scanned_at": "2026-07-13T01:17:42.279995Z", "has_high_risk_jurisdiction_exposure": false, "has_malicious_dependency": false, "growth_authenticity": "unverified", "abandonment_state": "unverified", "red_flags": [], "badge_url": "" }, { "id": 107, "full_name": "n8n-io/n8n", "url": "https://github.com/n8n-io/n8n", "description": "Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.", "ecosystem": "npm", "ecosystems": [ "npm" ], "primary_language": "TypeScript", "languages": [], "topics": [ "ai", "apis", "automation", "cli", "data-flow", "development", "integration-framework", "integrations", "ipaas", "low-code", "low-code-platform", "mcp", "mcp-client", "mcp-server", "n8n", "no-code", "self-hosted", "typescript", "workflow", "workflow-automation" ], "license_spdx": null, "license_state": "custom", "stars": 196209, "forks": 59293, "watchers": 1138, "monthly_downloads": 0, "latest_score": 87, "latest_band": "excellent", "latest_scanned_at": "2026-07-13T01:46:04.380428Z", "has_high_risk_jurisdiction_exposure": false, "has_malicious_dependency": false, "growth_authenticity": "unverified", "abandonment_state": "unverified", "red_flags": [], "badge_url": "" }, { "id": 1871, "full_name": "nrwl/nx", "url": "https://github.com/nrwl/nx", "description": "The Monorepo Platform that amplifies both developers and AI agents. Nx optimizes your builds, scales your CI, and fixes failed PRs automatically. Ship in half the time.", "ecosystem": "crates", "ecosystems": [ "crates", "maven", "npm" ], "primary_language": "TypeScript", "languages": [], "topics": [ "angular", "build", "build-system", "build-tool", "building-tool", "cli", "cypress", "hacktoberfest", "javascript", "monorepo", "nextjs", "nodejs", "nx", "nx-workspaces", "react", "storybook", "typescript" ], "license_spdx": "MIT", "license_state": "standard", "stars": 29170, "forks": 2930, "watchers": 264, "monthly_downloads": 0, "latest_score": 87, "latest_band": "excellent", "latest_scanned_at": "2026-07-14T00:35:50.135644Z", "has_high_risk_jurisdiction_exposure": false, "has_malicious_dependency": false, "growth_authenticity": "unverified", "abandonment_state": "unverified", "red_flags": [], "badge_url": "" } ] } }
Публічний реєстр
Звіт про здоров'я програмного забезпеченнясхема 0.27.0 · метрики 1.13.0 · 2026-07-25 14:28 UTC

OpusPopuli / create-op-node

Interactive bootstrap CLI for an Opus Populi federation node — from sealed-box Mac Studio + a Cloudflare account to a live public API in one command.

TypeScriptAGPL-3.0★ 0 зірок⑂ 1 форкз черв. 2026 р.Переглянути на GitHub ↗

OpusPopuli/create-op-node має індекс здоров’я 58 зі 100, що відповідає смузі «Помірний». Найвищий показник — Vitality (75/100), найнижчий — Community & Adoption (33/100). Останнє оновлення було 5 днів тому. Більшість нещодавньої роботи виконує один учасник.

58
загалом / 100
Помірний

Індекс здоров'я програмного забезпечення

Метрики згруповано у зважені категорії на шкалі 1–100. Загальна оцінка починається як їхнє середнє; коли публічні дані активують Політику юрисдикцій високого ризику, рейтинг коригується й отримує верхню межу 49 («Під ризиком»). Готовність до ШІ не входить до індексу.

58
Відмінний85-100Зразковий; відповідає практично всім перевіреним критеріям
Добрий70-84Здоровий; незначні прогалини
Помірний50-69Прийнятний, але з помітними прогалинами; рекомендовано перевірку
У зоні ризику30-49Суттєві слабкі місця; впровадження потребує обережності
Критичний1-29Серйозні проблеми (покинутий, єдиний мейнтейнер, без базової гігієни)
ЖиттєздатністьСпільнота тавпровадженняСталість таврядуванняІнженернаякістьБезпекаГотовність доШІ

Профіль оцінок

Кожна вісь — окрема категорія. Форма важить більше, ніж середнє: здоровий об'єкт заповнює всю фігуру, тоді як профіль із піками та провалами означає, що сила в одному вимірі маскує ризик в іншому.

Власність

Opus PopuliОрганізація
0 підписників7 публічних репозиторіївз груд. 2025 р.

За цим репозиторієм стоїть організація — спільна, підзвітна опіка, здатна пережити будь-якого окремого мейнтейнера.

Пакетні екосистеми

РеєстрПакетВерсіяЗавантажень / місВерсіїОстання публікаціяТеги
npmcreate-op-node0.16.05 028445 днів томуopuspopulicivic-techfederationclibootstrapmac-studiocloudflare-tunnel

Метрики за категоріями

Життєздатність

Чи живий проєкт — чи пишеться код і чи виходять релізи?

75Добрий · 22% загального індексу
Як обчислюється оцінка
36/36Свіжість push — останній push 5 дн. тому
3.5/36Ритм комітів — 5/52 тижнів із комітами
18/18Обсяг комітів — 187 комітів за останній рік
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Використані вхідні дані
commits_last_year187
human_commit_share1
days_since_last_push5
active_weeks_last_year5
Як обчислюється оцінка
27/27Випускає релізи — опубліковано 35 релізів
36/36Свіжість релізів — останній реліз 5 дн. тому
27/27Ритм релізів — реліз кожні ~0,9 дн.
0/10OpenSSF Scorecard: Signed-Releases — немає даних
Використані вхідні дані
releases_count35
latest_release_tagv0.16.0
releases_from_tagsні
days_since_latest_release5
mean_days_between_releases0,9
Виключено з оцінювання (немає даних або не застосовно): OpenSSF Scorecard: Signed-Releases. Залишкові ваги перенормовано.

Спільнота та впровадження

Чи має проєкт користувачів, завантаження, увагу та влаштовані умови для контриб’юторів?

33У зоні ризику · 18% загального індексу
Як обчислюється оцінка
0/60Зірки — 0 зірок
0/25Форки — 1 форків
0/15Спостерігачі — 0 спостерігачів
Використані вхідні дані
forks1
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Як обчислюється оцінка
22.5/22.5README
22.5/22.5Ліцензія — визнана ліцензія (AGPL-3.0)
0/18Настанови CONTRIBUTING
0/13.5Кодекс поведінки
0/7.2Шаблон issue
0/6.3Шаблон PR
Використані вхідні дані
has_readmeтак
has_licenseтак
has_contributingні
has_issue_templateні
has_code_of_conductні
has_pull_request_templateні
Як обчислюється оцінка
49.4/80Щомісячні завантаження — 5 028 завантажень/місяць у npm
0/20Залежні пакети в реєстрі — ця екосистема цього не повідомляє
Використані вхідні дані
packagescreate-op-node
dependents
ecosystemsnpm
total_downloads
monthly_downloads5 028
Виключено з оцінювання (немає даних або не застосовно): Залежні пакети в реєстрі. Залишкові ваги перенормовано.

Сталість та врядування

Чи переживе проєкт своїх людей — бас-фактор, реактивність, хто за ним стоїть і як супроводжуються пакети?

54Помірний · 24% загального індексу
Як обчислюється оцінка
9/54Бас-фактор — на 1 контриб’ютор(ів) припадає половина всіх комітів
0.4/22.5Розподіл комітів — головний контриб’ютор — автор 98% комітів
2.7/13.5Широта контриб’юторів — 2 контриб’юторів
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Використані вхідні дані
bus_factor1
contributors_sampled2
top_contributor_share0,984
Як обчислюється оцінка
44.6/46.8Вирішення issue — закрито 96% issue
37.4/38.3Прийняття PR — злито 90/92 вирішених PR
0/15OpenSSF Scorecard: Code-Review — Found 0/25 approved changesets -- score normalized to 0
Використані вхідні дані
merged_prs90
open_issues1
closed_issues21
issue_closed_ratio0,955
closed_unmerged_prs2

Власність та опіка

38У зоні ризику
Як обчислюється оцінка
30/30Підтримка власника — у власності організації
0/20Верифікований домен
0/25Охоплення власника — 0 підписників у OpusPopuli
7.8/25Послужний список — 7 публічних репозиторіїв, вік облікового запису ~0 р.
Використані вхідні дані
followers0
owner_typeOrganization
is_verified
owner_loginOpusPopuli
public_repos7
account_age_days216

Супровід пакетів

100Відмінний
Як обчислюється оцінка
25/25Опубліковано й доступно — 1 пакет(ів) у npm
35/35Свіжість публікацій — остання публікація 5 дн. тому
20/20Історія версій — 44 опублікованих версій
20/20Не застарілий — активний, не deprecated і не yanked
Використані вхідні дані
packagescreate-op-node
ecosystemsnpm
any_deprecatedні
min_days_since_publish5

Інженерна якість

Чи наявні базові інженерні практики та документація?

70Добрий · 20% загального індексу
Як обчислюється оцінка
24/24Процеси CI — 3 процес(ів) CI
24/24Наявні тести
16/16Конфігурація лінтера — eslint.config.mjs
0/9.6Pre-commit-хуки
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 25 out of 25 merged PRs checked by a CI test -- score normalized to 10
Використані вхідні дані
has_ciтак
has_testsтак
has_editorconfigні
has_linter_configтак
has_precommit_configні

Документація

50Помірний
Як обчислюється оцінка
30/30README
0/25Каталог документації
0/15Сайт документації / домашня сторінка
10/10Опис репозиторію
0/10Теми
10/10Wiki
Використані вхідні дані
topics
has_wikiтак
homepage
has_readmeтак
has_docs_dirні
has_descriptionтак

Безпека

Чи міцні видимі практики безпеки й ланцюга постачання, без непослабленої пов’язаності з юрисдикціями високого ризику?

51Помірний · 16% загального індексу

Стан безпеки

39У зоні ризику
Як обчислюється оцінка
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — немає даних
2.5/2.5CI-Tests — 25 out of 25 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/25 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Ліцензія — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
5/5Packaging — packaging workflow detected
3.5/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 7
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — немає даних
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
3.8/7.5Vulnerabilities — 5 existing vulnerabilities detected
Використані вхідні дані
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate3,9
Виключено з оцінювання (немає даних або не застосовно): branch_protection, signed_releases. Залишкові ваги перенормовано.
Як обчислюється оцінка
35/35Прямі залежності без відомих сповіщень — жодна пряма залежність не має відомих сповіщень
25/25Непрямі залежності без відомих сповіщень — жодна непряма залежність не має відомих сповіщень
0/40Немає задавнених сповіщень — жодне сповіщення не має дати публікації
Використані вхідні дані
sourceosv
advisories0
affected_packages0
assessed_packages88
unassessed_packages0
affected_by_severitynone
direct_affected_packages0
Виключено з оцінювання (немає даних або не застосовно): Немає задавнених сповіщень. Залишкові ваги перенормовано. Звірено з runtime-замиканням залежностей npm:create-op-node@0.16.0 — тим, що тягне за собою встановлення опублікованого пакета, — 88 пакетів. Досяжність не аналізується.

Готовність до ШІ

Наскільки репозиторій оснащений для розробки та супроводу за участі ШІ-агентів? Незалежний, експериментальний бейдж — вага 0.0, тож він подається окремо і не впливає на загальний індекс здоров'я.

65Помірний · 0% загального індексу
Як обчислюється оцінка
0/45Інструкції для агентів — немає CLAUDE.md / AGENTS.md / правил редактора
0/15Машиночитана документація (llms.txt)
40/40Читабельна історія комітів — намір зазначено у 98 з 100 людських комітів (структурований заголовок або пояснювальний текст)
Використані вхідні дані
has_llms_txtні
legible_history_share0,98
agent_instruction_files
agent_instruction_max_bytes
Як обчислюється оцінка
0/18Розгортання однією командою
22/22Автоматизовані тести
11/11Конфігурація лінтера / форматера — eslint.config.mjs
11/11Статична перевірка типів — tsconfig.json
10/10Відтворюване середовище — lockfile
10/10Підтверджена практика роботи з агентами — 29 з останніх 100 комітів створено агентом або з його зазначенням
0/8Автоматизоване супроводження — автоматичних оновлень залежностей не виявлено
7/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 7
Використані вхідні дані
has_nixні
has_testsтак
lockfilespnpm-lock.yaml
has_dockerfileні
typed_languageтак
bootstrap_files
has_devcontainerні
has_linter_configтак
typecheck_configstsconfig.json
agent_commit_share0,29
toolchain_manifests
dependency_bot_commit_share0
Як обчислюється оцінка
45/45Типізований код — TypeScript (статично типізована)
54.1/55Керовані розміри файлів — 1/58 файлів вихідного коду понад 60 КБ
Використані вхідні дані
primary_languageTypeScript
largest_source_bytes78 214
source_files_sampled58
oversized_source_files1

Ключові факти

0зірок GitHub
2контриб'юторів
187комітів за останні 12 місяців
5днів від останнього пушу
35релізів
1бас-фактор
1відкритих issue
npmпакетних екосистем

Попередження щодо збору даних

  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Докладніше

OpenSSF Scorecard 3.9 / 10
3.9сукупно

Незалежна, не прив'язана до інструментів оцінка безпеки від відкритого проєкту OpenSSF Scorecard. Кожна перевірка винагороджує практику безпеки, а не інструмент конкретного постачальника. Перевірки, які Scorecard не зміг визначити, позначено н/д і виключено з оцінки безпеки (вони ніколи не зараховуються як нуль).Scorecard v5.5.0 · 2026-07-25 14:28 UTC

10Binary-Artifactsno binaries found in the repo
н/дBranch-Protectioninternal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
10CI-Tests25 out of 25 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/25 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
10Packagingpackaging workflow detected
7Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 7
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
н/дSigned-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
5Vulnerabilities5 existing vulnerabilities detected
Прямі залежності 9
РеєстрПакетОбмеження версіїМаніфест
npm@cfworker/json-schema^4.1.1package.json
npm@clack/prompts^0.9.0package.json
npm@octokit/rest^22.0.0package.json
npmcloudflare^4.0.0package.json
npmcommander^13.1.0package.json
npmexeca^9.5.2package.json
npmlibsodium-wrappers^0.8.4package.json
npmpicocolors^1.1.1package.json
npmzod^3.24.1package.json
Усі залежності не зібрано

Не вдалося зібрати розв'язаний набір залежностей для цього звіту: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Сповіщення про залежності 0

Встановлення npm:create-op-node@0.16.0 тягне 88 пакетів, прямих і транзитивних: 0 мають відомі сповіщення, з них 0 — прямі залежності.

Жодне відоме сповіщення не стосується оцінених залежностей.

Сповіщення означає, що версія, записана в графі залежностей, потрапляє в уражений діапазон. Досяжність не аналізується, а граф містить піниї розробки й тестування — знахідка може стосуватися інструментів, а не поставленого коду.

Звіт у форматі JSON машиночитний
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 507,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "JavaScript": 3464,
        "TypeScript": 589418
      },
      "pushed_at": "2026-07-19T16:13:33Z",
      "created_at": "2026-06-18T01:13:54Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-19T16:13:26Z",
      "description": "Interactive bootstrap CLI for an Opus Populi federation node — from sealed-box Mac Studio + a   Cloudflare account to a live public API in one command.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "AGPL-3.0",
      "default_branch": "main",
      "license_spdx_raw": "AGPL-3.0",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": null,
      "name": "Opus Populi",
      "type": "Organization",
      "login": "OpusPopuli",
      "company": null,
      "location": "United States of America",
      "followers": 0,
      "avatar_url": "https://avatars.githubusercontent.com/u/250730830?v=4",
      "created_at": "2025-12-20T17:38:32Z",
      "is_verified": null,
      "public_repos": 7,
      "account_age_days": 216
    },
    "license": {
      "state": "standard",
      "spdx_id": "AGPL-3.0",
      "raw_spdx": "AGPL-3.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.16.0",
          "kind": "minor",
          "published_at": "2026-07-19T16:13:33Z"
        },
        {
          "tag": "v0.15.2",
          "kind": "patch",
          "published_at": "2026-07-18T02:46:06Z"
        },
        {
          "tag": "v0.15.1",
          "kind": "patch",
          "published_at": "2026-07-12T23:26:59Z"
        },
        {
          "tag": "v0.15.0",
          "kind": "minor",
          "published_at": "2026-07-12T22:41:15Z"
        },
        {
          "tag": "v0.14.0",
          "kind": "minor",
          "published_at": "2026-07-12T21:56:27Z"
        },
        {
          "tag": "v0.13.0",
          "kind": "minor",
          "published_at": "2026-07-12T21:11:26Z"
        },
        {
          "tag": "v0.12.4",
          "kind": "patch",
          "published_at": "2026-07-12T00:53:11Z"
        },
        {
          "tag": "v0.12.3",
          "kind": "patch",
          "published_at": "2026-07-12T00:20:28Z"
        },
        {
          "tag": "v0.12.2",
          "kind": "patch",
          "published_at": "2026-07-11T23:29:11Z"
        },
        {
          "tag": "v0.12.1",
          "kind": "patch",
          "published_at": "2026-07-11T23:00:57Z"
        },
        {
          "tag": "v0.12.0",
          "kind": "minor",
          "published_at": "2026-07-11T22:58:47Z"
        },
        {
          "tag": "v0.11.3",
          "kind": "patch",
          "published_at": "2026-07-09T01:44:08Z"
        },
        {
          "tag": "v0.11.2",
          "kind": "patch",
          "published_at": "2026-07-08T22:50:43Z"
        },
        {
          "tag": "v0.11.1",
          "kind": "patch",
          "published_at": "2026-07-08T20:58:47Z"
        },
        {
          "tag": "v0.11.0",
          "kind": "minor",
          "published_at": "2026-07-08T16:26:18Z"
        },
        {
          "tag": "v0.10.17",
          "kind": "patch",
          "published_at": "2026-07-08T04:00:32Z"
        },
        {
          "tag": "v0.10.16",
          "kind": "patch",
          "published_at": "2026-07-08T03:20:59Z"
        },
        {
          "tag": "v0.10.15",
          "kind": "patch",
          "published_at": "2026-07-08T02:52:26Z"
        },
        {
          "tag": "v0.10.14",
          "kind": "patch",
          "published_at": "2026-07-08T02:42:11Z"
        },
        {
          "tag": "v0.10.13",
          "kind": "patch",
          "published_at": "2026-07-08T02:30:58Z"
        },
        {
          "tag": "v0.10.12",
          "kind": "patch",
          "published_at": "2026-07-08T01:19:41Z"
        },
        {
          "tag": "v0.10.11",
          "kind": "patch",
          "published_at": "2026-07-08T00:03:10Z"
        },
        {
          "tag": "v0.10.10",
          "kind": "patch",
          "published_at": "2026-07-07T03:55:52Z"
        },
        {
          "tag": "v0.10.9",
          "kind": "patch",
          "published_at": "2026-07-07T00:00:30Z"
        },
        {
          "tag": "v0.10.8",
          "kind": "patch",
          "published_at": "2026-07-06T15:39:22Z"
        },
        {
          "tag": "v0.10.7",
          "kind": "patch",
          "published_at": "2026-07-06T00:25:04Z"
        },
        {
          "tag": "v0.10.6",
          "kind": "patch",
          "published_at": "2026-07-05T23:52:49Z"
        },
        {
          "tag": "v0.10.5",
          "kind": "patch",
          "published_at": "2026-07-05T23:18:49Z"
        },
        {
          "tag": "v0.10.4",
          "kind": "patch",
          "published_at": "2026-07-05T23:16:59Z"
        },
        {
          "tag": "v0.10.3",
          "kind": "patch",
          "published_at": "2026-07-05T23:02:07Z"
        },
        {
          "tag": "v0.10.2",
          "kind": "patch",
          "published_at": "2026-06-26T17:03:27Z"
        },
        {
          "tag": "v0.10.1",
          "kind": "patch",
          "published_at": "2026-06-25T22:57:26Z"
        },
        {
          "tag": "v0.10.0",
          "kind": "minor",
          "published_at": "2026-06-25T19:34:05Z"
        },
        {
          "tag": "v0.9.1",
          "kind": "patch",
          "published_at": "2026-06-21T15:47:03Z"
        },
        {
          "tag": "v0.9.0",
          "kind": "minor",
          "published_at": "2026-06-20T23:23:12Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "0edf6c903b9ada6a3973490465ce0de02856fc09",
          "body": null,
          "is_bot": false,
          "headline": "chore(main): release 0.16.0 (#113)",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-19T16:13:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "baca2e819d773d39de5f013ffb40949ff1113155",
          "body": "…ocation (#111) (#112)\n\ndefaultComposeFiles excluded the backup overlay for --local-only nodes, so the\nreference production topology (a --local-only Mac Studio holding the real\ncorpus) shipped with no backups and no warning.\n\nBackups are now a first-class bootstrap choice:\n- enable/disable: interact\n[…]\n --backups-dir when enabled); previously backups were silently\noff for --local-only nodes.\n\nCo-authored-by: Rodney Gagnon <rodneygagnon@mac.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(bootstrap)!: operator-configurable backups — on/off, schedule, l…",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-19T16:07:42Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "64e5056729d234733c9f78d5b6658908ebac3219",
          "body": null,
          "is_bot": false,
          "headline": "chore(main): release 0.15.2 (#110)",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-18T02:45:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c994e7f963b024d3969b48f1e43ca71c931d7950",
          "body": "…t (opuspopuli-node#43) (#109)\n\nThe generated op-compose wrapper exported SUPABASE_URL with a hard\nlocalhost:8000 default and ran `docker compose` with no --env-file, so an\nexported shell var overrode any .env value. Result: browser-facing auth URLs\n(API_EXTERNAL_URL, GOTRUE_JWT_ISSUER, SUPABASE_PUB\n[…]\nue breaks the managed-block validator), so both remain\nout of the managed block by design.\n\nCo-authored-by: Rodney Gagnon <rodneygagnon@mac.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: single-source SUPABASE_URL via .env, stop op-compose exporting i…",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-18T02:43:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8542bdf03ce4866f8da3a776e8d0a7642299f663",
          "body": null,
          "is_bot": false,
          "headline": "chore(main): release 0.15.1 (#108)",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-12T23:26:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e4c2fb41e3c6668a6ed0873fd8c2dab7203a3543",
          "body": "…ads (#107)\n\nThe generated node `.env` wrote `EMBEDDINGS_MODEL`, but no backend code reads\nthat name — packages/config-provider/src/configs/embeddings.config.ts reads\n`EMBEDDINGS_OLLAMA_MODEL` (and `EMBEDDINGS_OLLAMA_URL`). So the embeddings-model\nvalue bootstrap wrote bound to nothing: an operator \n[…]\n\ncreate-op-node doesn't need to write it.\n\nFollows #97/#98; pairs with opuspopuli-node#36.\n\nCo-authored-by: Rodney Gagnon <rodneygagnon@mac.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(env-file): write EMBEDDINGS_OLLAMA_MODEL — the key the backend re…",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-12T22:54:42Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "260578634cdb17fd655b180b44306ed427bd2337",
          "body": null,
          "is_bot": false,
          "headline": "chore(main): release 0.15.0 (#106)",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-12T22:41:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "914e3e018bd7730ae824f320b1881488e8f98bd3",
          "body": "…#103) (#105)\n\n* fix(verify): collect repeated --image into an array (#103)\n\nThe --image option had a default of [] but no argParser, so commander\nstored only the last value as a string. The cosign phase then iterated\nthat string character-by-character — verifying 'g', 'h', 'c', … as image\nrefs (40 \n[…]\notstrap --local-only'.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Rodney Gagnon <rodneygagnon@mac.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(verify): --local-only mode + fix --image array collector (#104, …",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-12T22:39:50Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2142b5503edee3d7c116440a02b485a64fe8526f",
          "body": null,
          "is_bot": false,
          "headline": "chore(main): release 0.14.0 (#102)",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-12T21:56:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7756f3ad3d1e4d49da28aed0914dd260b6ec35a5",
          "body": "…are pull (#101)\n\n* feat(verify): assert configured Ollama model is present + provider-aware pull\n\nCloses the config↔runtime drift that silently 404s at inference time: a node\nwhose LLM_MODEL names a model that was never pulled into the host Ollama trips\nthe circuit breaker and the job \"finishes\" wi\n[…]\nt (cosign is Phase 6).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Rodney Gagnon <rodneygagnon@mac.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(verify): assert configured Ollama model is present + provider-aw…",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-12T21:52:57Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "cae5a4b989a0d13afc1f4fd12e68214157981328",
          "body": null,
          "is_bot": false,
          "headline": "chore(main): release 0.13.0 (#100)",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-12T21:11:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8862610cea73a2d86edcadb0a985690b3419fd1d",
          "body": "… LLM tiers (#99)\n\nModel identifiers used to be pushed into the launchd session via\n`launchctl setenv` and injected into bootstrap's compose subprocess. Both\nshadow docker compose's `.env` at `${LLM_MODEL:-…}` interpolation time\n(shell/launchd env > .env), so partial container recreates baked diverg\n[…]\nODEL from buildComposeEnv and the LaunchAgent\n  so .env is authoritative.\n\nPairs with #98.\n\nCo-authored-by: Rodney Gagnon <rodneygagnon@mac.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(bootstrap): single-source .env for model config + hardware-aware…",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-12T21:07:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "197713e4aafd7c9e1e31700befeefa76e47dd01b",
          "body": null,
          "is_bot": false,
          "headline": "chore(main): release 0.12.4 (#96)",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-12T00:52:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8c6217fbee9f56276911cd9d2f24ef6472d0a302",
          "body": "…mpt-service (#95)\n\n#93: writePgsodiumKeyFile wrote the key at mode 0400, so a bootstrap re-run\nfailed EACCES reopening the read-only file (writeFile's `mode` only applies on\ncreate). rm -f before write makes it overwrite-safe across re-runs.\n\n#94: DEFAULT_IDENTITY_REGEXP pinned the cosign signer to\n[…]\npuspopuli|prompt-service) — spoofed/arbitrary org repos still fail.\n\nCloses #93\nCloses #94\n\nCo-authored-by: Rodney Gagnon <rodneygagnon@mac.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(bootstrap): idempotent key-file write + broaden cosign pin to pro…",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-12T00:51:26Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4b55a34686deb72a496645d8da96a01451cd0b18",
          "body": null,
          "is_bot": false,
          "headline": "chore(main): release 0.12.3 (#92)",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-12T00:20:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b1420223d4780e94a13faf3658f0c9893e5de41e",
          "body": "…ask (#91)\n\nTwo blockers found re-bootstrapping a region-with-prompts node from scratch.\n\nbuildComposeEnv (#90) omitted every prompt-service overlay secret\n(PROMPTS_DB_PASSWORD, PROMPT_SERVICE_API_KEY/_KEYS, admin key, URL), so\nbootstrap's own compose calls aborted interpolating ${PROMPTS_DB_PASSWOR\n[…]\nen the GUI app already exists (appPath, also\napplied to tailscale).\n\nCloses #90\nCloses #89\n\nCo-authored-by: Rodney Gagnon <rodneygagnon@mac.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(bootstrap): hydrate prompt-service env + detect existing docker c…",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-12T00:17:57Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "40a15729c85a8bab6ad0cb70ba0d7b0391478c84",
          "body": null,
          "is_bot": false,
          "headline": "chore(main): release 0.12.2 (#88)",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-11T23:28:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "32f94594e9f2180f52d9f15cbfc87429524ba107",
          "body": "…R:?} vars (#87)\n\nreset ran `docker compose down` with no env, but the opuspopuli-node\ntemplate guards required secrets with `${POSTGRES_PASSWORD:?…}` etc.\nCompose interpolates the whole file even for `down`, so teardown aborted\nbefore removing anything — and continue-on-failure then deleted the\nLau\n[…]\nps it in sync with the template\nrather than drifting against a hardcoded list.\n\nCloses #85\n\nCo-authored-by: Rodney Gagnon <rodneygagnon@mac.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(reset): hydrate placeholder env so `compose down` works with ${VA…",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-11T23:25:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ed8daa44bcbbccc70dfc2819fee1be0b0cdfb091",
          "body": null,
          "is_bot": false,
          "headline": "chore(main): release 0.12.1 (#84)",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-11T23:00:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "557949343fd1d08798a2034ce575475443ee83ef",
          "body": "The --compose-file option on bootstrap and reset was a plain value-taking\noption with no accumulator, so commander stored it as the last string\npassed rather than an array. resolveComposeFiles() then called .map on\nthat string and threw \"inputs.map is not a function\" — so passing\n--compose-file at a\n[…]\nesolveComposeFiles tests only passed arrays, so\nthey missed the option layer).\n\nCloses #82\n\nCo-authored-by: Rodney Gagnon <rodneygagnon@mac.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(cli): collect repeated --compose-file into an array (#83)",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-11T22:58:39Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f5d237ad2a6d9892ae97c0bf45ddb4834c22de21",
          "body": "…--components--create-op-node\n\nchore(main): release 0.12.0",
          "is_bot": false,
          "headline": "Merge pull request #81 from OpusPopuli/release-please--branches--main…",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-09T03:43:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "824e6a90f177a5bd41d48c4cbeaf2aa6b9bf88ba",
          "body": null,
          "is_bot": false,
          "headline": "chore(main): release 0.12.0",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-09T03:42:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "628878aaa39d9f3f5362acb425ef30a6f05af15c",
          "body": "feat(bootstrap): generate gateway/grafana secrets + public-profile guard (#27)",
          "is_bot": false,
          "headline": "Merge pull request #80 from OpusPopuli/fix/bootstrap-secret-guard-27",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-09T03:42:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5b9fcc5b5f5f800fb7047a790c0bffd6f1c26885",
          "body": "…posure\n\nThe prod compose defaults GATEWAY_HMAC_SECRET / API_KEYS to a well-known\ntemplate string and Grafana admin to admin/admin. Every checkout shares\nthose, so a Tunnel-exposed node could sign gateway<->microservice requests\nwith a publicly-known key.\n\nBootstrap now generates a per-node GATEWAY_\n[…]\nic profile when\nthose values are unset or still the well-known default; --local-only\nbootstraps (no public profile) are unaffected.\n\nCloses #27\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(bootstrap): generate gateway/grafana secrets and guard tunnel ex…",
          "author_name": "Rodney Gagnon",
          "author_login": null,
          "committed_at": "2026-07-09T03:41:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0345fdbeb4ad83caa4504e2ab44ed288ddbf0a88",
          "body": "…--components--create-op-node\n\nchore(main): release 0.11.3",
          "is_bot": false,
          "headline": "Merge pull request #79 from OpusPopuli/release-please--branches--main…",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-09T01:43:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "012317490726aae8610ec8fc095d99c1e092573a",
          "body": null,
          "is_bot": false,
          "headline": "chore(main): release 0.11.3",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-09T01:42:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ded70a7e647792a0d18c75455ebc864a43868b7a",
          "body": "…ry-59\n\nfix(polling): retry a transient output fetch instead of reporting output-missing",
          "is_bot": false,
          "headline": "Merge pull request #78 from OpusPopuli/fix/output-fetch-transient-ret…",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-09T01:42:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f5d6137bb6d3cb45079b75442eb1cb11151b3549",
          "body": "…put-missing\n\nIssue #59: once tfc.getJson degrades a network failure to\n{ status: 0, body: null }, fetchOutput returned null for two different\nsituations — the output being genuinely absent, and a transient blip while\nfetching it. waitForRunOutput couldn't tell them apart, so a network hiccup\non the\n[…]\n-string)/error(404)/\nerror(throw); polling transient-error-then-value => success (no\nmisdiagnosis) and persistent-error => timeout.\n\nCloses #59\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(polling): retry a transient output fetch instead of reporting out…",
          "author_name": "Rodney Gagnon",
          "author_login": null,
          "committed_at": "2026-07-09T01:41:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f284e0745f7ffffae60c1a1e51027ac6d7c9a360",
          "body": "…--components--create-op-node\n\nchore(main): release 0.11.2",
          "is_bot": false,
          "headline": "Merge pull request #77 from OpusPopuli/release-please--branches--main…",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-08T22:50:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "da577b2e83441cea4a629f4d26eae8463e36891f",
          "body": null,
          "is_bot": false,
          "headline": "chore(main): release 0.11.2",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-08T22:38:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b0fe6622b3ba27edec294c98717f3730c005563a",
          "body": "fix(init): query the real default branch when adopting an existing repo",
          "is_bot": false,
          "headline": "Merge pull request #76 from OpusPopuli/fix/init-default-branch-41",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-08T22:38:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "166598434c9e7c5a17ebe1d5ed494ee00e7a2666",
          "body": "Issue #41: when `init` re-uses a pre-existing region repo (HTTP 422 →\nadopt), it synthesized `defaultBranch: 'main'`. A repo initialized with a\ndifferent default (master, org default) would then have its prod.tfvars\nbranch cut from — and PR based on — a branch that doesn't exist.\n\n- github.ts: add g\n[…]\nm now.\n\nTests: getRepoDefaultBranch (branch from repos.get + owner/repo split, null\non API error / missing field / malformed slug).\n\nCloses #41\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(init): query the real default branch when adopting an existing repo",
          "author_name": "Rodney Gagnon",
          "author_login": null,
          "committed_at": "2026-07-08T22:27:27Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8c55037122598dca78d78c5848f19c5adc4e3055",
          "body": "…--components--create-op-node\n\nchore(main): release 0.11.1",
          "is_bot": false,
          "headline": "Merge pull request #75 from OpusPopuli/release-please--branches--main…",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-08T20:58:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "82ee9f549819c75845aa738fc7445fe5eccff852",
          "body": null,
          "is_bot": false,
          "headline": "chore(main): release 0.11.1",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-08T20:46:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a2ad94f7221b47a372c590b819d1aab39f7f08f7",
          "body": "fix: cleanup nits — cat quoting, teardown ok flag, default-subcommand routing",
          "is_bot": false,
          "headline": "Merge pull request #74 from OpusPopuli/fix/cleanup-nits-36",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-08T20:45:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a354c05cfb1bc584bb6657d9948bff95818cd532",
          "body": "… routing\n\nBatch of small correctness fixes from the #36 code-review (item 3,\nSAFE_URL_RE escape, was already fixed in the ESLint migration):\n\n- launchagent.ts (item 1): quote the key-file path inside `cat` —\n  `\"$(cat \"${keyFilePath}\")\"`. A space-containing keyFilePath (allowed by\n  SAFE_PATH_RE) p\n[…]\n test that encoded the old behavior), new\ncli-args.test.ts (no-args / flags-first / known-subcommand / global-flags /\nno-mutation).\n\nCloses #36\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: cleanup nits — cat quoting, teardown ok flag, default-subcommand…",
          "author_name": "Rodney Gagnon",
          "author_login": null,
          "committed_at": "2026-07-08T20:16:27Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "846429522bddccca775616239e11b3a064b892f2",
          "body": "…--components--create-op-node\n\nchore(main): release 0.11.0",
          "is_bot": false,
          "headline": "Merge pull request #73 from OpusPopuli/release-please--branches--main…",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-08T16:26:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "78af452ea77d7d239bb14fcd2b0693d0ea2b1dfe",
          "body": null,
          "is_bot": false,
          "headline": "chore(main): release 0.11.0",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-08T16:07:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f61c0d7abeb97a580ca1c0f56a8309e7a5455501",
          "body": "…es-34\n\nfeat(bootstrap): fail-closed cosign signature gate before pull",
          "is_bot": false,
          "headline": "Merge pull request #72 from OpusPopuli/feat/bootstrap-verify-signatur…",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-08T16:07:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8bab24b9e79b75adfda60237a852a826ceb02469",
          "body": "Issue #34 (point 1): bootstrap pulled + ran images with no signature\ncheck — cosign was only invoked by the separate, optional, fail-open\n`verify`. Gate the pull path fail-closed instead.\n\n- homebrew.ts: add `cosign` to STUDIO_PACKAGES so Phase 2 installs it.\n- docker.ts: composeConfigImages (`docke\n[…]\noseConfigImages (args + parse + null on non-zero/ENOENT),\nfilterVerifiableImages (keep/drop/override/empty), cosign in the brew list.\n\nRefs #34\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(bootstrap): fail-closed cosign signature gate before pull",
          "author_name": "Rodney Gagnon",
          "author_login": null,
          "committed_at": "2026-07-08T15:44:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "bd0e600ebc43ce6fe70ba920d7c6e0b16995c63a",
          "body": "…--components--create-op-node\n\nchore(main): release 0.10.17",
          "is_bot": false,
          "headline": "Merge pull request #71 from OpusPopuli/release-please--branches--main…",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-08T04:00:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aed7118e60ee72292831e8e44f8ccf008c772c61",
          "body": null,
          "is_bot": false,
          "headline": "chore(main): release 0.10.17",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-08T03:58:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "97eff19fbce17f735c850138b764a020f96919c9",
          "body": "fix(cosign): ref-pin the signature identity to release.yml",
          "is_bot": false,
          "headline": "Merge pull request #70 from OpusPopuli/fix/cosign-identity-pin-34",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-08T03:58:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "385f93e236ca392d8150861ce72d09a622ab9f91",
          "body": "Issue #34 (point 3): DEFAULT_IDENTITY_REGEXP was\n`.../\\.github/workflows/.*$`, which accepts ANY workflow in the opuspopuli\nrepo that ever obtained a Fulcio cert — over-broad. Pin it to the actual\npublishing workflow so verify only trusts images signed by it.\n\n- Pin the workflow FILE: `.../release\\.\n[…]\ncts a different workflow\n(ci.yml), a spoofed owner/repo, and a tag ref.\n\nAdvisory-only for now (verify); no bootstrap behavior change. Refs #34\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(cosign): ref-pin the signature identity to release.yml",
          "author_name": "Rodney Gagnon",
          "author_login": null,
          "committed_at": "2026-07-08T03:52:54Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "52fa99184f84fd45a58a4e4bf80833ce99c149a9",
          "body": "…--components--create-op-node\n\nchore(main): release 0.10.16",
          "is_bot": false,
          "headline": "Merge pull request #69 from OpusPopuli/release-please--branches--main…",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-08T03:20:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6e36b8e536d959d76b58eaff694b39b8d4d0232e",
          "body": null,
          "is_bot": false,
          "headline": "chore(main): release 0.10.16",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-08T03:18:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2a1d8efe9e348f30b4d3874c6e99945faaef17b1",
          "body": "fix(init): seed repo secrets via Octokit + libsodium under the PAT",
          "is_bot": false,
          "headline": "Merge pull request #68 from OpusPopuli/fix/seed-secrets-via-octokit-32",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-08T03:18:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ec084b945d4c9010b16170eee5d8043402602c07",
          "body": "Issue #32: repo-secret seeding shelled out to `gh secret set` (ambient gh\nCLI auth), while every sibling init call used the explicit --gh-token PAT\nvia Octokit. A PAT identity that differed from the gh login seeded to the\nwrong account, and the \"PAT-only, may not have gh\" escape hatch the doc\nclaime\n[…]\necryptable (and plaintext-free), public-key-fetch failure,\nmid-batch PUT failure with correct seeded/pending split, malformed slug.\n\nCloses #32\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(init): seed repo secrets via Octokit + libsodium under the PAT",
          "author_name": "Rodney Gagnon",
          "author_login": null,
          "committed_at": "2026-07-08T03:16:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "40d0d20b0d98da4211c0019629a2b3396c1d6a20",
          "body": "…--components--create-op-node\n\nchore(main): release 0.10.15",
          "is_bot": false,
          "headline": "Merge pull request #67 from OpusPopuli/release-please--branches--main…",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-08T02:52:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "63cbac754e1e77e1809b540ce7613c9a975eeb17",
          "body": null,
          "is_bot": false,
          "headline": "chore(main): release 0.10.15",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-08T02:51:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "291ad49d5175078e3a0889e0d19f802df650c186",
          "body": "…ep-35\n\nfix(polling): check workspace before sleeping in the discovery loop",
          "is_bot": false,
          "headline": "Merge pull request #66 from OpusPopuli/fix/discovery-check-before-sle…",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-08T02:51:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4d0da6456bb96fbf78875c4e19e91a2c3aa2e6c1",
          "body": "waitForApply's discovery loop slept a full poll interval before its first\nfindWorkspace call, so a run that already existed was found one interval\nlate, and with pollMs >= discoveryMs the budget could be spent before a\nuseful check. Move the sleep to the end of the loop body (check, then\nsleep): fin\n[…]\n t=0 without\nsleeping) and the pollMs >= discoveryMs edge case. All existing discovery /\ntimeout / resilience tests pass unchanged.\n\nCloses #35\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(polling): check workspace before sleeping in the discovery loop",
          "author_name": "Rodney Gagnon",
          "author_login": null,
          "committed_at": "2026-07-08T02:49:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "932aa74ab008ffca67217374c09b121035eb0e2f",
          "body": "…--components--create-op-node\n\nchore(main): release 0.10.14",
          "is_bot": false,
          "headline": "Merge pull request #65 from OpusPopuli/release-please--branches--main…",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-08T02:42:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4fd8b3855e648ec59982188a489fc8f1cbb9ad95",
          "body": null,
          "is_bot": false,
          "headline": "chore(main): release 0.10.14",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-08T02:40:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "52e8fb1b7a6fa6212d3c7d0d4d89e7e5ac86ff87",
          "body": "fix(ollama): add request timeouts to health + warm probes",
          "is_bot": false,
          "headline": "Merge pull request #64 from OpusPopuli/fix/network-timeouts-ollama-31",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-08T02:40:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8d1ff58e5fa2ab7f91ce2310416b340f9b597aac",
          "body": "Final slice of #31 (Ollama). Both checkOllamaHealth and warmModel already\nhad try/catch (Ollama never crashed), but their fetch calls had no\ntimeout, so a hung daemon (accepts the connection, never responds) would\nstall bootstrap forever.\n\n- checkOllamaHealth: AbortController + 5s timeout — a metada\n[…]\nboth timeouts via fake timers + an abort-aware fetch stub, plus a\nnon-timeout warm failure case so both catch branches are covered.\n\nCloses #31\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ollama): add request timeouts to health + warm probes",
          "author_name": "Rodney Gagnon",
          "author_login": null,
          "committed_at": "2026-07-08T02:39:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a0094db32a45ba9dd2cae7d03383beaa06c46851",
          "body": "…--components--create-op-node\n\nchore(main): release 0.10.13",
          "is_bot": false,
          "headline": "Merge pull request #63 from OpusPopuli/release-please--branches--main…",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-08T02:30:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ba48de76b3fa61f91be292fbb9d7be5c7c90b9d3",
          "body": null,
          "is_bot": false,
          "headline": "chore(main): release 0.10.13",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-08T02:29:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b4aa09632481f61a77572205eed2fecdd20fa210",
          "body": "…e-31\n\nfix(cloudflare): add request timeout + degrade network failures gracefully",
          "is_bot": false,
          "headline": "Merge pull request #62 from OpusPopuli/fix/network-timeouts-cloudflar…",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-08T02:29:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3075c6a67a6ac485819af31d6eb00ee250a7e17a",
          "body": "…fully\n\nSecond slice of #31 (Cloudflare), mirroring the TFC fix. The Cloudflare\n`get` helper had no timeout and only wrapped `.json()` in try/catch, so a\nstalled connection could hang `init` (probeCloudflareToken makes 6\nsequential calls) and a transient fetch throw could reject out of the\nwizard.\n\n\n[…]\net to a\nnetwork-error message) + added probeCloudflareToken network-error and\ntimeout-abort (fake timers) cases.\n\nOllama is Subtask 3. Refs #31\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(cloudflare): add request timeout + degrade network failures grace…",
          "author_name": "Rodney Gagnon",
          "author_login": null,
          "committed_at": "2026-07-08T02:26:51Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7c3840742961a87a4281a93c87bb6bc311c9bd37",
          "body": "…--components--create-op-node\n\nchore(main): release 0.10.12",
          "is_bot": false,
          "headline": "Merge pull request #61 from OpusPopuli/release-please--branches--main…",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-08T01:19:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "123314fa53c96fb08261d9c388da48ef11f0c6c3",
          "body": null,
          "is_bot": false,
          "headline": "chore(main): release 0.10.12",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-08T00:53:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7159518eaf98aea1f67b460ff7a472a4ac9f40c2",
          "body": "fix(tfc): add request timeouts + degrade network failures gracefully",
          "is_bot": false,
          "headline": "Merge pull request #60 from OpusPopuli/fix/network-timeouts-31",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-08T00:53:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b9a0aa0cfa043ddc5fece473412905e090cc4634",
          "body": "First slice of #31 (TFC). Native `fetch` has no default timeout and the\nTFC helpers had no try/catch around the fetch itself, so a stalled\nconnection could hang `init` indefinitely and a transient network throw\ncould reject out of the ~10-minute apply-wait and crash the wizard.\n\n- constants.ts: add \n[…]\n tracks the pre-existing output-missing misdiagnosis on a\ntransient final-output-fetch failure. Cloudflare + Ollama are Subtasks 2/3.\n\nRefs #31\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(tfc): add request timeouts + degrade network failures gracefully",
          "author_name": "Rodney Gagnon",
          "author_login": null,
          "committed_at": "2026-07-08T00:51:36Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8ee67ee7914d75d74f118f4dc770377fac74026b",
          "body": "…--components--create-op-node\n\nchore(main): release 0.10.11",
          "is_bot": false,
          "headline": "Merge pull request #58 from OpusPopuli/release-please--branches--main…",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-08T00:03:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "419a478f2e474223b8a3471d4d898738e3fa8a4c",
          "body": null,
          "is_bot": false,
          "headline": "chore(main): release 0.10.11",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-08T00:01:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5d5913cdbd76c05779b9ef916745c44a73871186",
          "body": "fix(bootstrap): align llm-model docs + picker hints with actual defaults",
          "is_bot": false,
          "headline": "Merge pull request #57 from OpusPopuli/fix/llm-default-consistency-33",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-08T00:01:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c1a24998464064eb0a1bf96483c9446fd1b4077c",
          "body": "Issue #33 asked to verify the default Ollama tag `qwen3.5:9b`. It is valid\nand pullable (confirmed against the Ollama registry manifest + the official\nQwen3.5 release announcement) — Qwen3.5 shipped after the reviewer's\nknowledge cutoff, and their review environment had the registry blocked,\nwhich i\n[…]\n36–48 GB\" hint (48 GB actually pre-selects\n  32b) to \"< 48 GB\".\n\nNo behavior change; bootstrap.test.ts doesn't assert on hint text.\n\nCloses #33\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(bootstrap): align llm-model docs + picker hints with actual defaults",
          "author_name": "Rodney Gagnon",
          "author_login": null,
          "committed_at": "2026-07-07T23:28:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9f6bf9282926335cb98c6379daae33dad19a3640",
          "body": "ci(lint): enforce the sonar pass in CI and prepublishOnly",
          "is_bot": false,
          "headline": "Merge pull request #56 from OpusPopuli/ci/enforce-sonar-gate-37",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-07T04:00:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cb02cec37dd0964cad2102d0935cbb54d71e5fd4",
          "body": "Final step of the #37 burndown. All cognitive-complexity findings are\ncleared (58 -> 0), so the second ESLint pass is now turned on as a\nblocking gate:\n\n- ci.yml: add a `Lint (sonar)` step after `Lint (eslint)`\n- package.json: restore `pnpm lint:sonar` to the prepublishOnly chain\n- eslint.sonar.conf\n[…]\nI\" deferral note\n\nThe two-pass ESLint setup (base + sonarjs cognitive-complexity <= 15) now\nmirrors @opuspopuli/regions end to end.\n\nCloses #37\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci(lint): enforce the sonar pass in CI and prepublishOnly",
          "author_name": "Rodney Gagnon",
          "author_login": null,
          "committed_at": "2026-07-07T03:58:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "23f978ec07257a1b55682d42d6e50a707e424849",
          "body": "…--components--create-op-node\n\nchore(main): release 0.10.10",
          "is_bot": false,
          "headline": "Merge pull request #55 from OpusPopuli/release-please--branches--main…",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-07T03:55:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aabf289e0b6251b091d02c1a03d33a20428a5db7",
          "body": null,
          "is_bot": false,
          "headline": "chore(main): release 0.10.10",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-07T03:55:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3b8b5337d8269729cfb173d18c9bd8c12f9596f0",
          "body": "refactor(lib): extract helpers to clear remaining complexity findings",
          "is_bot": false,
          "headline": "Merge pull request #54 from OpusPopuli/refactor/sonar-lib-cc-37",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-07T03:54:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b5e61671dd4779afe6733f920b7aefb3a3c14a06",
          "body": "Eighth slice of the #37 burndown — clears the last 7 cognitive-complexity\nfindings across the lib + region command. No behavior change.\n\n- lib/region.ts validateRegionConfig (22): split into 4 sub-validators;\n  issue-message order preserved via spread\n- lib/docker.ts waitForHealthy (16) + assessHeal\n[…]\ns, guarding the extractions.\n\nWith this, `pnpm lint:sonar` is green (0 findings) — the CI gate flip is\nthe only remaining step (#37).\n\nRefs #37\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(lib): extract helpers to clear remaining complexity findings",
          "author_name": "Rodney Gagnon",
          "author_login": null,
          "committed_at": "2026-07-07T03:53:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "71f818f11dbc8566d2582b4bb6e20d32dc62c9e7",
          "body": "…--components--create-op-node\n\nchore(main): release 0.10.9",
          "is_bot": false,
          "headline": "Merge pull request #53 from OpusPopuli/release-please--branches--main…",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-07T00:00:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4a7547e55666d8817803b867ea34926d0481a59a",
          "body": null,
          "is_bot": false,
          "headline": "chore(main): release 0.10.9",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-06T22:52:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "202b7f926de09f76c6725e36dd55461504328670",
          "body": "refactor(verify): extract phase helpers to cut handler complexity",
          "is_bot": false,
          "headline": "Merge pull request #52 from OpusPopuli/refactor/sonar-verify-cc-37",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-06T22:52:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ea4db7d1b5c825f2321729e16622af430076e67a",
          "body": "Seventh slice of the #37 burndown — verify had two cognitive-complexity\nfindings: runVerify (28) and the `.action` handler (28). Extract each into\n<=15-CC helpers. No behavior change.\n\nrunVerify -> verifyTlsPhase / verifyHealthPhase / verifyGraphqlPhase /\nverifyCloudflarePhase / verifyCosignPhase. E\n[…]\nhe 17\nrunVerify cases; the action helpers all mix resolution with\np.cancel/process.exit, so there is no fully-pure seam to unit-test.\n\nRefs #37\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(verify): extract phase helpers to cut handler complexity",
          "author_name": "Rodney Gagnon",
          "author_login": null,
          "committed_at": "2026-07-06T20:01:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "bb08a88b0d70a998e38476abf900d9d73ee19d17",
          "body": "…--components--create-op-node\n\nchore(main): release 0.10.8",
          "is_bot": false,
          "headline": "Merge pull request #51 from OpusPopuli/release-please--branches--main…",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-06T15:39:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4b14f4f60e3f824adc27519f0401504c4667dd96",
          "body": null,
          "is_bot": false,
          "headline": "chore(main): release 0.10.8",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-06T15:35:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dadb350bd5bc4cdbd6f03840e07ab58b58331015",
          "body": "refactor(reset): extract phase helpers to cut handler complexity",
          "is_bot": false,
          "headline": "Merge pull request #50 from OpusPopuli/refactor/sonar-reset-cc-37",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-06T15:35:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "42804295f4bdd0b9c3e509ad759b3afcbf5628d8",
          "body": "Sixth slice of the #37 burndown — reset had two cognitive-complexity\nfindings: runReset (36) and the `.action` handler (50). Extract each into\n<=15-CC helpers. No behavior change.\n\nrunReset -> resetStopStackPhase / resetLaunchAgentPhase /\nresetDockerLogoutPhase, each returning a ResetPhase; runReset\n[…]\n default) — mirrors the buildComposeEnv\nprecedent. Full suite 388 green, incl. the 21 existing runReset cases\n(onPhase order intact).\n\nRefs #37\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(reset): extract phase helpers to cut handler complexity",
          "author_name": "Rodney Gagnon",
          "author_login": null,
          "committed_at": "2026-07-06T14:55:17Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f61ce1912e082908843633d5c73fe9c2c38f2bca",
          "body": "…--components--create-op-node\n\nchore(main): release 0.10.7",
          "is_bot": false,
          "headline": "Merge pull request #49 from OpusPopuli/release-please--branches--main…",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-06T00:24:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c0d1c11fa1475db080d411de1d9575dd03047242",
          "body": null,
          "is_bot": false,
          "headline": "chore(main): release 0.10.7",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-06T00:23:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cc86886ee7e3df0ee67aacf6287e784a1daba1b9",
          "body": "refactor(init): extract phase helpers to cut handler complexity",
          "is_bot": false,
          "headline": "Merge pull request #48 from OpusPopuli/refactor/sonar-init-cc-37",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-06T00:23:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "20b3dba367df1fad265e182dba8417d5b8cee619",
          "body": "Fifth slice of the #37 burndown — the init `.action` handler was\ncognitive-complexity 71. Extract each phase into its own <=15-CC helper so\nthe handler becomes a ~45-line orchestrator. No behavior change: the\ninteractive prompts, spinners, and process.exit calls are relocated\nverbatim, restructured \n[…]\n interactive I/O; the existing\nsuite already covers the pure seams (summarizePhases,\nlistIgnoredLocalOnlyFlags), which are untouched.\n\nRefs #37\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(init): extract phase helpers to cut handler complexity",
          "author_name": "Rodney Gagnon",
          "author_login": null,
          "committed_at": "2026-07-06T00:16:26Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0d85c1fc0e2e5770a4380dbdefb6b6ae4a4e468b",
          "body": "…--components--create-op-node\n\nchore(main): release 0.10.6",
          "is_bot": false,
          "headline": "Merge pull request #47 from OpusPopuli/release-please--branches--main…",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-05T23:52:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "64738945053ff60d69af19680a56d03bcc15698e",
          "body": null,
          "is_bot": false,
          "headline": "chore(main): release 0.10.6",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-05T23:51:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d5799dfba567ffa36536f111921e083835407845",
          "body": "refactor(bootstrap): extract phase helpers to cut handler complexity",
          "is_bot": false,
          "headline": "Merge pull request #46 from OpusPopuli/refactor/sonar-bootstrap-cc-37",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-05T23:51:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "407caf434a7778ccefa9bb75d625d6f289579274",
          "body": "Fourth slice of the #37 burndown — the bootstrap `.action` handler was\ncognitive-complexity 85. Extract each phase into its own <=15-CC helper so\nthe handler becomes a ~17-line orchestrator. No behavior change: the\ninteractive prompts, spinners, and process.exit calls are relocated\nverbatim; a Colle\n[…]\nET fallback). The\ninteractive orchestration has no unit tests (it never did) — verified via\ntypecheck, build, and `bootstrap --help`.\n\nRefs #37\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(bootstrap): extract phase helpers to cut handler complexity",
          "author_name": "Rodney Gagnon",
          "author_login": null,
          "committed_at": "2026-07-05T23:48:24Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3aba80827900f83899d9a7eb918704164cc6f626",
          "body": "…--components--create-op-node\n\nchore(main): release 0.10.5",
          "is_bot": false,
          "headline": "Merge pull request #45 from OpusPopuli/release-please--branches--main…",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-05T23:18:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4abdd65a1921f674836a17ba8ee11a0496070957",
          "body": null,
          "is_bot": false,
          "headline": "chore(main): release 0.10.5",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-05T23:18:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9b5789ca38ad9bb28afd0ac4e0e13d3944326557",
          "body": "fix(lint): rewrite super-linear regexes in src",
          "is_bot": false,
          "headline": "Merge pull request #44 from OpusPopuli/fix/sonar-regex-backtracking-37",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-05T23:17:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "54ab5be40c42cfadd58e07c2824f9737bc81d6c0",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'main' into fix/sonar-regex-backtracking-37",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-05T23:17:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ff66176ac4b5e8252380d3afd97c808bb3e7172c",
          "body": "…--components--create-op-node\n\nchore(main): release 0.10.4",
          "is_bot": false,
          "headline": "Merge pull request #43 from OpusPopuli/release-please--branches--main…",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-05T23:16:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "84e957343b8afc0a374604a008f6387b4a2e1a14",
          "body": "Third slice of the #37 burndown — clears the 4 super-linear-regex\nfindings in `src/`, leaving only the 13 cognitive-complexity refactors.\nEach rewrite is backtracking-free and behavior-preserving for real\ninputs, with characterization tests locking the equivalence.\n\n- bootstrap.ts estimatedPullTime:\n[…]\n05b\nsizes) and the slugify edge trim; the existing generatePostgresPassword\n\"no + / =\" assertion already covers the base64url change.\n\nRefs #37\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(lint): rewrite super-linear regexes in src",
          "author_name": "Rodney Gagnon",
          "author_login": null,
          "committed_at": "2026-07-05T23:15:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4e0e0fada6cd3fb476d74c40477b47e7cd54ea7b",
          "body": null,
          "is_bot": false,
          "headline": "chore(main): release 0.10.4",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-05T23:04:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "68e892131c6260d7626292ed1f1cdefb45573047",
          "body": "refactor(lint): clear cheap sonar findings in src",
          "is_bot": false,
          "headline": "Merge pull request #42 from OpusPopuli/refactor/sonar-cheap-src-37",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-05T23:03:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "845f7fee4ecf763fdbbb5c561245dd788c009932",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'main' into refactor/sonar-cheap-src-37",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-05T23:03:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e9cd70224a103a688a2f0e9e4c44232de2b4c926",
          "body": "test(lint): clear sonar findings in the test suite",
          "is_bot": false,
          "headline": "Merge pull request #40 from OpusPopuli/test/sonar-test-findings-37",
          "author_name": "Rodney Gagnon",
          "author_login": "rodneygagnon",
          "committed_at": "2026-07-05T23:03:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 35,
      "commits_last_year": 187,
      "latest_release_at": "2026-07-19T16:13:33Z",
      "latest_release_tag": "v0.16.0",
      "releases_from_tags": false,
      "days_since_last_push": 5,
      "active_weeks_last_year": 5,
      "days_since_latest_release": 5,
      "mean_days_between_releases": 0.9
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 50,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "create-op-node",
          "exists": true,
          "license": "AGPL-3.0-or-later",
          "keywords": [
            "opuspopuli",
            "civic-tech",
            "federation",
            "cli",
            "bootstrap",
            "mac-studio",
            "cloudflare-tunnel"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/create-op-node",
          "is_deprecated": false,
          "latest_version": "0.16.0",
          "repository_url": "https://github.com/OpusPopuli/create-op-node",
          "versions_count": 44,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 5028,
          "first_published_at": "2026-06-18T01:59:12.555000Z",
          "latest_published_at": "2026-07-19T16:14:23.712000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        }
      ]
    },
    "popularity": {
      "forks": 1,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [
          {
            "date": "2026-07-11",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 1,
        "total_forks": 1
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0,
        "collected_at": null
      },
      "open_issues_and_prs": 1
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 78214,
      "source_files_sampled": 58,
      "oversized_source_files": 1,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 88,
        "malicious_count": 0,
        "assessed_package": "npm:create-op-node@0.16.0",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "@cfworker/json-schema",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.1.1"
        },
        {
          "name": "@clack/prompts",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.9.0"
        },
        {
          "name": "@octokit/rest",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^22.0.0"
        },
        {
          "name": "cloudflare",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.0.0"
        },
        {
          "name": "commander",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^13.1.0"
        },
        {
          "name": "execa",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^9.5.2"
        },
        {
          "name": "libsodium-wrappers",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.8.4"
        },
        {
          "name": "picocolors",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.1"
        },
        {
          "name": "zod",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.24.1"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 90,
        "open_issues": 1,
        "closed_ratio": 0.955,
        "closed_issues": 21,
        "closed_unmerged_prs": 2
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "rodneygagnon",
          "commits": 120,
          "avatar_url": "https://avatars.githubusercontent.com/u/43381472?v=4"
        },
        {
          "type": "User",
          "login": "claude",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/81847?v=4"
        }
      ],
      "contributors_sampled": 2,
      "top_contributor_share": 0.984
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "publish.yml",
        "release-please.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [
        "eslint.config.mjs"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "pnpm-lock.yaml"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": null,
            "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "25 out of 25 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/25 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 7,
            "reason": "dependency not pinned by hash detected -- score normalized to 7",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 5,
            "reason": "5 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "0edf6c903b9ada6a3973490465ce0de02856fc09",
        "ran_at": "2026-07-25T14:28:41Z",
        "aggregate_score": 3.9,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-19T16:14:28Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-19T16:13:23Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 114,
          "created_at": "2026-07-19T16:26:12Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/OpusPopuli/create-op-node",
    "host": "github.com",
    "name": "create-op-node",
    "owner": "OpusPopuli"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 58,
      "inputs": {
        "security": 51,
        "vitality": 75,
        "community": 33,
        "governance": 54,
        "engineering": 70
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 75,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 58,
            "inputs": {
              "commits_last_year": 187,
              "human_commit_share": 1,
              "days_since_last_push": 5,
              "active_weeks_last_year": 5
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "5/52 weeks with commits",
                "points": 3.5,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "187 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 187
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 35,
              "latest_release_tag": "v0.16.0",
              "releases_from_tags": false,
              "days_since_latest_release": 5,
              "mean_days_between_releases": 0.9
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "35 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 35
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~0.9 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 0.9
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 33,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 1,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "1 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (AGPL-3.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "AGPL-3.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 62,
            "inputs": {
              "packages": [
                "create-op-node"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 5028
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "5,028 downloads/month across npm",
                "points": 49.4,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 5028,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 54,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 12,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 2,
              "top_contributor_share": 0.984
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 98% of commits",
                "points": 0.4,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 98
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "2 contributors",
                "points": 2.7,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 82,
            "inputs": {
              "merged_prs": 90,
              "open_issues": 1,
              "closed_issues": 21,
              "issue_closed_ratio": 0.955,
              "closed_unmerged_prs": 2
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "96% of issues closed",
                "points": 44.6,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 96
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "90/92 decided PRs merged",
                "points": 37.4,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 90,
                      "decided": 92
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/25 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 38,
            "inputs": {
              "followers": 0,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "OpusPopuli",
              "public_repos": 7,
              "account_age_days": 216
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "0 followers of OpusPopuli",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 0,
                      "login": "OpusPopuli"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "7 public repos, account ~0 yr old",
                "points": 7.8,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 7
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "create-op-node"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 5
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 5 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "44 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 44
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 70,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "3 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": "eslint.config.mjs",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.mjs"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "25 out of 25 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 51,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Branch-Protection, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "branch_protection",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 39,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 3.9
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "25 out of 25 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/25 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 7",
                "points": 3.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "5 existing vulnerabilities detected",
                "points": 3.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:create-op-node@0.16.0 runtime dependency closure — what installing the published package pulls in — 88 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:create-op-node@0.16.0",
                  "assessed": 88
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 0,
              "affected_packages": 0,
              "assessed_packages": 88,
              "unassessed_packages": 0,
              "affected_by_severity": "none",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "no indirect dependency carries a known advisory",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "no_indirect_advisories",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 88,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 65,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.98,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "98 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 98,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 71,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "pnpm-lock.yaml"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "tsconfig.json"
              ],
              "agent_commit_share": 0.29,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": "eslint.config.mjs",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.mjs"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "29 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 29,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 7",
                "points": 7,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 99,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 78214,
              "source_files_sampled": 58,
              "oversized_source_files": 1
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "1/58 source files over 60KB",
                "points": 54.1,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 58,
                      "oversized": 1
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-25T14:28:58.849025Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/o/OpusPopuli/create-op-node.svg",
  "full_name": "OpusPopuli/create-op-node",
  "license_state": "standard",
  "license_spdx": "AGPL-3.0"
}

Оцінки — це сигнали, а не гарантії. Вони відображають публічно видимі практики на GitHub — це не аудит коду й не гарантія безпеки.

Відсутні дані виключаються, а ваги перенормовуються — нуль за відсутність ніколи не ставиться. Методологія версіонована й відкрита: метрики v1.13.0, схема v0.27.0 — повна методологія · вікі метрик.

Як окремий результат виглядає на тлі всього реєстру: сукупна статистикаnpm.