Публічний реєстр
Звіт про здоров'я програмного забезпеченнясхема 0.27.0 · метрики 1.13.0 · 2026-07-25 23:49 UTC

ThoTischner / observability-mcp

Unified observability gateway for AI agents — one MCP server for Prometheus, Loki, and any backend, with cross-signal anomaly detection and a built-in Web UI.

TypeScript · JavaScript · HTMLApache-2.0★ 6 зірок⑂ 1 форкз бер. 2026 р.Переглянути на GitHub ↗

ThoTischner/observability-mcp має індекс здоров’я 67 зі 100, що відповідає смузі «Помірний». Найвищий показник — AI Readiness (89/100), найнижчий — Community & Adoption (50/100). Останнє оновлення — сьогодні. Більшість нещодавньої роботи виконує один учасник.

67
загалом / 100
Помірний

Індекс здоров'я програмного забезпечення

Метрики згруповано у зважені категорії на шкалі 1–100. Загальна оцінка починається як їхнє середнє; коли публічні дані активують Політику юрисдикцій високого ризику, рейтинг коригується й отримує верхню межу 49 («Під ризиком»). Готовність до ШІ не входить до індексу.

67
Відмінний85-100Зразковий; відповідає практично всім перевіреним критеріям
Добрий70-84Здоровий; незначні прогалини
Помірний50-69Прийнятний, але з помітними прогалинами; рекомендовано перевірку
У зоні ризику30-49Суттєві слабкі місця; впровадження потребує обережності
Критичний1-29Серйозні проблеми (покинутий, єдиний мейнтейнер, без базової гігієни)
ЖиттєздатністьСпільнота тавпровадженняСталість таврядуванняІнженернаякістьБезпекаГотовність доШІ

Профіль оцінок

Кожна вісь — окрема категорія. Форма важить більше, ніж середнє: здоровий об'єкт заповнює всю фігуру, тоді як профіль із піками та провалами означає, що сила в одному вимірі маскує ризик в іншому.

Власність

Thomas TischnerОсобистий обліковий запис
17 підписників43 публічні репозиторіїз лист. 2014 р.System Vertrieb Alexander GmbH

Цей репозиторій належить особистому обліковому запису. Проєкт з єдиним власником несе більший ризик безперервності, ніж підтримуваний організацією.

Пакетні екосистеми

РеєстрПакетВерсіяЗавантажень / місВерсіїОстання публікаціяТеги
npm@thotischner/observability-mcp3.9.32 001425 днів томуmcpmodel-context-protocolobservabilityprometheuslokikubernetestempotopologyblast-radiusanomaly-detectionincident-responseroot-cause-analysissreplatform-engineeringagentai-agentllm-toolsclaudeollama

Метрики за категоріями

Життєздатність

Чи живий проєкт — чи пишеться код і чи виходять релізи?

80Добрий · 22% загального індексу
Як обчислюється оцінка
36/36Свіжість push — останній push 0 дн. тому
10.4/36Ритм комітів — 15/52 тижнів із комітами
18/18Обсяг комітів — 529 комітів за останній рік
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 15 issue activity found in the last 90 days -- score normalized to 10
Використані вхідні дані
commits_last_year529
human_commit_share0,86
days_since_last_push0
active_weeks_last_year15
Як обчислюється оцінка
27/27Випускає релізи — опубліковано 84 релізів
36/36Свіжість релізів — останній реліз 5 дн. тому
27/27Ритм релізів — реліз кожні ~2,9 дн.
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Використані вхідні дані
releases_count84
latest_release_tagv3.9.3
releases_from_tagsні
days_since_latest_release5
mean_days_between_releases2,9

Спільнота та впровадження

Чи має проєкт користувачів, завантаження, увагу та влаштовані умови для контриб’юторів?

50Помірний · 18% загального індексу
Як обчислюється оцінка
11.3/60Зірки — 6 зірок
0/25Форки — 1 форків
0/15Спостерігачі — 0 спостерігачів
Використані вхідні дані
forks1
stars6
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Як обчислюється оцінка
22.5/22.5README
22.5/22.5Ліцензія — визнана ліцензія (Apache-2.0)
18/18Настанови CONTRIBUTING
13.5/13.5Кодекс поведінки
0/7.2Шаблон issue
6.3/6.3Шаблон PR
Використані вхідні дані
has_readmeтак
has_licenseтак
has_contributingтак
has_issue_templateні
has_code_of_conductтак
has_pull_request_templateтак
Як обчислюється оцінка
44/80Щомісячні завантаження — 2 001 завантажень/місяць у npm
0/20Залежні пакети в реєстрі — ця екосистема цього не повідомляє
Використані вхідні дані
packages@thotischner/observability-mcp
dependents
ecosystemsnpm
total_downloads
monthly_downloads2 001
Виключено з оцінювання (немає даних або не застосовно): Залежні пакети в реєстрі. Залишкові ваги перенормовано.

Сталість та врядування

Чи переживе проєкт своїх людей — бас-фактор, реактивність, хто за ним стоїть і як супроводжуються пакети?

58Помірний · 24% загального індексу
Як обчислюється оцінка
9/54Бас-фактор — на 1 контриб’ютор(ів) припадає половина всіх комітів
0/22.5Розподіл комітів — головний контриб’ютор — автор 100% комітів
1.4/13.5Широта контриб’юторів — 1 контриб’юторів
3/10OpenSSF Scorecard: Contributors — project has 1 contributing companies or organizations -- score normalized to 3
Використані вхідні дані
bus_factor1
contributors_sampled1
top_contributor_share1
Як обчислюється оцінка
46.8/46.8Вирішення issue — закрито 100% issue
35.5/38.3Прийняття PR — злито 495/533 вирішених PR
0/15OpenSSF Scorecard: Code-Review — Found 0/16 approved changesets -- score normalized to 0
Використані вхідні дані
merged_prs495
open_issues0
closed_issues15
issue_closed_ratio1
closed_unmerged_prs38
Як обчислюється оцінка
10/30Підтримка власника — особистий (користувацький) обліковий запис
0/20Верифікований домен — не застосовно до користувацьких облікових записів
9/25Охоплення власника — 17 підписників у ThoTischner
24/25Послужний список — 43 публічних репозиторіїв, вік облікового запису ~11 р.
Використані вхідні дані
followers17
owner_typeUser
is_verified
owner_loginThoTischner
public_repos43
account_age_days4 265
Виключено з оцінювання (немає даних або не застосовно): Верифікований домен. Залишкові ваги перенормовано.

Супровід пакетів

100Відмінний
Як обчислюється оцінка
25/25Опубліковано й доступно — 1 пакет(ів) у npm
35/35Свіжість публікацій — остання публікація 5 дн. тому
20/20Історія версій — 42 опублікованих версій
20/20Не застарілий — активний, не deprecated і не yanked
Використані вхідні дані
packages@thotischner/observability-mcp
ecosystemsnpm
any_deprecatedні
min_days_since_publish5

Інженерна якість

Чи наявні базові інженерні практики та документація?

81Добрий · 20% загального індексу
Як обчислюється оцінка
24/24Процеси CI — 25 процес(ів) CI
24/24Наявні тести
0/16Конфігурація лінтера
0/9.6Pre-commit-хуки
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
Використані вхідні дані
has_ciтак
has_testsтак
has_editorconfigні
has_linter_configні
has_precommit_configні

Документація

100Відмінний
Як обчислюється оцінка
30/30README
25/25Каталог документації
15/15Сайт документації / домашня сторінка — https://www.npmjs.com/package/@thotischner/observability-mcp
10/10Опис репозиторію
10/10Теми — 16 тем
10/10Wiki
Використані вхідні дані
topicsai-agents, anomaly-detection, anthropic, claude, gateway, helm, kubernetes, llm, loki, mcp, mcp-server, model-context-protocol, monitoring, observability, prometheus, sre
has_wikiтак
homepagehttps://www.npmjs.com/package/@thotischner/observability-mcp
has_readmeтак
has_docs_dirтак
has_descriptionтак

Безпека

Чи міцні видимі практики безпеки й ланцюга постачання, без непослабленої пов’язаності з юрисдикціями високого ризику?

62Помірний · 16% загального індексу

Стан безпеки

57Помірний
Як обчислюється оцінка
7.5/7.5Binary-Artifacts — no binaries found in the repo
2.2/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/16 approved changesets -- score normalized to 0
0.8/2.5Contributors — project has 1 contributing companies or organizations -- score normalized to 3
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Ліцензія — license file detected
7.5/7.5Maintained — 30 commit(s) and 15 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
4.5/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 9
5/5SAST — SAST tool is run on all commits
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 11 existing vulnerabilities detected
Використані вхідні дані
sourceopenssf_scorecard
checks_evaluated18
scorecard_versionv5.5.0
checks_inconclusive0
scorecard_aggregate5,7
Як обчислюється оцінка
35/35Прямі залежності без відомих сповіщень — жодна пряма залежність не має відомих сповіщень
8.7/25Непрямі залежності без відомих сповіщень — уражено 2: brace-expansion 2.1.2 (high 7.5), @hono/node-server 1.19.15 (moderate 5.9)
40/40Немає задавнених сповіщень — жодне сповіщення не є публічним довше за 90 дн.
Використані вхідні дані
sourceosv
advisories2
affected_packages2
assessed_packages330
unassessed_packages0
affected_by_severityhigh 1, moderate 1
direct_affected_packages0
Звірено з runtime-замиканням залежностей npm:@thotischner/observability-mcp@3.9.3 — тим, що тягне за собою встановлення опублікованого пакета, — 330 пакетів. Досяжність не аналізується.

Готовність до ШІ

Наскільки репозиторій оснащений для розробки та супроводу за участі ШІ-агентів? Незалежний, експериментальний бейдж — вага 0.0, тож він подається окремо і не впливає на загальний індекс здоров'я.

89Відмінний · 0% загального індексу
Як обчислюється оцінка
45/45Інструкції для агентів — CLAUDE.md, docs/agent.md
15/15Машиночитана документація (llms.txt) — llms.txt наявний
40/40Читабельна історія комітів — намір зазначено у 86 з 86 людських комітів (структурований заголовок або пояснювальний текст)
Використані вхідні дані
has_llms_txtтак
legible_history_share1
agent_instruction_filesCLAUDE.md, docs/agent.md
agent_instruction_max_bytes8 032
Як обчислюється оцінка
18/18Розгортання однією командою — Makefile
22/22Автоматизовані тести
0/11Конфігурація лінтера / форматера
11/11Статична перевірка типів — examples/agent/tsconfig.json, examples/example-services/tsconfig.json, mcp-server/tsconfig.json, packages/sdk/tsconfig.json
10/10Відтворюване середовище — Dockerfile, lockfile
10/10Підтверджена практика роботи з агентами — 76 з останніх 100 комітів створено агентом або з його зазначенням
8/8Автоматизоване супроводження — 14 з останніх 100 комітів — автоматичні оновлення залежностей
9/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 9
Використані вхідні дані
has_nixні
has_testsтак
lockfilespackage-lock.json
has_dockerfileтак
typed_languageтак
bootstrap_filesMakefile
has_devcontainerні
has_linter_configні
typecheck_configsexamples/agent/tsconfig.json, examples/example-services/tsconfig.json, mcp-server/tsconfig.json, packages/sdk/tsconfig.json
agent_commit_share0,76
toolchain_manifests
dependency_bot_commit_share0,14
Як обчислюється оцінка
45/45Типізований код — TypeScript (статично типізована)
54.8/55Керовані розміри файлів — 1/313 файлів вихідного коду понад 60 КБ
Використані вхідні дані
primary_languageTypeScript
largest_source_bytes207 571
source_files_sampled313
oversized_source_files1
Як обчислюється оцінка
0/40Схема API (OpenAPI/GraphQL/proto)
20/20Сервер MCP
40/40Придатні до запуску приклади — examples
Використані вхідні дані
example_dirsexamples
has_mcp_signalтак
api_schema_files

Ключові факти

6зірок GitHub
1контриб'юторів
529комітів за останні 12 місяців
0днів від останнього пушу
84релізів
1бас-фактор
0відкритих issue
npmпакетних екосистем

Попередження щодо збору даних

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

Докладніше

OpenSSF Scorecard 5.7 / 10
5.7сукупно

Незалежна, не прив'язана до інструментів оцінка безпеки від відкритого проєкту OpenSSF Scorecard. Кожна перевірка винагороджує практику безпеки, а не інструмент конкретного постачальника. Перевірки, які Scorecard не зміг визначити, позначено н/д і виключено з оцінки безпеки (вони ніколи не зараховуються як нуль).Scorecard v5.5.0 · 2026-07-25 23:49 UTC

10Binary-Artifactsno binaries found in the repo
3Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/16 approved changesets -- score normalized to 0
3Contributorsproject has 1 contributing companies or organizations -- score normalized to 3
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 15 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
9Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 9
10SASTSAST tool is run on all commits
10Security-Policysecurity policy file detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities11 existing vulnerabilities detected
Прямі залежності 15
РеєстрПакетОбмеження версіїМаніфест
npm@kubernetes/client-node^1.4.0mcp-server/package.json
npm@modelcontextprotocol/sdk^1.12.0mcp-server/package.json
npm@opentelemetry/api^1.9.0mcp-server/package.json
npm@opentelemetry/auto-instrumentations-node^0.78.0mcp-server/package.json
npm@opentelemetry/exporter-trace-otlp-http^0.220.0mcp-server/package.json
npm@opentelemetry/resources^2.2.0mcp-server/package.json
npm@opentelemetry/sdk-node^0.220.0mcp-server/package.json
npm@opentelemetry/semantic-conventions^1.40.0mcp-server/package.json
npmexpress^5.2.1mcp-server/package.json
npmexpress-rate-limit^8.5.2mcp-server/package.json
npmjs-yaml^4.1.0mcp-server/package.json
npmprom-client^15.1.0mcp-server/package.json
npmredis^4.7.0mcp-server/package.json
npmws^8.18.0mcp-server/package.json
npmzod^4.4.3mcp-server/package.json
Усі залежності 433

Повний розв'язаний набір залежностей із графа залежностей GitHub: 18 прямих і 415 непрямих (транзитивних) пакетів. Транзитивне замикання є повним, коли в репозиторії закомічено lockfile.

РеєстрПакетВерсіяЗв'язок
npm@kubernetes/client-node1.4.0пряма
npm@modelcontextprotocol/sdk1.29.0пряма
npm@opentelemetry/api1.9.1пряма
npm@opentelemetry/auto-instrumentations-node0.78.0пряма
npm@opentelemetry/exporter-trace-otlp-http0.220.0пряма
npm@opentelemetry/resources2.9.0пряма
npm@opentelemetry/sdk-node0.220.0пряма
npm@opentelemetry/semantic-conventions1.43.0пряма
npmexpress5.2.1пряма
npmexpress^4.21.0пряма
npmexpress-rate-limit8.5.2пряма
npmexpress-rate-limit8.6.0пряма
npmjs-yaml4.2.0пряма
npmprom-client15.1.3пряма
npmprom-client^15.1.3пряма
npmredis4.7.1пряма
npmws8.21.1пряма
npmzod4.4.3пряма
npm@aws-crypto/crc325.2.0непряма
npm@aws-crypto/sha256-browser5.2.0непряма
npm@aws-crypto/sha256-js5.2.0непряма
npm@aws-crypto/supports-web-crypto5.2.0непряма
npm@aws-crypto/util5.2.0непряма
npm@aws-sdk/client-ec23.1063.0непряма
npm@aws-sdk/client-ecs3.1063.0непряма
npm@aws-sdk/client-eks3.1063.0непряма
npm@aws-sdk/core3.974.18непряма
npm@aws-sdk/credential-provider-env3.972.44непряма
npm@aws-sdk/credential-provider-http3.972.46непряма
npm@aws-sdk/credential-provider-ini3.972.50непряма
npm@aws-sdk/credential-provider-login3.972.49непряма
npm@aws-sdk/credential-provider-node3.972.52непряма
npm@aws-sdk/credential-provider-process3.972.44непряма
npm@aws-sdk/credential-provider-sso3.972.49непряма
npm@aws-sdk/credential-provider-web-identity3.972.49непряма
npm@aws-sdk/middleware-sdk-ec23.972.32непряма
npm@aws-sdk/nested-clients3.997.17непряма
npm@aws-sdk/signature-v4-multi-region3.996.32непряма
npm@aws-sdk/token-providers3.1063.0непряма
npm@aws-sdk/types3.973.11непряма
npm@aws-sdk/util-locate-window3.965.6непряма
npm@aws-sdk/xml-builder3.972.28непряма
npm@aws/lambda-invoke-store0.2.4непряма
npm@esbuild/aix-ppc640.28.1непряма
npm@esbuild/android-arm0.28.1непряма
npm@esbuild/android-arm640.28.1непряма
npm@esbuild/android-x640.28.1непряма
npm@esbuild/darwin-arm640.28.1непряма
npm@esbuild/darwin-x640.28.1непряма
npm@esbuild/freebsd-arm640.28.1непряма
npm@esbuild/freebsd-x640.28.1непряма
npm@esbuild/linux-arm0.28.1непряма
npm@esbuild/linux-arm640.28.1непряма
npm@esbuild/linux-ia320.28.1непряма
npm@esbuild/linux-loong640.28.1непряма
npm@esbuild/linux-mips64el0.28.1непряма
npm@esbuild/linux-ppc640.28.1непряма
npm@esbuild/linux-riscv640.28.1непряма
npm@esbuild/linux-s390x0.28.1непряма
npm@esbuild/linux-x640.28.1непряма
npm@esbuild/netbsd-arm640.28.1непряма
npm@esbuild/netbsd-x640.28.1непряма
npm@esbuild/openbsd-arm640.28.1непряма
npm@esbuild/openbsd-x640.28.1непряма
npm@esbuild/openharmony-arm640.28.1непряма
npm@esbuild/sunos-x640.28.1непряма
npm@esbuild/win32-arm640.28.1непряма
npm@esbuild/win32-ia320.28.1непряма
npm@esbuild/win32-x640.28.1непряма
npm@google-cloud/compute^4.13.0непряма
npm@google-cloud/container^5.16.0непряма
npm@google-cloud/run^1.6.0непряма
npm@grpc/grpc-js1.14.4непряма
npm@grpc/proto-loader0.8.1непряма
npm@hono/node-server1.19.14непряма
npm@hono/node-server2.0.2непряма
npm@isaacs/cliui8.0.2непряма
npm@js-sdsl/ordered-map4.4.2непряма
npm@jsep-plugin/assignment1.3.0непряма
npm@jsep-plugin/regex1.0.4непряма
npm@nodable/entities2.1.1непряма
npm@opentelemetry/api-logs0.220.0непряма
npm@opentelemetry/configuration0.220.0непряма
npm@opentelemetry/context-async-hooks2.9.0непряма
npm@opentelemetry/core2.8.0непряма
npm@opentelemetry/exporter-logs-otlp-grpc0.220.0непряма
npm@opentelemetry/exporter-logs-otlp-http0.220.0непряма
npm@opentelemetry/exporter-logs-otlp-proto0.220.0непряма
npm@opentelemetry/exporter-metrics-otlp-grpc0.220.0непряма
npm@opentelemetry/exporter-metrics-otlp-http0.220.0непряма
npm@opentelemetry/exporter-metrics-otlp-proto0.220.0непряма
npm@opentelemetry/exporter-prometheus0.220.0непряма
npm@opentelemetry/exporter-trace-otlp-grpc0.220.0непряма
npm@opentelemetry/exporter-trace-otlp-proto0.220.0непряма
npm@opentelemetry/exporter-zipkin2.9.0непряма
npm@opentelemetry/instrumentation0.220.0непряма
npm@opentelemetry/instrumentation-amqplib0.67.0непряма
npm@opentelemetry/instrumentation-aws-lambda0.72.0непряма
npm@opentelemetry/instrumentation-aws-sdk0.75.0непряма
npm@opentelemetry/instrumentation-bunyan0.65.0непряма
npm@opentelemetry/instrumentation-cassandra-driver0.65.0непряма
npm@opentelemetry/instrumentation-connect0.63.0непряма
npm@opentelemetry/instrumentation-cucumber0.36.0непряма
npm@opentelemetry/instrumentation-dataloader0.37.0непряма
npm@opentelemetry/instrumentation-dns0.63.0непряма
npm@opentelemetry/instrumentation-express0.68.0непряма
npm@opentelemetry/instrumentation-fs0.39.0непряма
npm@opentelemetry/instrumentation-generic-pool0.63.0непряма
npm@opentelemetry/instrumentation-graphql0.68.0непряма
npm@opentelemetry/instrumentation-grpc0.220.0непряма
npm@opentelemetry/instrumentation-hapi0.66.0непряма
npm@opentelemetry/instrumentation-host-metrics0.3.0непряма
npm@opentelemetry/instrumentation-http0.220.0непряма
npm@opentelemetry/instrumentation-ioredis0.68.0непряма
npm@opentelemetry/instrumentation-kafkajs0.29.0непряма
npm@opentelemetry/instrumentation-knex0.64.0непряма
npm@opentelemetry/instrumentation-koa0.68.0непряма
npm@opentelemetry/instrumentation-lru-memoizer0.64.0непряма
npm@opentelemetry/instrumentation-memcached0.63.0непряма
npm@opentelemetry/instrumentation-mongodb0.73.0непряма
npm@opentelemetry/instrumentation-mongoose0.66.0непряма
npm@opentelemetry/instrumentation-mysql0.66.0непряма
npm@opentelemetry/instrumentation-mysql20.66.0непряма
npm@opentelemetry/instrumentation-nestjs-core0.66.0непряма
npm@opentelemetry/instrumentation-net0.64.0непряма
npm@opentelemetry/instrumentation-openai0.18.0непряма
npm@opentelemetry/instrumentation-oracledb0.45.0непряма
npm@opentelemetry/instrumentation-pg0.72.0непряма
npm@opentelemetry/instrumentation-pino0.66.0непряма
npm@opentelemetry/instrumentation-redis0.68.0непряма
npm@opentelemetry/instrumentation-restify0.65.0непряма
npm@opentelemetry/instrumentation-router0.64.0непряма
npm@opentelemetry/instrumentation-runtime-node0.33.0непряма
npm@opentelemetry/instrumentation-socket.io0.67.0непряма
npm@opentelemetry/instrumentation-tedious0.39.0непряма
npm@opentelemetry/instrumentation-undici0.30.0непряма
npm@opentelemetry/instrumentation-winston0.64.0непряма
npm@opentelemetry/otlp-exporter-base0.220.0непряма
npm@opentelemetry/otlp-grpc-exporter-base0.220.0непряма
npm@opentelemetry/otlp-transformer0.220.0непряма
npm@opentelemetry/propagator-aws-xray2.2.0непряма
npm@opentelemetry/propagator-b32.9.0непряма
npm@opentelemetry/propagator-jaeger2.9.0непряма
npm@opentelemetry/redis-common0.38.3непряма
npm@opentelemetry/resource-detector-alibaba-cloud0.35.0непряма
npm@opentelemetry/resource-detector-aws2.20.0непряма
npm@opentelemetry/resource-detector-azure0.28.0непряма
npm@opentelemetry/resource-detector-container0.8.11непряма
npm@opentelemetry/resource-detector-gcp0.55.0непряма
npm@opentelemetry/sdk-logs0.220.0непряма
npm@opentelemetry/sdk-metrics2.9.0непряма
npm@opentelemetry/sdk-trace2.9.0непряма
npm@opentelemetry/sdk-trace-base2.9.0непряма
npm@opentelemetry/sdk-trace-node2.9.0непряма
npm@opentelemetry/sql-common0.42.0непряма
npm@pkgjs/parseargs0.11.0непряма
npm@playwright/test1.49.1непряма
npm@protobufjs/aspromise1.1.2непряма
npm@protobufjs/base641.1.2непряма
npm@protobufjs/codegen2.0.5непряма
npm@protobufjs/eventemitter1.1.1непряма
npm@protobufjs/fetch1.1.1непряма
npm@protobufjs/float1.0.2непряма
npm@protobufjs/path1.1.2непряма
npm@protobufjs/pool1.1.0непряма
npm@protobufjs/utf81.1.2непряма
npm@redis/bloom1.2.0непряма
npm@redis/client1.6.1непряма
npm@redis/graph1.1.1непряма
npm@redis/json1.0.7непряма
npm@redis/search1.2.0непряма
npm@redis/time-series1.1.0непряма
npm@smithy/core3.24.6непряма
npm@smithy/credential-provider-imds4.3.8непряма
npm@smithy/fetch-http-handler5.4.6непряма
npm@smithy/is-array-buffer2.2.0непряма
npm@smithy/node-http-handler4.7.7непряма
npm@smithy/signature-v45.4.6непряма
npm@smithy/types4.14.3непряма
npm@smithy/util-buffer-from2.2.0непряма
npm@smithy/util-utf82.3.0непряма
npm@types/aws-lambda8.10.162непряма
npm@types/body-parser1.19.6непряма
npm@types/bunyan1.8.11непряма
npm@types/connect3.4.38непряма
npm@types/express5.0.6непряма
npm@types/express^5.0.0непряма
npm@types/express-serve-static-core5.1.1непряма
npm@types/http-errors2.0.5непряма
npm@types/js-yaml4.0.9непряма
npm@types/memcached2.2.10непряма
npm@types/mysql2.15.27непряма
npm@types/node24.12.4непряма
npm@types/node25.9.2непряма
npm@types/node25.9.3непряма
npm@types/node^22.0.0непряма
npm@types/node-fetch2.6.13непряма
npm@types/oracledb6.5.2непряма
npm@types/pg8.15.6непряма
npm@types/pg-pool2.0.7непряма
npm@types/qs6.15.0непряма
npm@types/range-parser1.2.7непряма
npm@types/send1.2.1непряма
npm@types/serve-static2.2.0непряма
npm@types/stream-buffers3.0.8непряма
npm@types/tedious4.0.14непряма
npm@types/ws8.18.1непряма
npmaccepts2.0.0непряма
npmacorn8.16.0непряма
npmacorn-import-attributes1.9.5непряма
npmagent-base7.1.4непряма
npmajv8.18.0непряма
npmajv8.20.0непряма
npmajv-formats3.0.1непряма
npmansi-regex5.0.1непряма
npmansi-regex6.2.2непряма
npmansi-styles4.3.0непряма
npmansi-styles6.2.3непряма
npmargparse2.0.1непряма
npmasynckit0.4.0непряма
npmb4a1.8.1непряма
npmbalanced-match1.0.2непряма
npmbare-events2.8.3непряма
npmbare-fs4.7.1непряма
npmbare-os3.9.1непряма
npmbare-path3.0.0непряма
npmbare-stream2.13.1непряма
npmbare-url2.4.3непряма
npmbignumber.js9.3.1непряма
npmbintrees1.0.2непряма
npmbody-parser2.2.2непряма
npmbowser2.14.1непряма
npmbrace-expansion2.1.1непряма
npmbytes3.1.2непряма
npmcall-bind-apply-helpers1.0.2непряма
npmcall-bound1.0.4непряма
npmcjs-module-lexer2.2.0непряма
npmcliui8.0.1непряма
npmcluster-key-slot1.1.2непряма
npmcolor-convert2.0.1непряма
npmcolor-name1.1.4непряма
npmcombined-stream1.0.8непряма
npmcontent-disposition1.1.0непряма
npmcontent-type1.0.5непряма
npmcontent-type2.0.0непряма
npmcookie0.7.2непряма
npmcookie-signature1.2.2непряма
npmcors2.8.6непряма
npmcross-spawn7.0.6непряма
npmdata-uri-to-buffer4.0.1непряма
npmdebug4.4.3непряма
npmdelayed-stream1.0.0непряма
npmdepd2.0.0непряма
npmdunder-proto1.0.1непряма
npmeastasianwidth0.2.0непряма
npmee-first1.1.1непряма
npmemoji-regex8.0.0непряма
npmemoji-regex9.2.2непряма
npmencodeurl2.0.0непряма
npmend-of-stream1.4.5непряма
npmes-define-property1.0.1непряма
npmes-errors1.3.0непряма
npmes-object-atoms1.1.1непряма
npmes-set-tostringtag2.1.0непряма
npmesbuild0.28.1непряма
npmescalade3.2.0непряма
npmescape-html1.0.3непряма
npmetag1.8.1непряма
npmevents-universal1.0.1непряма
npmeventsource3.0.7непряма
npmeventsource-parser3.0.6непряма
npmeventsource-parser3.0.8непряма
npmextend3.0.2непряма
npmfast-deep-equal3.1.3непряма
npmfast-fifo1.3.2непряма
npmfast-uri3.1.2непряма
npmfast-xml-builder1.2.0непряма
npmfast-xml-parser5.7.3непряма
npmfetch-blob3.2.0непряма
npmfinalhandler2.1.1непряма
npmforeground-child3.3.1непряма
npmform-data4.0.6непряма
npmformdata-polyfill4.0.10непряма
npmforwarded0.2.0непряма
npmforwarded-parse2.1.2непряма
npmfresh2.0.0непряма
npmfsevents2.3.3непряма
npmfunction-bind1.1.2непряма
npmgaxios7.1.3непряма
npmgcp-metadata8.1.3непряма
npmgeneric-pool3.9.0непряма
npmget-caller-file2.0.5непряма
npmget-intrinsic1.3.0непряма
npmget-proto1.0.1непряма
npmglob10.5.0непряма
npmgoogle-logging-utils1.1.3непряма
npmgopd1.2.0непряма
npmhas-symbols1.1.0непряма
npmhas-tostringtag1.0.2непряма
npmhasown2.0.3непряма
npmhasown2.0.4непряма
npmhono4.12.26непряма
npmhpagent1.2.0непряма
npmhttp-errors2.0.1непряма
npmhttps-proxy-agent7.0.6непряма
npmiconv-lite0.7.2непряма
npmimport-in-the-middle3.0.1непряма
npminherits2.0.4непряма
npmip-address10.2.0непряма
npmipaddr.js1.9.1непряма
npmis-fullwidth-code-point3.0.0непряма
npmis-promise4.0.0непряма
npmisexe2.0.0непряма
npmisomorphic-ws5.0.0непряма
npmjackspeak3.4.3непряма
npmjose6.2.2непряма
npmjose6.2.3непряма
npmjsep1.4.0непряма
npmjson-bigint1.0.0непряма
npmjson-schema-traverse1.0.0непряма
npmjson-schema-traverse1.1.0непряма
npmjson-schema-typed8.0.2непряма
npmjsonpath-plus10.4.0непряма
npmlodash.camelcase4.3.0непряма
npmlong5.3.2непряма
npmlru-cache10.4.3непряма
npmmath-intrinsics1.1.0непряма
npmmedia-typer1.1.0непряма
npmmerge-descriptors2.0.0непряма
npmmime-db1.52.0непряма
npmmime-db1.54.0непряма
npmmime-types2.1.35непряма
npmmime-types3.0.2непряма
npmminimatch9.0.9непряма
npmminipass7.1.3непряма
npmmodule-details-from-path1.0.4непряма
npmms2.1.3непряма
npmnegotiator1.0.0непряма
npmnode-domexception1.0.0непряма
npmnode-fetch2.7.0непряма
npmnode-fetch3.3.2непряма
npmoauth4webapi3.8.6непряма
npmobject-assign4.1.1непряма
npmobject-inspect1.13.4непряма
npmon-finished2.4.1непряма
npmonce1.4.0непряма
npmopenapi-types12.1.3непряма
npmopenid-client6.8.4непряма
npmpackage-json-from-dist1.0.1непряма
npmparseurl1.3.3непряма
npmpath-expression-matcher1.5.0непряма
npmpath-key3.1.1непряма
npmpath-scurry1.11.1непряма
npmpath-to-regexp8.4.0непряма
npmpath-to-regexp8.4.2непряма
npmpg-int81.0.1непряма
npmpg-protocol1.15.0непряма
npmpg-types2.2.0непряма
npmpkce-challenge5.0.1непряма
npmpostgres-array2.0.0непряма
npmpostgres-bytea1.0.1непряма
npmpostgres-date1.0.7непряма
npmpostgres-interval1.2.0непряма
npmprotobufjs7.6.5непряма
npmproxy-addr2.0.7непряма
npmpump3.0.4непряма
npmqs6.15.2непряма
npmrange-parser1.2.1непряма
npmraw-body3.0.2непряма
npmrequire-directory2.1.1непряма
npmrequire-from-string2.0.2непряма
npmrequire-in-the-middle8.0.1непряма
npmrfc46481.5.4непряма
npmrimraf5.0.10непряма
npmrouter2.2.0непряма
npmsafer-buffer2.1.2непряма
npmsend1.2.1непряма
npmserve-static2.2.1непряма
npmsetprototypeof1.2.0непряма
npmshebang-command2.0.0непряма
npmshebang-regex3.0.0непряма
npmside-channel1.1.0непряма
npmside-channel-list1.0.1непряма
npmside-channel-list1.1.0непряма
npmside-channel-map1.0.1непряма
npmside-channel-weakmap1.0.2непряма
npmsignal-exit4.1.0непряма
npmsmart-buffer4.2.0непряма
npmsocks2.8.9непряма
npmsocks-proxy-agent8.0.5непряма
npmstatuses2.0.2непряма
npmstream-buffers3.0.3непряма
npmstreamx2.25.0непряма
npmstring-width4.2.3непряма
npmstring-width5.1.2непряма
npmstrip-ansi6.0.1непряма
npmstrip-ansi7.2.0непряма
npmstrnum2.3.0непряма
npmsysteminformation5.31.13непряма
npmtar-fs3.1.2непряма
npmtar-stream3.2.0непряма
npmtdigest0.1.2непряма
npmteex1.0.1непряма
npmtext-decoder1.2.7непряма
npmtoidentifier1.0.1непряма
npmtr460.0.3непряма
npmtslib2.8.1непряма
npmtsx4.23.1непряма
npmtsx^4.19.0непряма
npmtype-is2.1.0непряма
npmtypescript6.0.3непряма
npmtypescript^5.6.0непряма
npmundici-types7.16.0непряма
npmundici-types7.24.6непряма
npmunpipe1.0.0непряма
npmunpipe1.1.0непряма
npmvary1.1.2непряма
npmweb-streams-polyfill3.3.3непряма
npmwebidl-conversions3.0.1непряма
npmwhatwg-url5.0.0непряма
npmwhich2.0.2непряма
npmwrap-ansi7.0.0непряма
npmwrap-ansi8.1.0непряма
npmwrappy1.0.2непряма
npmxml-naming0.1.0непряма
npmxtend4.0.2непряма
npmy18n5.0.8непряма
npmyallist4.0.0непряма
npmyaml2.9.0непряма
npmyargs17.7.3непряма
npmyargs-parser21.1.1непряма
npmzod-to-json-schema3.25.1непряма
npmzod-to-json-schema3.25.2непряма
Сповіщення про залежності 2

Встановлення npm:@thotischner/observability-mcp@3.9.3 тягне 330 пакетів, прямих і транзитивних: 2 мають відомі сповіщення, з них 0 — прямі залежності.

ПакетВерсіяЗв'язокКритичністьСповіщеньВиправлено в
brace-expansion2.1.2непрямависока15.0.8
@hono/node-server1.19.15непрямапомірна12.0.5

Сповіщення означає, що версія, записана в графі залежностей, потрапляє в уражений діапазон. Досяжність не аналізується, а граф містить піниї розробки й тестування — знахідка може стосуватися інструментів, а не поставленого коду.

Звіт у форматі JSON машиночитний
{
  "data": {
    "repo": {
      "topics": [
        "ai-agents",
        "anomaly-detection",
        "anthropic",
        "claude",
        "gateway",
        "helm",
        "kubernetes",
        "llm",
        "loki",
        "mcp",
        "mcp-server",
        "model-context-protocol",
        "monitoring",
        "observability",
        "prometheus",
        "sre"
      ],
      "is_fork": false,
      "size_kb": 17972,
      "has_wiki": true,
      "homepage": "https://www.npmjs.com/package/@thotischner/observability-mcp",
      "languages": {
        "HTML": 475270,
        "Shell": 13277,
        "Makefile": 14970,
        "Dockerfile": 4205,
        "JavaScript": 603751,
        "TypeScript": 1437339,
        "Go Template": 2945
      },
      "pushed_at": "2026-07-25T09:36:54Z",
      "created_at": "2026-03-26T20:01:28Z",
      "owner_type": "User",
      "updated_at": "2026-07-21T09:26:05Z",
      "description": "Unified observability gateway for AI agents — one MCP server for Prometheus, Loki, and any backend, with cross-signal anomaly detection and a built-in Web UI.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript",
        "JavaScript",
        "HTML"
      ]
    },
    "owner": {
      "blog": "https://aisolutionscamp.io/",
      "name": "Thomas Tischner",
      "type": "User",
      "login": "ThoTischner",
      "company": "System Vertrieb Alexander GmbH",
      "location": "Nuremberg",
      "followers": 17,
      "avatar_url": "https://avatars.githubusercontent.com/u/9863411?v=4",
      "created_at": "2014-11-20T11:34:50Z",
      "is_verified": null,
      "public_repos": 43,
      "account_age_days": 4265
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v3.9.3",
          "kind": "patch",
          "published_at": "2026-07-19T23:58:02Z"
        },
        {
          "tag": "observability-mcp-2.9.3",
          "kind": "other",
          "published_at": "2026-07-19T23:57:21Z"
        },
        {
          "tag": "v3.9.2",
          "kind": "patch",
          "published_at": "2026-07-12T23:53:37Z"
        },
        {
          "tag": "observability-mcp-2.9.2",
          "kind": "other",
          "published_at": "2026-07-12T23:53:31Z"
        },
        {
          "tag": "v3.9.1",
          "kind": "patch",
          "published_at": "2026-07-06T00:05:57Z"
        },
        {
          "tag": "observability-mcp-2.9.1",
          "kind": "other",
          "published_at": "2026-07-06T00:05:44Z"
        },
        {
          "tag": "v3.9.0",
          "kind": "minor",
          "published_at": "2026-06-23T19:25:53Z"
        },
        {
          "tag": "observability-mcp-2.9.0",
          "kind": "other",
          "published_at": "2026-06-23T19:25:43Z"
        },
        {
          "tag": "v3.8.3",
          "kind": "patch",
          "published_at": "2026-06-23T17:29:48Z"
        },
        {
          "tag": "observability-mcp-2.8.3",
          "kind": "other",
          "published_at": "2026-06-23T17:29:35Z"
        },
        {
          "tag": "v3.8.2",
          "kind": "patch",
          "published_at": "2026-06-22T00:12:27Z"
        },
        {
          "tag": "observability-mcp-2.8.2",
          "kind": "other",
          "published_at": "2026-06-22T00:12:14Z"
        },
        {
          "tag": "v3.8.1",
          "kind": "patch",
          "published_at": "2026-06-18T17:12:31Z"
        },
        {
          "tag": "observability-mcp-2.8.1",
          "kind": "other",
          "published_at": "2026-06-18T17:12:08Z"
        },
        {
          "tag": "v3.8.0",
          "kind": "minor",
          "published_at": "2026-06-13T19:02:07Z"
        },
        {
          "tag": "observability-mcp-2.8.0",
          "kind": "other",
          "published_at": "2026-06-13T18:55:28Z"
        },
        {
          "tag": "v3.7.0",
          "kind": "minor",
          "published_at": "2026-06-12T11:04:00Z"
        },
        {
          "tag": "observability-mcp-2.7.0",
          "kind": "other",
          "published_at": "2026-06-12T11:03:48Z"
        },
        {
          "tag": "v3.6.1",
          "kind": "patch",
          "published_at": "2026-06-11T21:51:09Z"
        },
        {
          "tag": "observability-mcp-2.6.1",
          "kind": "other",
          "published_at": "2026-06-11T21:50:58Z"
        },
        {
          "tag": "v3.6.0",
          "kind": "minor",
          "published_at": "2026-06-11T21:10:23Z"
        },
        {
          "tag": "observability-mcp-2.6.0",
          "kind": "other",
          "published_at": "2026-06-11T21:10:02Z"
        },
        {
          "tag": "v3.5.0",
          "kind": "minor",
          "published_at": "2026-06-11T20:22:33Z"
        },
        {
          "tag": "observability-mcp-2.5.0",
          "kind": "other",
          "published_at": "2026-06-11T20:22:15Z"
        },
        {
          "tag": "v3.4.0",
          "kind": "minor",
          "published_at": "2026-06-11T19:22:26Z"
        },
        {
          "tag": "observability-mcp-2.4.0",
          "kind": "other",
          "published_at": "2026-06-11T19:22:18Z"
        },
        {
          "tag": "v3.3.2",
          "kind": "patch",
          "published_at": "2026-06-11T17:23:22Z"
        },
        {
          "tag": "observability-mcp-2.3.2",
          "kind": "other",
          "published_at": "2026-06-11T17:23:17Z"
        },
        {
          "tag": "v3.3.1",
          "kind": "patch",
          "published_at": "2026-06-10T18:12:59Z"
        },
        {
          "tag": "observability-mcp-2.3.1",
          "kind": "other",
          "published_at": "2026-06-10T18:12:51Z"
        },
        {
          "tag": "v3.3.0",
          "kind": "minor",
          "published_at": "2026-06-10T16:25:20Z"
        },
        {
          "tag": "observability-mcp-2.3.0",
          "kind": "other",
          "published_at": "2026-06-10T16:25:02Z"
        },
        {
          "tag": "v3.2.1",
          "kind": "patch",
          "published_at": "2026-06-09T22:11:28Z"
        },
        {
          "tag": "observability-mcp-2.2.1",
          "kind": "other",
          "published_at": "2026-06-09T22:11:12Z"
        },
        {
          "tag": "v3.2.0",
          "kind": "minor",
          "published_at": "2026-06-09T19:30:36Z"
        },
        {
          "tag": "observability-mcp-2.2.0",
          "kind": "other",
          "published_at": "2026-06-09T19:30:25Z"
        },
        {
          "tag": "v3.1.1",
          "kind": "patch",
          "published_at": "2026-06-09T17:40:19Z"
        },
        {
          "tag": "observability-mcp-2.1.1",
          "kind": "other",
          "published_at": "2026-06-09T17:39:13Z"
        },
        {
          "tag": "v3.1.0",
          "kind": "minor",
          "published_at": "2026-06-08T19:02:53Z"
        },
        {
          "tag": "observability-mcp-2.1.0",
          "kind": "other",
          "published_at": "2026-06-08T19:02:43Z"
        },
        {
          "tag": "v3.0.1",
          "kind": "patch",
          "published_at": "2026-06-08T00:07:20Z"
        },
        {
          "tag": "observability-mcp-2.0.2",
          "kind": "other",
          "published_at": "2026-06-08T00:07:09Z"
        },
        {
          "tag": "v3.0.0",
          "kind": "major",
          "published_at": "2026-06-06T13:24:55Z"
        },
        {
          "tag": "observability-mcp-2.0.1",
          "kind": "other",
          "published_at": "2026-06-06T12:35:03Z"
        },
        {
          "tag": "observability-mcp-2.0.0",
          "kind": "other",
          "published_at": "2026-06-06T03:04:35Z"
        },
        {
          "tag": "observability-mcp-1.0.0",
          "kind": "other",
          "published_at": "2026-06-06T00:07:39Z"
        },
        {
          "tag": "v1.8.1",
          "kind": "patch",
          "published_at": "2026-06-01T00:06:46Z"
        },
        {
          "tag": "observability-mcp-0.12.1",
          "kind": "other",
          "published_at": "2026-06-01T00:06:36Z"
        },
        {
          "tag": "observability-mcp-0.12.0",
          "kind": "other",
          "published_at": "2026-05-28T06:02:40Z"
        },
        {
          "tag": "v1.7.1",
          "kind": "patch",
          "published_at": "2026-05-25T00:00:19Z"
        },
        {
          "tag": "observability-mcp-0.11.4",
          "kind": "other",
          "published_at": "2026-05-25T00:00:13Z"
        },
        {
          "tag": "v1.7.0",
          "kind": "minor",
          "published_at": "2026-05-24T17:18:22Z"
        },
        {
          "tag": "observability-mcp-0.11.3",
          "kind": "other",
          "published_at": "2026-05-24T17:18:13Z"
        },
        {
          "tag": "v1.6.0",
          "kind": "minor",
          "published_at": "2026-05-19T20:17:33Z"
        },
        {
          "tag": "observability-mcp-0.11.2",
          "kind": "other",
          "published_at": "2026-05-19T20:17:25Z"
        },
        {
          "tag": "v1.5.1",
          "kind": "patch",
          "published_at": "2026-05-18T08:27:12Z"
        },
        {
          "tag": "observability-mcp-0.11.1",
          "kind": "other",
          "published_at": "2026-05-18T08:27:00Z"
        },
        {
          "tag": "observability-mcp-0.11.0",
          "kind": "other",
          "published_at": "2026-05-17T19:05:55Z"
        },
        {
          "tag": "v1.4.1",
          "kind": "patch",
          "published_at": "2026-05-16T08:40:25Z"
        },
        {
          "tag": "observability-mcp-0.10.1",
          "kind": "other",
          "published_at": "2026-05-16T08:40:17Z"
        },
        {
          "tag": "connector-elasticsearch-1.0.0",
          "kind": "other",
          "published_at": "2026-05-16T08:36:16Z"
        },
        {
          "tag": "observability-mcp-0.10.0",
          "kind": "other",
          "published_at": "2026-05-15T23:37:42Z"
        },
        {
          "tag": "observability-mcp-0.9.0",
          "kind": "other",
          "published_at": "2026-05-15T21:49:02Z"
        },
        {
          "tag": "connector-grafana-1.0.0",
          "kind": "other",
          "published_at": "2026-05-15T20:42:49Z"
        },
        {
          "tag": "connector-datadog-1.0.0",
          "kind": "other",
          "published_at": "2026-05-15T19:26:10Z"
        },
        {
          "tag": "observability-mcp-0.8.1",
          "kind": "other",
          "published_at": "2026-05-15T15:53:31Z"
        },
        {
          "tag": "observability-mcp-0.8.0",
          "kind": "other",
          "published_at": "2026-05-15T14:46:58Z"
        },
        {
          "tag": "observability-mcp-0.7.0",
          "kind": "other",
          "published_at": "2026-05-15T13:23:20Z"
        },
        {
          "tag": "observability-mcp-0.6.0",
          "kind": "other",
          "published_at": "2026-05-15T12:18:06Z"
        },
        {
          "tag": "observability-mcp-0.5.0",
          "kind": "other",
          "published_at": "2026-05-15T11:49:54Z"
        },
        {
          "tag": "v1.4.0",
          "kind": "minor",
          "published_at": "2026-05-14T17:23:04Z"
        },
        {
          "tag": "observability-mcp-0.3.0",
          "kind": "other",
          "published_at": "2026-05-14T17:29:04Z"
        },
        {
          "tag": "v1.3.4",
          "kind": "patch",
          "published_at": "2026-05-10T23:51:22Z"
        },
        {
          "tag": "v1.3.3",
          "kind": "patch",
          "published_at": "2026-05-03T23:42:37Z"
        },
        {
          "tag": "v1.3.2",
          "kind": "patch",
          "published_at": "2026-05-02T11:43:47Z"
        },
        {
          "tag": "v1.3.1",
          "kind": "patch",
          "published_at": "2026-05-02T11:35:05Z"
        },
        {
          "tag": "v1.3.0",
          "kind": "minor",
          "published_at": "2026-05-01T22:16:08Z"
        },
        {
          "tag": "v1.2.2",
          "kind": "patch",
          "published_at": "2026-05-01T21:08:48Z"
        },
        {
          "tag": "v1.2.1",
          "kind": "patch",
          "published_at": "2026-05-01T20:52:26Z"
        },
        {
          "tag": "v1.2.0",
          "kind": "minor",
          "published_at": "2026-05-01T20:33:06Z"
        },
        {
          "tag": "v1.1.3",
          "kind": "patch",
          "published_at": "2026-05-01T20:02:40Z"
        },
        {
          "tag": "v1.1.2",
          "kind": "patch",
          "published_at": "2026-05-01T19:35:47Z"
        },
        {
          "tag": "v1.1.1",
          "kind": "patch",
          "published_at": "2026-05-01T19:08:24Z"
        },
        {
          "tag": "v1.1.0",
          "kind": "minor",
          "published_at": "2026-05-01T18:17:05Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "888d55722bda5834210d8e9707107a41374ab619",
          "body": "Bumps the actions group with 6 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [actions/checkout](https://github.com/actions/checkout) | `7.0.0` | `7.0.1` |\n| [actions/setup-node](https://github.com/actions/setup-node) | `6.4.0` | `7.0.0` |\n| [github/codeql-action/init](https://github.com/gi\n[…]\npe: version-update:semver-patch\n  dependency-group: actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump the actions group with 6 updates (#558)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-21T09:25:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e0695e30badd4d014d903957e5d6b679899bc877",
          "body": "Bumps the production-deps group in /mcp-server with 2 updates: [express-rate-limit](https://github.com/express-rate-limit/express-rate-limit) and [ws](https://github.com/websockets/ws).\n\n\nUpdates `express-rate-limit` from 8.5.2 to 8.6.0\n- [Release notes](https://github.com/express-rate-limit/express\n[…]\nion-update:semver-patch\n  dependency-group: production-deps\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump the production-deps group (#557)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-20T20:57:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "18b2e87d4bfe58fad4294f2247e611d1ac530b6f",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): v3.9.3 (#556)",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-07-19T23:57:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "46624d6fe177f5a14692c75b9440e2975c0c5e02",
          "body": "* test(ci): add verify-only dispatch mode to prove the published-index check\n\nThe verify-published job added in #554 has never executed — both merges\ncorrectly skipped it because no chart version changed. An unexercised check\nthat first fires during a real release is a liability: if the needs/output\n[…]\nails after 18min. Proven by the negative\ndispatch run: 53 attempts, 18m23s.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(ci): prove the published-index check actually works (#555)",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-07-18T20:31:20Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8405f69dab04f382fb4dc6b6a82ce8041b85da5b",
          "body": "…ers to check (#554)\n\nPR #544 fixed the Helm publish race but closed the loop with prose: it\ndispatched docs.yml fire-and-forget, then added a troubleshooting entry\nasking users to cross-check GitHub Releases against `helm search repo` and\nopen an issue if they differed. That offloads monitoring ont\n[…]\n a user: refresh the local cache,\nand if the index is still propagating right after a release, install from\nOCI (already documented) meanwhile.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci): verify the chart is actually reachable instead of telling us…",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-07-18T14:27:58Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3b1f7f352ff6a6aa507af6a812a628d822bc4211",
          "body": "These two files (examples/federation-demo/echo-mcp.mjs and\ndocs/screenshots/inspect-federation.png) were work-in-progress for a\nfederation demo that isn't wired up yet — nothing in the repo references\neither. They rode into #544 by accident (a `git add -A` in the CI-fix\nbranch swept up untracked files). Removing them until the demo is finished\nand referenced; no code or docs point at them, so this is a clean removal.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: drop unreferenced federation-demo WIP from main (#553)",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-07-17T12:44:04Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "e1281548616ef16b11c7ab0d73d17a47e700b125",
          "body": "Bumps the actions group with 5 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [github/codeql-action/init](https://github.com/github/codeql-action) | `4.36.3` | `4.37.0` |\n| [github/codeql-action/analyze](https://github.com/github/codeql-action) | `4.36.3` | `4.37.0` |\n| [actions/labeler](ht\n[…]\npe: version-update:semver-minor\n  dependency-group: actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump the actions group with 5 updates (#552)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-13T21:01:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2ce71689cfa5cd33411c1379cd4e51c17d9f915f",
          "body": "Bumps the dev-deps group in /mcp-server with 1 update: [tsx](https://github.com/privatenumber/tsx).\n\n\nUpdates `tsx` from 4.23.0 to 4.23.1\n- [Release notes](https://github.com/privatenumber/tsx/releases)\n- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)\n- [Commits](ht\n[…]\ne: version-update:semver-patch\n  dependency-group: dev-deps\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump tsx in /mcp-server in the dev-deps group (#548)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-13T20:59:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1f6e9aca2852f6f80012890fc43d8069fcbc3a5d",
          "body": "Bumps the production-deps group in /mcp-server with 1 update: [@opentelemetry/semantic-conventions](https://github.com/open-telemetry/opentelemetry-js).\n\n\nUpdates `@opentelemetry/semantic-conventions` from 1.42.0 to 1.43.0\n- [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases\n[…]\nion-update:semver-minor\n  dependency-group: production-deps\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump @opentelemetry/semantic-conventions (#545)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-13T20:58:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9e7b76f2984dce5e21522aacb4b8806d0b782b2c",
          "body": "…546)\n\nBumps the all-deps group in /examples/agent with 1 update: [tsx](https://github.com/privatenumber/tsx).\n\n\nUpdates `tsx` from 4.23.0 to 4.23.1\n- [Release notes](https://github.com/privatenumber/tsx/releases)\n- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)\n- [\n[…]\ne: version-update:semver-patch\n  dependency-group: all-deps\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump tsx in /examples/agent in the all-deps group (#…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-13T20:58:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "802f68fa597a16a5774b855d78ecdaeffe3504bd",
          "body": "…e chart (#544)\n\nThe v3.9.2 `Publish Helm chart` run failed. Two causes, one root.\n\nA release commit fires helm-release.yml twice: the push to main touches\nhelm/**, and tag-on-release.yml then pushes the v* tag (path filters don't\napply to tag pushes). Both runs call `cr index`, which pulls, rewrite\n[…]\nort the\njob would recreate the exact bug the step exists to prevent.\n\nAlso document the symptom and the OCI fallback in the Helm install guide.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci): stop the Helm release racing itself, and actually publish th…",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-07-13T10:33:16Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "419ef207dd0b3c8d23ba2bc1f400fa017386f065",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): v3.9.2 (#543)",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-07-12T23:53:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "65e02c2570ff01d07c04b806be71879677bb3055",
          "body": "Bumps the actions group with 8 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [github/codeql-action/init](https://github.com/github/codeql-action) | `4.36.2` | `4.36.3` |\n| [github/codeql-action/analyze](https://github.com/github/codeql-action) | `4.36.2` | `4.36.3` |\n| [docker/setup-buildx\n[…]\nendency-type: direct:production\n  dependency-group: actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump the actions group with 8 updates (#542)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-06T21:01:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6e2a6257369b630b8ee2e441217419ac8d863660",
          "body": "Bumps the dev-deps group in /mcp-server with 1 update: [tsx](https://github.com/privatenumber/tsx).\n\n\nUpdates `tsx` from 4.22.4 to 4.23.0\n- [Release notes](https://github.com/privatenumber/tsx/releases)\n- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)\n- [Commits](ht\n[…]\ne: version-update:semver-minor\n  dependency-group: dev-deps\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump tsx in /mcp-server in the dev-deps group (#538)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-06T20:59:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dd2b8b750c86bf72aaccd4efea9991e65a99279d",
          "body": "Bumps the production-deps group in /mcp-server with 5 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [@opentelemetry/auto-instrumentations-node](https://github.com/open-telemetry/opentelemetry-js-contrib/tree/HEAD/packages/auto-instrumentations-node) | `0.77.0` | `0.78.0` |\n| [@opentelemetr\n[…]\nion-update:semver-minor\n  dependency-group: production-deps\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump the production-deps group (#537)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-06T20:58:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "065e2323f598347d477732b87fe8dbe1d4bd3801",
          "body": "…535)\n\nBumps the all-deps group in /examples/agent with 1 update: [tsx](https://github.com/privatenumber/tsx).\n\n\nUpdates `tsx` from 4.22.4 to 4.23.0\n- [Release notes](https://github.com/privatenumber/tsx/releases)\n- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)\n- [\n[…]\ne: version-update:semver-minor\n  dependency-group: all-deps\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump tsx in /examples/agent in the all-deps group (#…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-06T20:57:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2ac50cf0de6f2319d960bf5a2f448d3bab1d9164",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): v3.9.1 (#534)",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-07-06T00:05:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "68240cb97452d7b22b79896f72efc485766e9c09",
          "body": "Bumps the actions group with 2 updates: [actions/setup-python](https://github.com/actions/setup-python) and [azure/setup-helm](https://github.com/azure/setup-helm).\n\n\nUpdates `actions/setup-python` from 6.2.0 to 6.3.0\n- [Release notes](https://github.com/actions/setup-python/releases)\n- [Commits](ht\n[…]\npe: version-update:semver-patch\n  dependency-group: actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump the actions group with 2 updates (#533)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-30T10:30:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f4269ad85015d978a6b4d139ffb4b80b48fa8cb8",
          "body": "Feature release: per-credential tool allow-list (OMCP_KEY_TOOLS, #526) + strict plugin signatures (PLUGIN_REQUIRE_SIGNATURE, #527). Both default-OFF. mcp-server 3.9.0 / Helm 2.9.0.",
          "is_bot": false,
          "headline": "chore(release): v3.9.0 (#528)",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-23T19:25:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "13b3b74b6eeec3ea42d8a7b005c26bc3129f9c81",
          "body": "…(#527)\n\nDefault-OFF strict mode: a present-but-unverifiable filesystem plugin (incl. malformed manifest) or missing trust root aborts startup instead of silently skipping. Implies VERIFY_PLUGINS; builtins never gated; Helm plugins.verify.requireSignature. Reviewer SHIP + malformed-manifest gap folded in; loader suite 17/0.",
          "is_bot": false,
          "headline": "feat(plugins): PLUGIN_REQUIRE_SIGNATURE strict load-time enforcement …",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-23T18:42:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3671774bd7ee18fd9e84532b968fbd6aea367942",
          "body": "Per-credential tool allow-list as a second fail-closed allow-list axis (default-OFF, composes with Products by intersection). Advances the per-credential RBAC roadmap item. Reviewer SHIP; full suite green.",
          "is_bot": false,
          "headline": "feat(rbac): per-credential tool allow-list (OMCP_KEY_TOOLS) (#526)",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-23T17:57:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b2740d8a88eea34b9b84bf667c25e6dcbb55bec5",
          "body": "Bug-fix release shipping the #523 enrich_ips RDAP rate-limit fix (#524). Bumps mcp-server 3.8.3 + Helm chart 2.8.3; refreshes ArtifactHub changes block; CHANGELOG [3.8.3] + backfilled [3.8.2].",
          "is_bot": false,
          "headline": "chore(release): v3.8.3 (#525)",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-23T17:29:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bfefef79599dd61e90db3889b84e9997a1c7deaa",
          "body": "Closes #523. RDAP lookups now resolve to ok/not_found/transient; transient (429/403/5xx/timeout/network) is never cached and retried with capped backoff. enrich_ips surfaces transient:true/error + summary.transient + note. Full suite green; reviewer SHIP.",
          "is_bot": false,
          "headline": "fix(enrich_ips): distinguish RDAP rate-limit from a true negative (#524)",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-23T17:18:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3308ae813f1af979417e061e7cb9d9672cddc709",
          "body": "… (#522)\n\nBumps the actions group with 3 updates in the / directory: [actions/checkout](https://github.com/actions/checkout), [softprops/action-gh-release](https://github.com/softprops/action-gh-release) and [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action).\n\n\nUpdates `action\n[…]\nendency-type: direct:production\n  dependency-group: actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump the actions group across 1 directory with 3 updates…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-23T10:35:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2b0ddb2a6cf5710b0d6d43be92bf72ea3e307c42",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): v3.8.2 (#519)",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-22T00:12:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b3c5c17273cc0465086cfcbd84fef8bd26a578c5",
          "body": "… updates (#513)\n\nBumps the production-deps group with 4 updates in the /mcp-server directory: [@opentelemetry/auto-instrumentations-node](https://github.com/open-telemetry/opentelemetry-js-contrib/tree/HEAD/packages/auto-instrumentations-node), [@opentelemetry/exporter-trace-otlp-http](https://gith\n[…]\nion-update:semver-minor\n  dependency-group: production-deps\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump the production-deps group across 1 directory with 4…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-18T17:16:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ca4ffd0e3527bece9ffa971517ada0bc5eb62f9d",
          "body": "Bumps the dev-deps group with 1 update in the /mcp-server directory: [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node).\n\n\nUpdates `@types/node` from 25.9.2 to 25.9.3\n- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)\n- [Commits](https:\n[…]\ne: version-update:semver-patch\n  dependency-group: dev-deps\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump @types/node (#514)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-18T17:16:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "aa8883bc4c7d152881f12b8f1e71cf02fb8cb532",
          "body": "Security patch release — patch transitive hono/form-data/protobufjs/@opentelemetry-core CVEs via npm overrides; bump mcp-server 3.8.1 + Helm chart 2.8.1. Clears 21 code-scanning + 1 Dependabot alert.",
          "is_bot": false,
          "headline": "chore(release): v3.8.1 (#518)",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-18T17:11:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9131a6b83d84cb6714089914d4f08ebd2c3fee57",
          "body": "…(#512)\n\nCuts v3.8.0: bumps mcp-server to 3.8.0 and the Helm chart to 2.8.0\n(appVersion 3.8.0, ArtifactHub image/changes refreshed), adds the\n[3.8.0] CHANGELOG section, and presents the new Inspect feature in the\nREADME with a hero flow-graph screenshot + a learn-a-profile screenshot.\n\nAdditive / non-breaking — every new control is default-OFF, so existing\ndeployments behave exactly as before and the air-gapped default is\nunchanged.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): v3.8.0 — Inspect + entitlement model + UI lock optic …",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-13T18:55:16Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "90fb80ef0197e5f5fcaf122b8981434fc13ce2ba",
          "body": "Enterprise features now read as \"visible but locked\" without a license,\ninstead of silently inert. enterprise-gate exposes entitledFeatures() — a\nflat {feature: bool} map over the fixed ENTITLEABLE_FEATURES vocabulary\n(access-control, audit, inspect-enforce, sso, scim, tenancy) — surfaced\nonce at bo\n[…]\n-when-OFF + vocabulary completeness;\nPlaywright entitlement-locks spec asserts badges + banners on the live\nUI (added to the smoke Dockerfile).\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(ui): consistent lock-badge optic for entitled features (#511)",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-13T18:24:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "52adf208a8e459a5cc8a67e9c9585b902930fff9",
          "body": "…P calls) (#510)\n\nMCP_URL.replace(\"/mcp\", \"/api/sources\") matched the \"/mcp\" inside the\nhost \"//mcp-server\", rewriting the URL to http://api/sources-server:3000/mcp\n→ ENOTFOUND. The demo agent therefore never passed its readiness wait,\nnever connected, and made zero MCP tool calls — so the Inspect F\n[…]\nThe\nMCP transport still uses MCP_URL verbatim. Verified live: the agent now\nconnects, lists 12 tools, runs scans, and calls surface in Inspect.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(agent): derive API base by anchored /mcp strip (demo made zero MC…",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-13T18:09:28Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7b08bd6273d55397d745c24bec2f7a1bc7d4ebee",
          "body": "…(#509)\n\nThe gateway is always tenant-scoped, but every principal lands in the\n`default` tenant unless an operator actively maps identities to\nnon-default tenants (an OIDC tenant claim, or OMCP_KEY_TENANTS pointing a\ncredential at a non-default tenant). The single-tenant default — the\nopen-source pa\n[…]\n across tenant boundaries). Detection is a pure, unit-tested\npredicate (isMultiTenantConfigured); /api/info gains a `multiTenant`\nposture flag.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(tenancy): active multi-tenancy requires the tenancy entitlement …",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-13T16:27:11Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b0e9374960bcdcc563f8f09a33913bea897a6b98",
          "body": "OMCP_SCIM_TOKEN now gates on a valid `scim` entitlement. The open-source\nauth surface — local users (OMCP_USERS_FILE) and api-keys — stays free\nand unchanged; SCIM is OFF by default, so an unconfigured deployment is\nunaffected.\n\nFail-closed: with OMCP_SCIM_TOKEN set but no entitlement the gateway\nke\n[…]\nful empty note.\n\n/api/info: scimEnabled now means \"active\" (configured AND entitled);\nadds scimConfigured for the token-present posture signal.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(scim): SCIM provisioning requires the scim entitlement (#508)",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-13T16:12:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9ca73ab9019624e1690d6614a58bdaca0f57d295",
          "body": "OMCP_AUTH=oidc now gates on a valid `sso` entitlement. The open-source\nauth surface — anonymous, basic (local users), and api-key — stays free\nand unchanged; only delegating identity to an external IdP is entitled.\n\nFail-closed: with OMCP_AUTH=oidc set but no entitlement the server\nrefuses to start \n[…]\nntitled(name)\n(inspectEnforceEntitled delegates to it), the seam SCIM and multi-tenancy\nwill reuse. Default-OFF returns false and never throws.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(auth): SSO/OIDC requires the sso entitlement (#507)",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-13T16:00:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "81ed4748d87b1b403799693994ba38d58996ffbc",
          "body": "… free) (#506)\n\nInspect's active blocking (enforce) is now gated by an entitlement; the live\ngraph, learning a profile, and dry-run would-block deviations remain free/OSS.\nDefault-OFF (no token) is unchanged — only enforce is affected.\n\n- enterprise-gate.ts: active gate exposes inspectEnforce (has \"\n[…]\n unit tests for the entitlement guard; the live E2E asserts the\n  gate (enforce→403 unlicensed, dry-run free; blocks when entitled). docs note.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(inspect): make enforce an entitled control (observe/dry-run stay…",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-13T15:43:58Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6efa3794896f1e2ca21b7689b0ce52207e4be682",
          "body": "Query args (query/expr/promql/logql) were collapsed to \"present\". Now derive a\nstructural fingerprint — functions, metric name(s), label keys — so a profile\nrule can distinguish \"query_metrics on metric X\" from \"...on Y\", and the\ndrill-down/editor show which metric/labels a call touched. The literal\n[…]\nnew observations store a fingerprint where old ones stored \"present\";\nsince Inspect is unreleased there are no profiles in the wild to migrate.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(inspect): finer query signatures (PromQL/LogQL fingerprint) (#505)",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-13T15:24:55Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "400d501be9aac8e74026794dc8664dc2c56ac4dc",
          "body": "* feat(inspect): one-click \"add to profile\" from a deviation\n\nEach Deviations row gets an \"Add to profile\" action that absorbs exactly that\nobserved call shape into the accepted profile — widening the matching\n(subject,tool) rule (sorted union of source/service/namespace + arg buckets)\nor creating a\n[…]\nolluting names before\nassigning. Functionally identical for real arg names.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(inspect): one-click add-to-profile from a deviation (#504)",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-13T15:03:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8de2debf7d1117157b79b6491bfde75d1ceae0f4",
          "body": "…ws (#503)\n\nAccepting a rule was all-or-nothing. Add an Edit action on suggested and\naccepted rules that opens a modal of toggle chips — one per observed\nsource/service/namespace value and per arg-shape bucket — so you can uncheck\nthe values a rule should NOT allow, then Save or Save & accept. Persi\n[…]\noth contexts. Playwright asserts the editor opens\nand that chips carry the real value (not the checkbox default), guarding the\nsave round-trip.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(inspect): granular rule editor — narrow which values a rule allo…",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-13T14:30:55Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "28c06ccff0d1988cdf75e41d0e12b00d81b2bc51",
          "body": "Clicking a node or edge in the Flows graph now lists the actual underlying\nobservations — time, principal, tool, backend, exact argument shape, outcome\nand decision — so you can look into the calls, not just aggregate counts.\n\n- API: /api/inspect/events gains a `backend` filter (service|source|names\n[…]\n are arbitrary tool-call arg names); decision chips are static.\n- Playwright: node-drill test asserts the panel renders with no console errors.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(inspect): drill into the real calls behind a node/edge (#502)",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-13T14:11:48Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "de10e98743df93f9338c524a4efcfc99a9db9c38",
          "body": "The governance features (Access Control, Products, Policies, Inspect, Audit,\nCatalog) answer different questions but read as overlapping. Add a compact\n\"How governance fits together\" overview on the Access Control page showing the\nlayered flow (Identity → Offer → Permission → Behavior, with Catalog \n[…]\narned; Products = offered vs Policies = permitted). Static markup\n+ CSS only. Playwright governance spec asserts the overview flow + subtitles.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(ui): governance overview + per-tab clarifying subtitles (#501)",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-13T14:00:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9262f8b5924951a045a08cb76adb32c5339333a1",
          "body": "…) (#500)\n\nThe hub catalog 404s at /hub/index.json. Root cause: GitHub Pages is built\nfrom main by docs.yml (MkDocs + a merge of the gh-pages Helm artifacts into\nsite/), NOT from the gh-pages branch — so the hub/ subtree that hub-pages.yml\npublishes to gh-pages was never part of the served site (tha\n[…]\non + /hub/catalog/*.json resolve on the Pages site. Merging this\nre-runs docs.yml (it watches its own path), rebuilding Pages with the catalog.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(hub): serve the connector catalog from the Pages site (docs build…",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-13T13:50:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "910acbd8363b59a043799e0618d99cce39e1b75c",
          "body": "In Installed Connectors only datadog showed a description; the builtins\n(prometheus/loki/kubernetes) showed none. They load via loadBuiltins() with\nno manifest, so describeInstalled() fell back to an empty description (datadog\nloads from a filesystem manifest, which carries one). Attach inline manif\n[…]\nmetadata (displayName/version/description/signalTypes, mirroring\nplugins/<name>/manifest.json) to each builtin registration so the UI shows it.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(connectors): show descriptions for builtin connectors (#499)",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-13T13:50:10Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3b7e10383b27948b0f19775c192896d57177d274",
          "body": "… (#498)\n\nThe hub catalog 404s at /hub/index.json even though the files exist on the\ngh-pages branch: GitHub Pages runs Jekyll by default, which drops the static\n/hub/ subtree (root index.yaml still serves, hence helm worked but the hub\ndidn't). Write a root .nojekyll in the hub-pages publish step s\n[…]\nn + /hub/catalog/*.json then resolve.\nIdempotent. Merging this re-runs the workflow (it triggers on its own path),\nrepublishing with .nojekyll.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(hub): publish .nojekyll so the connector hub catalog is reachable…",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-13T13:35:00Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "af47eac642c1bda0d5acacdafb2ff4c0454db15d",
          "body": "Rejected rules vanished from the Profile tab — renderInspectProfile only\nlisted suggested + accepted, so a rejected suggestion disappeared entirely\n(it persists server-side and is correctly excluded from re-derive, but the\nuser had no way to see or undo it).\n\nAdd a \"Rejected rules\" section: a table \n[…]\ne rejected total. Playwright Profile test extended to reject → assert it\nstays visible in the Rejected section with a Restore button → restore.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(inspect): keep rejected profile rules visible with restore (#497)",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-13T13:24:58Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "22ae99c80354984d81bc98072b31e95a2d36079f",
          "body": "…P5) (#496)\n\nFinal phase of the Inspect feature.\n\n- inspect/enforcer.ts: a tool_pre_invoke hook that BLOCKS (and records a\n  `blocked` observation) for calls outside the accepted profile — only when\n  mode=enforce; pass-through (no eval) in off/observe/dry-run. Fails OPEN: any\n  internal error retur\n[…]\nenforce-confirm Playwright test (open+cancel).\n  Full suite 954 pass / 0 fail; tsc clean; 5/5 inspect Playwright specs green.\n  Reviewer: SHIP.\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(inspect): enforce mode — block out-of-profile calls + full E2E (…",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-13T10:52:55Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4ef43d8fbde4a3b8486c44591a51781819ce4a1a",
          "body": "Phase 4. Dry-run evaluates calls against the accepted profile and surfaces\ndeviations — but never blocks (blocking is P5).\n\n- recorder.ts: optional `evaluator`; when mode.evaluating (dryrun/enforce) the\n  post-invoke recorder evaluates the derived signature against the accepted\n  profile and records\n[…]\nh + Deviations\n  test green in a real browser. Full suite 948 pass / 0 fail; tsc clean.\n  Reviewer: SHIP (no blocking leak; all cells escaped).\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(inspect): dry-run (complain) mode + Deviations view (P4) (#495)",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-13T10:34:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0af93fabb22b26da61975259382b78aa2d88540f",
          "body": "* feat(inspect): behavior profile — derive, review + accept rules (P3)\n\nPhase 3 of the Inspect feature: the AppArmor-style learn loop. Suggestions\nonly — no enforcement on the call path yet.\n\n- inspect/profile.ts: deriveProfile (one rule per subject+tool, union of\n  observed resource dims + arg-shap\n[…]\nduction uses the operator-set OMCP_INSPECT_PROFILE_FILE (never a temp dir).\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(inspect): behavior profile — derive, review + accept (P3) (#494)",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-13T10:18:24Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "749d466be2da6e9cdb7b567231f2697d0c535da3",
          "body": "* feat(inspect): Flows live graph UI — Kiali-style identity→tool→backend view (P2)\n\nPhase 2 of the Inspect feature. Adds the \"Inspect\" tab (Governance group)\nwith a live Flows graph in the single-file console.\n\n- New #page-inspect with a Flows sub-tab: an SVG graph laid out in three\n  columns (Ident\n[…]\naddressed\nuniquely. Verified: inspect + topology specs both green together.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(inspect): Flows live graph UI (P2) (#493)",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-13T09:51:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b8c99c76485fb6c958fcc6832d2c39fa1231eeab",
          "body": "…PI (P1) (#492)\n\nPhase 1 of the Inspect feature (observe → learn → enforce). Observe-only,\ndefault mode, zero enforcement, no new egress.\n\n- mcp-server/src/inspect/: signature (redacted arg-shape derivation; resource\n  dims kept, literals never), store (ring + optional JSONL mirror, best-effort,\n  n\n[…]\n clean. Reviewer: SHIP.\n\nModes dryrun/enforce are settable but only record until the evaluator lands in\na later phase (no UI exposes them yet).\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(inspect): observe core — record MCP tool calls, flows + events A…",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-13T09:24:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "25b9aea33de0f729800fd58f225b961aa33acf26",
          "body": "…rce) (#490)\n\nAdds docs/inspect.md describing the AppArmor-learning-mode + Kiali-style\nflow-graph feature for MCP tool calls: the off/observe/dryrun/enforce state\nmachine, what gets captured (signatures/shapes, not raw args; redacted),\nthe profile model + deviation kinds, the Inspect tab (Flows/Prof\n[…]\npped/privacy posture. Wired into the mkdocs nav under Audit & Compliance.\n\nDesign artifact for the multi-phase Inspect build (P0); no code yet.\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(inspect): design doc for the Inspect feature (observe→learn→enfo…",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-13T09:06:42Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "95b107eff05332b2806597bc6c2e167b5b085435",
          "body": "… (#491)\n\nnpm-audit started failing on main: esbuild ≤0.28.0 has a high-severity\nadvisory (GHSA-gv7w-rqvm-qjhr binary-integrity RCE + GHSA-g7r4-m6w7-qqqr\ndev-server file read). esbuild is a transitive dev dependency via tsx\n(~0.28.0). Pin it forward with an npm override to 0.28.1 (the patched\nreleas\n[…]\n\n`npm audit --audit-level=high` → 0 vulnerabilities in both packages;\ntsc + full unit suite (894 pass / 0 fail) green under the bumped esbuild.\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci): override esbuild ^0.28.1 to clear GHSA-gv7w-rqvm-qjhr (high)…",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-13T09:02:42Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e8347120ce0a02ba8fa3dcfbb0d7824c1286f796",
          "body": "…487)\n\n`Verify listing` ran `curl -fsS <url> | head -c 600` under `set -euo\npipefail`. head closes the pipe after 600 bytes, curl gets SIGPIPE /\na write error and exits 23, and pipefail fails the whole job — even\nthough `Publish server metadata` succeeded and the registry serves the\nnew version. It \n[…]\nSION is listed\n(grep -qF), retries with backoff for the registry's eventual\nconsistency, and prints a truncated preview guarded with `|| true`.\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci): MCP-registry verify step no longer false-fails on exit 23 (#…",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-12T11:39:18Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "48a4303f145db0904487beabbba06ba7933c500c",
          "body": "Feature release — optional online RDAP enrich_ips backend (#477), OFF by\ndefault. Offline CSV stays preferred; the air-gapped default is unchanged.\n\n- mcp-server 3.6.1 → 3.7.0 (+ lock root version)\n- helm chart 2.6.1 → 2.7.0, appVersion/image → 3.7.0, artifacthub changes\n- CHANGELOG [3.7.0] + ROADMAP v3.7 shipped\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): v3.7.0 (#486)",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-12T11:03:35Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f936cb7a6a3b538c0cef855772cdfc5171e494e1",
          "body": "… (#485)\n\n* feat(enrich_ips): optional online RDAP backend, OFF by default (issue #477)\n\nFor non-air-gapped operators who don't want to provision a MaxMind licence\njust to answer \"where is this IP / is it a datacenter\", enrich_ips can now\nfall back to an online RDAP lookup (RFC 9082/9083) over HTTPS\n[…]\nl happens unless the\noperator opts in; the air-gapped default is preserved.\n\nCo-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(enrich_ips): optional online RDAP backend, OFF by default (#477)…",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-11T22:21:18Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7dfcaf71168bb0f4224a563a062d571fa7a561fb",
          "body": "Security + agent-feedback patch:\n\n- enrich_ips advertises IPv6 in its MCP tool description + ips param —\n  was IPv4-only in tools/list despite working since 3.4.0 (#476)\n- OpenSSL libssl3/libcrypto3 upgraded to 3.5.7-r0 in the runtime image,\n  clearing the Trivy base-image CVEs\n- 14 CodeQL alerts tr\n[…]\ncode already defensive) — no code change, recorded for audit\n\nmcp-server 3.6.0→3.6.1; helm chart 2.6.0→2.6.1 (appVersion 3.6.1). SDK unchanged.\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): v3.6.1 (#484)",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-11T21:50:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "18a15b5ea6251857d25607514cac4208e3f9fc71",
          "body": "…mage CVEs (#483)\n\nThe pinned node:26-alpine digest ships libcrypto3/libssl3 3.5.6-r0 — a\nbatch of ~15 OpenSSL CVEs Trivy flags on the image. The Alpine repo\nalready carries the 3.5.7-r0 fix, so the runtime stage now runs\n`apk upgrade --no-cache libcrypto3 libssl3` to pull just those packages\nat build time — no wait for a new base digest, no broad upgrade.\n\nVerified: image builds; libssl3 + libcrypto3 are 3.5.7-r0 in the result.\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(docker): patch OpenSSL (libssl3/libcrypto3) to clear Trivy base-i…",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-11T21:42:44Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9f39ae80f73602e8ec3d738861bc58046c2c1764",
          "body": "…am (issue #476) (#482)\n\nIPv6 lookup shipped in 3.4.0 (#469) but the agent-facing tools/list\nsurface — the inline registerTool description + `ips` param in index.ts,\nwhich is what an agent actually reads — still said \"IPv4 addresses\". So\nan agent doing access-log geo classification would pre-filter \n[…]\ne to a v6\nliteral, and added the don't-pre-filter-v6 hint. Conformance assertion\n(live tools/list) guards the advertise surface; live-verified.\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(enrich_ips): advertise IPv6 in the MCP tool description + ips par…",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-11T21:30:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "13d5dce449d90e657baa5d30a9a311cc7dba1695",
          "body": "Closes the last v3.3 candidate — the SCIM Provisioning UI.\n\n- read-only SCIM Provisioning dashboard sub-tab + GET /api/provisioning\n  (admin-gated, secret-free view of IdP-pushed Users/Groups; configured:false\n  with a note when SCIM is disabled) (#480)\n\nmcp-server 3.5.0→3.6.0 (minor: additive feature); helm chart 2.5.0→2.6.0\n(appVersion 3.6.0). SDK unchanged. The v3.3 candidate set is now complete —\nevery item shipped.\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): v3.6.0 (#481)",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-11T21:09:43Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5afb92832fee064694d0be23bc6364c27b0f0f4a",
          "body": "…b) (#480)\n\nCloses the last v3.3 candidate. A dashboard view of the Users/Groups an\nidentity provider has pushed via SCIM 2.0, without exposing the\ntoken-gated /scim/v2 API to a browser session.\n\n- scim/provisioning-view.ts: projectProvisioning(store) — a pure,\n  secret-free projection (userName/dis\n[…]\n count) + openapi. Live-verified end to end:\nno-SCIM → configured:false+note; SCIM-enabled → the pushed user appears\nprojected and secret-free.\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(scim): read-only Provisioning UI sub-tab + /api/provisioning (C2…",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-11T21:00:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a6f40e34140f18ec7e5978c4ad8d1e3b5edfe2ea",
          "body": "Candidate-cleanup release closing the remaining v3.3 candidates:\n\n- SCIM filter (<attr> eq) + startIndex/count pagination on GET /Users and\n  /Groups (RFC 7644); ServiceProviderConfig advertises filter.supported (#475)\n- custom post-mortem template engine via OMCP_POSTMORTEM_TEMPLATE\n  ({{token}} pl\n[…]\n 3.5.0). SDK unchanged. The SCIM Provisioning UI\nsub-tab is the one remaining v3.3 candidate (deferred — IdPs reconcile\ndirectly via /scim/v2).\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): v3.5.0 (#479)",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-11T20:22:00Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "88791761fbb081e57dc1d10961936fc11492358d",
          "body": "generate_postmortem's markdown layout is now overridable. Set\nOMCP_POSTMORTEM_TEMPLATE to a file of {{token}} placeholders to match\nyour own incident-report format; unset → the built-in layout, unchanged.\n\n- synthesizer.ts: synthesizePostmortem accepts an optional `template`.\n  When set it renders v\n[…]\nation (known/unknown tokens, empty-section placeholders) +\ntool env-load (used when set, fallback when unset/unreadable). Docs:\npostmortems.md.\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(postmortem): custom report template engine (v3.3 candidate) (#478)",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-11T20:11:55Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2fc4f0d8f657192be3de2a8c1843c25a73f596cb",
          "body": "…nts (#475)\n\nSCIM 2.0 candidate. GET /Users and /Groups previously returned the whole\nlist with no filter — Okta requires `filter` for reconciliation and large\ndirectories need paging.\n\n- new scim/query.ts: parseScimFilter (eq on a string attr, or boolean for\n  `active eq true`; a non-eq/malformed f\n[…]\ntional UI Provisioning sub-tab is tracked\nseparately — IdPs reconcile directly via /scim/v2, so the dashboard view\nis lower-value and deferred.\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(scim): filter + pagination on the Users/Groups collection endpoi…",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-11T19:54:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b784e3dac2403bd20745c6b6ee74741c4bb6c672",
          "body": "…s (#473)\n\nThe \"strict-mode MkDocs build\" v3.3 candidate is already done: docs.yml\nruns `mkdocs build --strict`, so a broken cross-repo link fails CI today.\nVerified `mkdocs build --strict` is clean (exit 0, no warnings). Removed\nit from the candidate list with a one-line pointer — same roadmap-hygiene\nclass as the earlier reconcile.\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(roadmap): strict-mode MkDocs already ships — drop from candidate…",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-11T19:44:45Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f017944165b70e930a126767e5694eb96bdf517b",
          "body": "Roadmap-candidate release bundling five merged slices:\n\n- enrich_ips IPv6 + offline MaxMind GeoLite2 → CSV converter (v3.3 candidate, #469)\n- per-credential raw_query gating via OMCP_KEY_RAW_QUERY (v3.3 candidate, #470)\n- honest no-data/partial states across list_services / list_sources /\n  get_blas\n[…]\n two additive features); helm chart 2.3.2→2.4.0\n(appVersion 3.4.0). SDK unchanged. ROADMAP: the two shipped candidates moved\nto a v3.4 section.\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): v3.4.0 (#472)",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-11T19:22:00Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "48c438b3fca1f736454de792b57c7911591a98d6",
          "body": "…#468)\n\nThe \"CLI hash-password.mjs stays in sync\" guard reads the repo-root\nscripts/hash-password.mjs via ../../../scripts. The docker-first unit-test\ncommand mounts only mcp-server/ (`-v \"$(pwd)/mcp-server:/app\"`), so the\nrepo-root scripts/ dir is absent → the test ENOENT-failed on every local\nrun,\n[…]\nd out, so it runs and asserts exactly\nas before; a real move/rename of the script in CI still fails loudly. The\ndrift assertions are unchanged.\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci): de-flake the hash-password sync test under a partial mount (…",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-11T19:12:23Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2927e890b4595bed9bee3d22e398d247eb9aa5ea",
          "body": "…(R5 audit) (#471)\n\nA systematic sweep for the \"absent ≠ zero / silent-partial\" class behind\n#453/#462 turned up four remaining gaps; all fixed additively (existing\nsuccess-path output unchanged):\n\n- list_services: an empty result now says WHY — no backends configured,\n  discovery failed on all sour\n[…]\ning.\n\nTests: list_services no-data/all-failed/partial, list_sources no-data,\nblast-radius no-connector, postmortem no-signal banner + coverage.\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(tools): honest no-data/partial states across the remaining tools …",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-11T19:06:27Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1ed1e6efd7c08a6914e8d0b4df36f49c050a0f18",
          "body": "…andidate) (#470)\n\nraw_query was a global-only capability (OMCP_RAW_QUERY=on) — every session\nor none. Now a credential can be granted it individually, mirroring the\nOMCP_KEY_BYPASS_REDACTION precedent exactly.\n\n- credentials.ts: Credential.allowRawQuery, parsed from\n  OMCP_KEY_RAW_QUERY=\"agent,ci\" \n[…]\nbal enable\nstill works; anonymous with neither set stays gated off). Tests: credential\nparse, principalContext passthrough. Docs: raw-query.md.\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(raw_query): per-credential gating via OMCP_KEY_RAW_QUERY (v3.3 c…",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-11T18:53:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3edfc475a6df7a9630cef35d4ef90ed052014e68",
          "body": "…#469)\n\nCloses the v3.3 candidate. enrich_ips previously skipped IPv6 rows and\nrejected IPv6 inputs; now both families are first-class.\n\n- ip-dataset.ts: ipv6ToBigInt (handles :: zero-compression + IPv4-mapped\n  tails) + parseCidr6 (128-bit BigInt ranges). The dataset keeps a\n  separate v6 range tab\n[…]\nts: v6 parse/cidr/lookup + v4/v6 independence, tool-level v6 input,\nand an e2e converter spawn test (wired into security.yml CI). Docs updated.\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(enrich_ips): IPv6 support + offline GeoLite2 dataset converter (…",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-11T18:39:47Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8b5a99cf21a7c22f0e209f1741e5c40a422941a8",
          "body": "The vision lists had drifted: several \"Next\"/\"Later\" items had already\nshipped, and a whole \"v3.0 — next\" block duplicated \"v3.0 — shipped\".\n\n- Removed the redundant \"v3.0 — next\" block (every item is under v3.0 — shipped).\n- Moved two shipped-but-unlisted features to \"Earlier — landed\": the\n  embed\n[…]\nrivate\n  `.claude/plans` directory in the v4.x blurb / deleted block.\n\nDocs-only; reviewer-verified each shipped/open claim against the source.\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(roadmap): reconcile Next/Later against shipped state (#467)",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-11T18:16:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0fe2a588ba50f544f8cd30c20ee2dda92e558046",
          "body": "Agent-feedback patch bundling three fixes from two reports against 3.3.1\n(#462 and the reopened #452):\n\n- query_metrics reports no-data honestly (summary:null + note), not false\n  all-zeros, for a service with no matching series (#462)\n- query_logs error/no-data responses report `window` (the look-b\n[…]\n; helm chart 2.3.1→2.3.2 (appVersion 3.3.2).\nMetricResult.summary/MetricGroup.summary are now nullable (additive\nno-data state). SDK unchanged.\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): v3.3.2 (#466)",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-11T17:22:53Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8617e8eb3575b8d4eb971eeb278cef485f62d1e2",
          "body": "…ssue #452 leftover #2) (#465)\n\nThe reporter saw an intermittent Loki 400 on a label-filtered\ncount_over_time and wondered if the collapse path emits different LogQL\nwhen a filter is present. It does not: the label filter lives in the\nstreamPipeline (shared verbatim with the sum/topk path, which wor\n[…]\n` —\nbalanced and single-range-selector. No production change; the 400 is\nclassified as backend/transient (the emitted query is provably valid).\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(loki): guard label-filtered count_over_time emits valid LogQL (i…",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-11T17:12:23Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "cbd53e3275994aca9f88da0e53af189300891e4d",
          "body": "…ssue #452) (#464)\n\nThe fail-fast fix (S2) surfaced a stale field: the error / no-data\nresponses returned `duration` (the requested look-back window, e.g.\n\"5m\"), which an agent reads as elapsed wall-clock time — so a <1s fast\nfailure looks like a 5-minute hang, the very symptom the fix removed.\nRena\n[…]\n`. The success path is\nunchanged (it never carried the field).\n\nTest: a throwing connector → error response carries `window`, never `duration`.\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(query_logs): report `window` not `duration` in error responses (i…",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-11T17:08:28Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5ae2bda63be67b63398507ce759127d30638b572",
          "body": "… zeros (issue #462) (#463)\n\nSibling of the #453A health fix, one level down in the raw metric tool.\nFor a logs-only service (no cpu/latency_p99 series), query_metrics\nreturned values:[] but summary:{current:0,...,trend:\"stable\"} — an agent\ntrusting the summary (as the description invites) reads \"CP\n[…]\ne.\n\nTests: computeSummary empty→null; queryMetrics no-data → values:[],\nsummary:null, note; health/handlers mocks updated to the null contract.\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(metrics): query_metrics returns null summary (no-data), not false…",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-11T17:03:00Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a28869120db6df8e415bf80a41797b3117373e33",
          "body": "Agent-feedback patch bundling six fixes from three structured agent\nreports against 3.3.0 (#452/#453/#455):\n\n- query_logs count_over_time without `by` collapses to one series (#452)\n- query_logs raw_query vector/matrix fails fast, not crashes (#452)\n- get_service_health honest no-data/unknown/not-fo\n[…]\nhanged. Health-score weighting now renormalises by active signals —\ndefault weights (sum 1.0) unchanged; custom non-1.0 weights shift slightly.\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): v3.3.1 (#461)",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-10T18:12:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ecf4e15478909eff2a65a6df91a81e167ea48a12",
          "body": "…t-usage guide (issue #455 follow-up) (#460)\n\nPer the #455 follow-up: the resource omcp://guide/agent-usage and\n/llms.txt disagreed — llms.txt pointed at Discussions, the guide (the\nchannel that reaches an in-session agent) only named the agent-report\ntemplate. Add the Discussions link to the guide'\n[…]\ntching the\ntester's layering recommendation (instructions = operational kernel;\nguide = full collab surface; llms.txt = setup/crawler surface).\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(ax): align collaboration pointers — Discussions link in the agen…",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-10T17:58:09Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "29300bb22938fd762b9a0fc47751c670b8003e24",
          "body": "…verage (issue #453B) (#459)\n\nThe fleet scan discovered services only from metrics connectors, so a\nlog-only service was silently dropped — scanned 2 of 3 and the \"All\nservices healthy\" all-clear never said which one it skipped, even though\nthe tool advertises log-error-spike detection.\n\n- Discover \n[…]\nields kept (additive).\n\nTest: a metrics-only + a log-only connector → both scanned, log-only\nreports signals:[\"logs\"], summary names the count.\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(detect-anomalies): scan log-only services + report per-service co…",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-10T17:54:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "74ee9509b3e854b3071e0af6b8b86a0753854120",
          "body": "…(issue #453A) (#458)\n\nget_service_health coerced absent metrics to 0 and reported a confident\nscore:100 / \"healthy\" — even for a log-only service with zero metric\ncoverage, and even for a service that doesn't exist (a typo read as good\nnews). This was the one place the gateway handed an agent false\n[…]\num to 1.0, the\nrenormalisation slightly shifts the default-path score (more correct;\nold code could exceed 100 pre-clamp). Defaults unaffected.\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(health): honest no-data / not-found instead of false 100/healthy …",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-10T17:43:16Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "16c92a1b6bcf916efc36803ef1177081dd2b0aa2",
          "body": "…s (issue #455) (#457)\n\n`initialize.instructions` is the one channel the MCP spec auto-injects\ninto an agent's context on connect — and it was empty, so the 3.3.0\nagent-usage guide (resource + llms.txt) only reached agents a human\npointed at it. Now the McpServer is constructed with a tight instruct\n[…]\nce instructions.\n\nLive-verified over the transport (instructions present, points at the\nguide + carries the rule); conformance assertion added.\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(ax): populate initialize.instructions + golden rule in query_log…",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-10T17:22:50Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ab68da8b7442882cf6ef27b910f72966b06597ef",
          "body": "…x (issue #452) (#456)\n\nA metric raw_query (e.g. sum(count_over_time(...))) returns Loki\nresultType vector/matrix, not streams. The streams parser then\ndereferenced undefined .stream/.values and crashed on `.level`, and the\n5m default duration meant it ran to timeout instead of erroring. Now we\nchec\n[…]\nor/matrix\") — surfaced\nby the handler as a structured Query-failed result. Normal log queries\n(resultType \"streams\", or absent) are unaffected.\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(loki): fail fast when query_logs raw_query returns a vector/matri…",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-10T17:11:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "fe52d64696106d07c08c7cc3fb88d37ab117eb3e",
          "body": "…e #452) (#454)\n\nA bucketed count_over_time over a `| json`-piped stream kept every\nextracted label (rid/ip/status/…) as its own series, so the headline\n\"requests over time\" use case (aggregate count_over_time, empty by)\nreturned a high-cardinality mess instead of ~N hourly buckets. sum/topk\nwere un\n[…]\n explicit by → `sum by(...) (...)` (unchanged). Updated the\nno-by unit test (it had encoded the buggy bare shape) + 4 sibling tests\nstay green.\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(loki): count_over_time without `by` collapses to one series (issu…",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-10T17:06:48Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8a8e70b4f90430b0667855ca21ec8f9c198d5060",
          "body": "Agent-experience release — the MCP surface is now self-describing and\nthe agent-collaboration loop a paved road:\n\n- MCP ToolAnnotations on all 12 tools (readOnlyHint etc.)\n- builtin MCP resources + prompts (omcp://guide/agent-usage,\n  triage-incident, write-postmortem) through the hook-wrapped seams\n[…]\nerified: no\npackages/sdk changes since the 3.2.1 tag). All features live-verified\nover the MCP transport and pinned by conformance tests in CI.\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): v3.3.0 (#451)",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-10T16:24:47Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "339c73199001b53c33398c130eaa5562e6d140d9",
          "body": "…h workflow) (#450)\n\nDistribution sprint: list the gateway on registry.modelcontextprotocol.io\nso MCP clients discover it natively.\n\n- server.json — metadata manifest (schema 2025-12-11): name\n  io.github.ThoTischner/observability-mcp (exactly matches the mcpName\n  already shipped in the live npm pa\n[…]\n-in-shell).\n\nReviewer-agent: BLOCK→fixed (description length per live schema) →\nSHIP-equivalent; both hardening nits applied (pin + env input).\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(dist): official MCP Registry presence (server.json + OIDC publis…",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-10T08:15:42Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "44c1554f8941c3464cdccfd6006577794b0bdca0",
          "body": "The llms.txt convention (llmstxt.org) — a plain-text, LLM-friendly\nsummary at the server root. This gateway's primary audience IS an LLM\nagent, so it serves its own:\n\n- GET /llms.txt — generated at boot from the canonical tool registry\n  (registry-names.ts: name/category/summary for all 12 tools, so\n[…]\nes, for-agents link) — CI-persisted.\n\nReviewer-agent: SHIP (route is public in all auth modes; claims\nverified; mkdocs copies the static file).\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(ax): serve llms.txt on the gateway + docs site (#449)",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-10T08:08:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2576b617fcfa2e48bce969c176716c514d34388c",
          "body": "… postmortem) (#448)\n\nAgent experience: the gateway now ships first-party MCP resources and\nprompts through the existing (previously void-ed) hook-wrapped\nregisterResource/registerPrompt seams:\n\n- resource `omcp://guide/agent-usage` (text/markdown) — the distilled,\n  agent-validated #415 workflow: f\n[…]\nargs), prompts/get with\narg interpolation. Conformance assertions added so all of it is\nCI-persisted (skip-guarded like the rest of the suite).\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(ax): builtin MCP resources + prompts (agent usage guide, triage,…",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-10T07:39:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "98ff8064d9fbfc05803b9625f6ee321db819ba70",
          "body": "…#447)\n\nDistribution sprint: a GitHub visitor (human or agent) now sees the value\nprop before the chrome — the 0/10→10/10 blast-radius benchmark headline,\na two-line start+connect snippet, and the agent-first positioning\n(12 read-only tools, numbers-not-haystacks, For-Agents guide link) all\nsit abov\n[…]\nd into a <details> block — nothing removed, 8 stay visible.\n\nReviewer-agent: SHIP (rendering structure, claim accuracy, badge parity\nverified).\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(readme): benchmark headline + 30s connect above the badge wall (…",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-10T07:36:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f10021284ab3d3886acc2dd428fc474e9c8b5325",
          "body": "…#444)\n\nAgent-collaboration sprint: make the loop that worked in issue #415 (an\nagent files a precise report → fixes ship → agent re-verifies) a paved\nroad instead of a happy accident.\n\n- .github/ISSUE_TEMPLATE/agent-report.yml — optional issue form encoding\n  the #415 report format (version, live t\n[…]\nr Agents\" as the second top-level entry.\n\nReviewer-agent: SHIP (accuracy cross-checked; the annotations claim\nrequired G1 merged first — done).\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(agents): for-agents guide + structured agent-report issue form (…",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-10T07:17:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ab1433483dc465e48868b87ac2177f9004937eae",
          "body": "Agent-experience hardening: every builtin tool now advertises MCP\nToolAnnotations ({title, readOnlyHint:true, destructiveHint:false,\nidempotentHint:true, openWorldHint:false}) via the SDK overload\ntool(name, description, schema, annotations, cb). All 12 tools are\nread-only query/list/diagnose paths \n[…]\nded\n(builtin tools must advertise readOnlyHint+title; federated namespaced\ntools exempt — they proxy upstream metadata).\n\nReviewer-agent: SHIP.\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(ax): MCP ToolAnnotations on all 12 builtin tools (#443)",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-10T06:59:54Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5825b99446a0e48afa0af5703df02cac9d96759b",
          "body": "Hardening patch from a post-3.2.0 reachability/E2E audit (4 gap classes,\nadversarially verified):\n\n- fix: get_anomaly_history returns data again — it passed a complete\n  PromQL selector as `metric`, yielding invalid double-brace PromQL →\n  400 → silent \"no history\"; now routed via rawQuery (regressi\n[…]\nn 3.2.1,\nimage :3.2.1), and the SDK 3.1.0→3.2.1 (its published manifestSchema\ngained the new capability keys). Verified: typecheck, SDK parity.\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): v3.2.1 (#442)",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-09T22:10:58Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f7b1cac51712b90af17aa1705096b93187286fe5",
          "body": "…lidation (#441)\n\nThe v3.2 audit flagged the Add-Source \"test-connection\" interaction as\nhaving no playwright coverage. Exercises the two real flows over the UI\nwith verified selectors:\n- Test Connection: open #source-modal → fill an unreachable URL →\n  #test-btn → assert #test-result gets `.show` (\n[…]\nlaywright config → runs in\nui-smoke CI against the demo stack. Reviewer-agent: SHIP (selectors +\nbehaviour verified against src/ui/index.html).\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(ui): playwright coverage for Add-Source test-connection + URL va…",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-09T21:59:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2079e258c6862202140f7c49320640fcbeedb4b5",
          "body": "…dit) (#440)\n\nThe v3.2 audit found the builtin connector manifests under-advertised\ntheir implemented capabilities (the Connectors UI renders `capabilities`,\nso operators saw an inaccurate surface):\n- loki implements queryLogAggregate (the query_logs aggregate path routes\n  to it) but advertised onl\n[…]\nns carry no SRI\ndigest (unlike hub connectors/), so no hash bump needed.\n\nReviewer-agent: SHIP (caps real, parity holds, no hash gate touched).\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(connectors): advertise real capabilities in builtin manifests (au…",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-09T21:53:24Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "56c723f10ee1586db9bb9e050282e078b0345323",
          "body": "…mortems/audit/entitlement) (#439)\n\nThe v3.2 audit flagged several rail tabs with NO playwright coverage —\nsmoke.spec only covers dashboard/sources/services/health/topology, and\nproducts/playground/topology/access/policies/tables have dedicated specs.\nThis adds the same proven nav→#page-<id>-visible\n[…]\nns wherever the tab is exposed.\n\nDeeper interaction specs (sources test-connection, settings save, health\nsparkline) tracked separately as H3b.\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(ui): playwright render-smoke for previously-uncovered tabs (post…",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-09T21:43:24Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "293b6827cfad3236e16de392b2fad51c2a1ca059",
          "body": "…udit (#438)\n\nBatch of stale-doc / description fixes (gap class 3 of the audit), each\nnow matching the code:\n\n- list_services: carry per-service `labels` (e.g. the Loki connector's\n  discoveredVia) through the dedup merge so docs/loki.md's claim is true\n  — the metadata was computed then silently dr\n[…]\nmalies→record()\n  history hook IS wired (was described as deferred/F15b-pending).\n\nReviewer-agent: SHIP (every claim re-verified against code).\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(docs+wiring): correct stale docs/descriptions found by the v3.2 a…",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-09T21:36:42Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8ad5061a9ddcd79f9731efd54f0148a52151afc8",
          "body": "…ort (#437)\n\nCloses the gap that let #415 ship: a param can be ADVERTISED in\ntools/list yet silently stripped by the SDK before reaching the handler,\nand an advertise-only assertion passes anyway. These run over the real\n/mcp Streamable-HTTP transport against the booted demo stack (live in\nintegrati\n[…]\nover MCP and returns a CallToolResult\n  (no -32xxx) — per-tool transport coverage for all 12 tools.\n\nPart of the post-#415 E2E-hardening sweep.\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(conformance): real tools/call behavioral E2E over the MCP transp…",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-09T21:13:17Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0c0682b7b33192731707ae969c76bbcc1e1ed90e",
          "body": "…(was wired-but-dead) (#436)\n\nFound by the v3.2 reachability audit. get_anomaly_history hand-builds a\ncomplete PromQL selector (omcp_anomaly_score{service=\"x\",method=\"mad\"})\nand passed it as the `metric` arg. The Prometheus connector's curated\npath wraps a bare metric in `{ {{selector}} }`, so an al\n[…]\nsion test pins it: the connector receives rawQuery = the verbatim\nselector, `metric` carries no brace, exactly one brace block. Reviewer: SHIP.\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(anomaly-history): route omcp_anomaly_score selector via rawQuery …",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-09T21:04:53Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b529ebdaaa50e5ad0aeab4ebd4939414f849a08c",
          "body": "Agent-usability release — closes the remaining points from the\nreal-world feedback in issue #415 (the log-side #1/#2 shipped in 3.1.x):\n\n- query_metrics `labels` equality filter (#4)\n- raw_query passthrough for query_metrics/query_logs, capability-gated\n  default off (#3)\n- enrich_ips tool — offline\n[…]\n_ips present. Full\nsuite 303 passing. Reviewer-agent: SHIP (version consistency + flag\nnames + air-gapped property cross-checked against code).\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): v3.2.0 (#435)",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-09T19:30:11Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0415827bb268b0f6bee11349ec9ffd5d3ca5e882",
          "body": "…dataset (issue #415 Gap B) (#434)\n\nNew MCP tool `enrich_ips`: resolves a batch of IPv4 addresses to geo\n(country/city), ASN/org, and a hosting/proxy flag — the three things\nevery traffic/abuse/security investigation needs per IP, and the\nhosting flag is what separates real humans from bots/datacent\n[…]\nrmance\nadvertise. Live-verified end-to-end. Docs: docs/ip-enrichment.md + nav.\nReviewer-agent: SHIP (air-gapped property + CIDR math verified).\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(enrich): offline enrich_ips tool — geo/ASN/hosting from a local …",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-09T19:14:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "52ee47d08731798345a81bedf723da2958878e2f",
          "body": "…) (#433)\n\nIn an anonymous deployment (no OMCP_API_KEYS) the per-call\n`bypass_redaction: true` arg could never succeed: the bypass requires\nthe calling credential to be in OMCP_KEY_BYPASS_REDACTION, and there is\nno named credential to add. The only lever was the blunt global\nOMCP_REDACTION=off. A se\n[…]\no per-request bypass\ntoday\" section (per-call bypass already shipped) and aligned the\nbypass_redaction param description. Reviewer-agent: SHIP.\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(redaction): anonymous-friendly per-call bypass (issue #415 Gap A…",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-09T18:49:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "dc60f6bf99b59c5690f1e05a3698fbb39edd8ca2",
          "body": "…15 #3) (#432)\n\nAdd a `raw_query` escape hatch to query_metrics (verbatim PromQL) and\nquery_logs (verbatim LogQL) for ad-hoc queries the curated catalog/\nselector can't express. It widens the read surface (any series/stream\nin a reachable backend), so it is gated behind an explicit operator\ncapabili\n[…]\nidateRawQuery bounds, conformance advertise.\nDocs: docs/raw-query.md + nav. Reviewer-agent: SHIP (gate adversarially\nchecked, no bypass found).\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(q-raw): raw PromQL/LogQL passthrough, capability-gated (issue #4…",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-09T18:36:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "822dde356784080015f3856e220e8db795ea8fa8",
          "body": "… (#431)\n\nAdd an optional `labels` map to query_metrics — the PromQL equivalent of\nthe query_logs `labels` param. Exact-match filters are AND'd into the\nmetric's series selector, so an agent can scope a curated metric to a\nsubset of series (e.g. error_rate for one route/status) instead of the\nall-se\n[…]\nd a live\ntools/list conformance assertion. Verified end-to-end against a booted\nserver (query_metrics advertises labels). Reviewer-agent: SHIP.\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(q-metrics): query_metrics labels equality filter (issue #415 #4)…",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-09T18:05:11Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d7850fea78f52d70ab018631095ebb6cd3d652c9",
          "body": "…d (#430)\n\nget_topology returned a bare empty {resources:[],edges:[]} when no\ntopology-capable connector contributed a snapshot, which an agent can't\ndistinguish from a genuinely empty graph. Mirror query_traces' explicit\n\"no backend configured\" message: attach a `note` to the payload when\nagg.sourc\n[…]\ncp/istio/\nlinkerd/consul providers. Purely additive — the existing fields are\nunchanged and `note` is optional. (issue #415, signal-vs-silence)\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(topology): explicit note when no topology connector is configure…",
          "author_name": "Thomas Tischner",
          "author_login": "ThoTischner",
          "committed_at": "2026-06-09T17:51:42Z",
          "body_truncated": true,
          "is_coding_agent": true
        }
      ],
      "releases_count": 84,
      "commits_last_year": 529,
      "latest_release_at": "2026-07-19T23:58:02Z",
      "latest_release_tag": "v3.9.3",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 15,
      "days_since_latest_release": 5,
      "mean_days_between_releases": 2.9
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 100,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "@thotischner/observability-mcp",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [
            "mcp",
            "model-context-protocol",
            "observability",
            "prometheus",
            "loki",
            "kubernetes",
            "tempo",
            "topology",
            "blast-radius",
            "anomaly-detection",
            "incident-response",
            "root-cause-analysis",
            "sre",
            "platform-engineering",
            "agent",
            "ai-agent",
            "llm-tools",
            "claude",
            "ollama"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@thotischner/observability-mcp",
          "is_deprecated": false,
          "latest_version": "3.9.3",
          "repository_url": "https://github.com/ThoTischner/observability-mcp",
          "versions_count": 42,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 2001,
          "first_published_at": "2026-05-01T17:58:34.373000Z",
          "latest_published_at": "2026-07-19T23:57:52.871000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        }
      ]
    },
    "popularity": {
      "forks": 1,
      "stars": 6,
      "watchers": 0,
      "fork_history": {
        "days": [
          {
            "date": "2026-06-06",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 1,
        "total_forks": 1
      },
      "star_history": null,
      "open_issues_and_prs": 14
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": true,
      "has_dockerfile": true,
      "has_mcp_signal": true,
      "bootstrap_files": [
        "Makefile"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "examples/agent/tsconfig.json",
        "examples/example-services/tsconfig.json",
        "mcp-server/tsconfig.json",
        "packages/sdk/tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 207571,
      "source_files_sampled": 313,
      "oversized_source_files": 1,
      "agent_instruction_files": [
        "CLAUDE.md",
        "docs/agent.md"
      ],
      "agent_instruction_max_bytes": 8032
    },
    "dependencies": {
      "manifests": [
        "mcp-server/package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "2.1.2",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-mh99-v99m-4gvg"
            ],
            "fixed_version": "5.0.8",
            "advisory_count": 1,
            "oldest_advisory_days": 1
          },
          {
            "name": "@hono/node-server",
            "direct": false,
            "version": "1.19.15",
            "severity": "moderate",
            "ecosystem": "npm",
            "cvss_score": 5.9,
            "advisory_ids": [
              "GHSA-frvp-7c67-39w9"
            ],
            "fixed_version": "2.0.5",
            "advisory_count": 1,
            "oldest_advisory_days": 4
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "high": 1,
          "moderate": 1
        },
        "advisory_count": 2,
        "affected_count": 2,
        "assessed_count": 330,
        "malicious_count": 0,
        "assessed_package": "npm:@thotischner/observability-mcp@3.9.3",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "@kubernetes/client-node",
          "manifest": "mcp-server/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.4.0"
        },
        {
          "name": "@modelcontextprotocol/sdk",
          "manifest": "mcp-server/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.12.0"
        },
        {
          "name": "@opentelemetry/api",
          "manifest": "mcp-server/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.9.0"
        },
        {
          "name": "@opentelemetry/auto-instrumentations-node",
          "manifest": "mcp-server/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.78.0"
        },
        {
          "name": "@opentelemetry/exporter-trace-otlp-http",
          "manifest": "mcp-server/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.220.0"
        },
        {
          "name": "@opentelemetry/resources",
          "manifest": "mcp-server/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.2.0"
        },
        {
          "name": "@opentelemetry/sdk-node",
          "manifest": "mcp-server/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.220.0"
        },
        {
          "name": "@opentelemetry/semantic-conventions",
          "manifest": "mcp-server/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.40.0"
        },
        {
          "name": "express",
          "manifest": "mcp-server/package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.2.1"
        },
        {
          "name": "express-rate-limit",
          "manifest": "mcp-server/package.json",
          "ecosystem": "npm",
          "version_constraint": "^8.5.2"
        },
        {
          "name": "js-yaml",
          "manifest": "mcp-server/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.1.0"
        },
        {
          "name": "prom-client",
          "manifest": "mcp-server/package.json",
          "ecosystem": "npm",
          "version_constraint": "^15.1.0"
        },
        {
          "name": "redis",
          "manifest": "mcp-server/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.7.0"
        },
        {
          "name": "ws",
          "manifest": "mcp-server/package.json",
          "ecosystem": "npm",
          "version_constraint": "^8.18.0"
        },
        {
          "name": "zod",
          "manifest": "mcp-server/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.4.3"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "@kubernetes/client-node",
            "direct": true,
            "version": "1.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "@modelcontextprotocol/sdk",
            "direct": true,
            "version": "1.29.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/api",
            "direct": true,
            "version": "1.9.1",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/auto-instrumentations-node",
            "direct": true,
            "version": "0.78.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/exporter-trace-otlp-http",
            "direct": true,
            "version": "0.220.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/resources",
            "direct": true,
            "version": "2.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/sdk-node",
            "direct": true,
            "version": "0.220.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/semantic-conventions",
            "direct": true,
            "version": "1.43.0",
            "ecosystem": "npm"
          },
          {
            "name": "express",
            "direct": true,
            "version": "5.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "express",
            "direct": true,
            "version": "^4.21.0",
            "ecosystem": "npm"
          },
          {
            "name": "express-rate-limit",
            "direct": true,
            "version": "8.5.2",
            "ecosystem": "npm"
          },
          {
            "name": "express-rate-limit",
            "direct": true,
            "version": "8.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "js-yaml",
            "direct": true,
            "version": "4.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "prom-client",
            "direct": true,
            "version": "15.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "prom-client",
            "direct": true,
            "version": "^15.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "redis",
            "direct": true,
            "version": "4.7.1",
            "ecosystem": "npm"
          },
          {
            "name": "ws",
            "direct": true,
            "version": "8.21.1",
            "ecosystem": "npm"
          },
          {
            "name": "zod",
            "direct": true,
            "version": "4.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-crypto/crc32",
            "direct": false,
            "version": "5.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-crypto/sha256-browser",
            "direct": false,
            "version": "5.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-crypto/sha256-js",
            "direct": false,
            "version": "5.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-crypto/supports-web-crypto",
            "direct": false,
            "version": "5.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-crypto/util",
            "direct": false,
            "version": "5.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/client-ec2",
            "direct": false,
            "version": "3.1063.0",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/client-ecs",
            "direct": false,
            "version": "3.1063.0",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/client-eks",
            "direct": false,
            "version": "3.1063.0",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/core",
            "direct": false,
            "version": "3.974.18",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/credential-provider-env",
            "direct": false,
            "version": "3.972.44",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/credential-provider-http",
            "direct": false,
            "version": "3.972.46",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/credential-provider-ini",
            "direct": false,
            "version": "3.972.50",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/credential-provider-login",
            "direct": false,
            "version": "3.972.49",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/credential-provider-node",
            "direct": false,
            "version": "3.972.52",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/credential-provider-process",
            "direct": false,
            "version": "3.972.44",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/credential-provider-sso",
            "direct": false,
            "version": "3.972.49",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/credential-provider-web-identity",
            "direct": false,
            "version": "3.972.49",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/middleware-sdk-ec2",
            "direct": false,
            "version": "3.972.32",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/nested-clients",
            "direct": false,
            "version": "3.997.17",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/signature-v4-multi-region",
            "direct": false,
            "version": "3.996.32",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/token-providers",
            "direct": false,
            "version": "3.1063.0",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/types",
            "direct": false,
            "version": "3.973.11",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/util-locate-window",
            "direct": false,
            "version": "3.965.6",
            "ecosystem": "npm"
          },
          {
            "name": "@aws-sdk/xml-builder",
            "direct": false,
            "version": "3.972.28",
            "ecosystem": "npm"
          },
          {
            "name": "@aws/lambda-invoke-store",
            "direct": false,
            "version": "0.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/aix-ppc64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-arm",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/darwin-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/darwin-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/freebsd-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/freebsd-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-arm",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-ia32",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-loong64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-mips64el",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-ppc64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-riscv64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-s390x",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/netbsd-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/netbsd-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openbsd-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openbsd-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openharmony-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/sunos-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-ia32",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@google-cloud/compute",
            "direct": false,
            "version": "^4.13.0",
            "ecosystem": "npm"
          },
          {
            "name": "@google-cloud/container",
            "direct": false,
            "version": "^5.16.0",
            "ecosystem": "npm"
          },
          {
            "name": "@google-cloud/run",
            "direct": false,
            "version": "^1.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "@grpc/grpc-js",
            "direct": false,
            "version": "1.14.4",
            "ecosystem": "npm"
          },
          {
            "name": "@grpc/proto-loader",
            "direct": false,
            "version": "0.8.1",
            "ecosystem": "npm"
          },
          {
            "name": "@hono/node-server",
            "direct": false,
            "version": "1.19.14",
            "ecosystem": "npm"
          },
          {
            "name": "@hono/node-server",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@isaacs/cliui",
            "direct": false,
            "version": "8.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@js-sdsl/ordered-map",
            "direct": false,
            "version": "4.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "@jsep-plugin/assignment",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jsep-plugin/regex",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "@nodable/entities",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/api-logs",
            "direct": false,
            "version": "0.220.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/configuration",
            "direct": false,
            "version": "0.220.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/context-async-hooks",
            "direct": false,
            "version": "2.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/core",
            "direct": false,
            "version": "2.8.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/exporter-logs-otlp-grpc",
            "direct": false,
            "version": "0.220.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/exporter-logs-otlp-http",
            "direct": false,
            "version": "0.220.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/exporter-logs-otlp-proto",
            "direct": false,
            "version": "0.220.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/exporter-metrics-otlp-grpc",
            "direct": false,
            "version": "0.220.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/exporter-metrics-otlp-http",
            "direct": false,
            "version": "0.220.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/exporter-metrics-otlp-proto",
            "direct": false,
            "version": "0.220.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/exporter-prometheus",
            "direct": false,
            "version": "0.220.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/exporter-trace-otlp-grpc",
            "direct": false,
            "version": "0.220.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/exporter-trace-otlp-proto",
            "direct": false,
            "version": "0.220.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/exporter-zipkin",
            "direct": false,
            "version": "2.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation",
            "direct": false,
            "version": "0.220.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-amqplib",
            "direct": false,
            "version": "0.67.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-aws-lambda",
            "direct": false,
            "version": "0.72.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-aws-sdk",
            "direct": false,
            "version": "0.75.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-bunyan",
            "direct": false,
            "version": "0.65.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-cassandra-driver",
            "direct": false,
            "version": "0.65.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-connect",
            "direct": false,
            "version": "0.63.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-cucumber",
            "direct": false,
            "version": "0.36.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-dataloader",
            "direct": false,
            "version": "0.37.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-dns",
            "direct": false,
            "version": "0.63.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-express",
            "direct": false,
            "version": "0.68.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-fs",
            "direct": false,
            "version": "0.39.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-generic-pool",
            "direct": false,
            "version": "0.63.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-graphql",
            "direct": false,
            "version": "0.68.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-grpc",
            "direct": false,
            "version": "0.220.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-hapi",
            "direct": false,
            "version": "0.66.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-host-metrics",
            "direct": false,
            "version": "0.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-http",
            "direct": false,
            "version": "0.220.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-ioredis",
            "direct": false,
            "version": "0.68.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-kafkajs",
            "direct": false,
            "version": "0.29.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-knex",
            "direct": false,
            "version": "0.64.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-koa",
            "direct": false,
            "version": "0.68.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-lru-memoizer",
            "direct": false,
            "version": "0.64.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-memcached",
            "direct": false,
            "version": "0.63.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-mongodb",
            "direct": false,
            "version": "0.73.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-mongoose",
            "direct": false,
            "version": "0.66.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-mysql",
            "direct": false,
            "version": "0.66.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-mysql2",
            "direct": false,
            "version": "0.66.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-nestjs-core",
            "direct": false,
            "version": "0.66.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-net",
            "direct": false,
            "version": "0.64.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-openai",
            "direct": false,
            "version": "0.18.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-oracledb",
            "direct": false,
            "version": "0.45.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-pg",
            "direct": false,
            "version": "0.72.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-pino",
            "direct": false,
            "version": "0.66.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-redis",
            "direct": false,
            "version": "0.68.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-restify",
            "direct": false,
            "version": "0.65.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-router",
            "direct": false,
            "version": "0.64.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-runtime-node",
            "direct": false,
            "version": "0.33.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-socket.io",
            "direct": false,
            "version": "0.67.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-tedious",
            "direct": false,
            "version": "0.39.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-undici",
            "direct": false,
            "version": "0.30.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/instrumentation-winston",
            "direct": false,
            "version": "0.64.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/otlp-exporter-base",
            "direct": false,
            "version": "0.220.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/otlp-grpc-exporter-base",
            "direct": false,
            "version": "0.220.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/otlp-transformer",
            "direct": false,
            "version": "0.220.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/propagator-aws-xray",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/propagator-b3",
            "direct": false,
            "version": "2.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/propagator-jaeger",
            "direct": false,
            "version": "2.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/redis-common",
            "direct": false,
            "version": "0.38.3",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/resource-detector-alibaba-cloud",
            "direct": false,
            "version": "0.35.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/resource-detector-aws",
            "direct": false,
            "version": "2.20.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/resource-detector-azure",
            "direct": false,
            "version": "0.28.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/resource-detector-container",
            "direct": false,
            "version": "0.8.11",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/resource-detector-gcp",
            "direct": false,
            "version": "0.55.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/sdk-logs",
            "direct": false,
            "version": "0.220.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/sdk-metrics",
            "direct": false,
            "version": "2.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/sdk-trace",
            "direct": false,
            "version": "2.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/sdk-trace-base",
            "direct": false,
            "version": "2.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/sdk-trace-node",
            "direct": false,
            "version": "2.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "@opentelemetry/sql-common",
            "direct": false,
            "version": "0.42.0",
            "ecosystem": "npm"
          },
          {
            "name": "@pkgjs/parseargs",
            "direct": false,
            "version": "0.11.0",
            "ecosystem": "npm"
          },
          {
            "name": "@playwright/test",
            "direct": false,
            "version": "1.49.1",
            "ecosystem": "npm"
          },
          {
            "name": "@protobufjs/aspromise",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@protobufjs/base64",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@protobufjs/codegen",
            "direct": false,
            "version": "2.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "@protobufjs/eventemitter",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "@protobufjs/fetch",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "@protobufjs/float",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@protobufjs/path",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@protobufjs/pool",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@protobufjs/utf8",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@redis/bloom",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@redis/client",
            "direct": false,
            "version": "1.6.1",
            "ecosystem": "npm"
          },
          {
            "name": "@redis/graph",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "@redis/json",
            "direct": false,
            "version": "1.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "@redis/search",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@redis/time-series",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@smithy/core",
            "direct": false,
            "version": "3.24.6",
            "ecosystem": "npm"
          },
          {
            "name": "@smithy/credential-provider-imds",
            "direct": false,
            "version": "4.3.8",
            "ecosystem": "npm"
          },
          {
            "name": "@smithy/fetch-http-handler",
            "direct": false,
            "version": "5.4.6",
            "ecosystem": "npm"
          },
          {
            "name": "@smithy/is-array-buffer",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@smithy/node-http-handler",
            "direct": false,
            "version": "4.7.7",
            "ecosystem": "npm"
          },
          {
            "name": "@smithy/signature-v4",
            "direct": false,
            "version": "5.4.6",
            "ecosystem": "npm"
          },
          {
            "name": "@smithy/types",
            "direct": false,
            "version": "4.14.3",
            "ecosystem": "npm"
          },
          {
            "name": "@smithy/util-buffer-from",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@smithy/util-utf8",
            "direct": false,
            "version": "2.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@types/aws-lambda",
            "direct": false,
            "version": "8.10.162",
            "ecosystem": "npm"
          },
          {
            "name": "@types/body-parser",
            "direct": false,
            "version": "1.19.6",
            "ecosystem": "npm"
          },
          {
            "name": "@types/bunyan",
            "direct": false,
            "version": "1.8.11",
            "ecosystem": "npm"
          },
          {
            "name": "@types/connect",
            "direct": false,
            "version": "3.4.38",
            "ecosystem": "npm"
          },
          {
            "name": "@types/express",
            "direct": false,
            "version": "5.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "@types/express",
            "direct": false,
            "version": "^5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@types/express-serve-static-core",
            "direct": false,
            "version": "5.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "@types/http-errors",
            "direct": false,
            "version": "2.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "@types/js-yaml",
            "direct": false,
            "version": "4.0.9",
            "ecosystem": "npm"
          },
          {
            "name": "@types/memcached",
            "direct": false,
            "version": "2.2.10",
            "ecosystem": "npm"
          },
          {
            "name": "@types/mysql",
            "direct": false,
            "version": "2.15.27",
            "ecosystem": "npm"
          },
          {
            "name": "@types/node",
            "direct": false,
            "version": "24.12.4",
            "ecosystem": "npm"
          },
          {
            "name": "@types/node",
            "direct": false,
            "version": "25.9.2",
            "ecosystem": "npm"
          },
          {
            "name": "@types/node",
            "direct": false,
            "version": "25.9.3",
            "ecosystem": "npm"
          },
          {
            "name": "@types/node",
            "direct": false,
            "version": "^22.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@types/node-fetch",
            "direct": false,
            "version": "2.6.13",
            "ecosystem": "npm"
          },
          {
            "name": "@types/oracledb",
            "direct": false,
            "version": "6.5.2",
            "ecosystem": "npm"
          },
          {
            "name": "@types/pg",
            "direct": false,
            "version": "8.15.6",
            "ecosystem": "npm"
          },
          {
            "name": "@types/pg-pool",
            "direct": false,
            "version": "2.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "@types/qs",
            "direct": false,
            "version": "6.15.0",
            "ecosystem": "npm"
          },
          {
            "name": "@types/range-parser",
            "direct": false,
            "version": "1.2.7",
            "ecosystem": "npm"
          },
          {
            "name": "@types/send",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "@types/serve-static",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@types/stream-buffers",
            "direct": false,
            "version": "3.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "@types/tedious",
            "direct": false,
            "version": "4.0.14",
            "ecosystem": "npm"
          },
          {
            "name": "@types/ws",
            "direct": false,
            "version": "8.18.1",
            "ecosystem": "npm"
          },
          {
            "name": "accepts",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "acorn",
            "direct": false,
            "version": "8.16.0",
            "ecosystem": "npm"
          },
          {
            "name": "acorn-import-attributes",
            "direct": false,
            "version": "1.9.5",
            "ecosystem": "npm"
          },
          {
            "name": "agent-base",
            "direct": false,
            "version": "7.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "ajv",
            "direct": false,
            "version": "8.18.0",
            "ecosystem": "npm"
          },
          {
            "name": "ajv",
            "direct": false,
            "version": "8.20.0",
            "ecosystem": "npm"
          },
          {
            "name": "ajv-formats",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-regex",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-regex",
            "direct": false,
            "version": "6.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-styles",
            "direct": false,
            "version": "4.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-styles",
            "direct": false,
            "version": "6.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "argparse",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "asynckit",
            "direct": false,
            "version": "0.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "b4a",
            "direct": false,
            "version": "1.8.1",
            "ecosystem": "npm"
          },
          {
            "name": "balanced-match",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "bare-events",
            "direct": false,
            "version": "2.8.3",
            "ecosystem": "npm"
          },
          {
            "name": "bare-fs",
            "direct": false,
            "version": "4.7.1",
            "ecosystem": "npm"
          },
          {
            "name": "bare-os",
            "direct": false,
            "version": "3.9.1",
            "ecosystem": "npm"
          },
          {
            "name": "bare-path",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "bare-stream",
            "direct": false,
            "version": "2.13.1",
            "ecosystem": "npm"
          },
          {
            "name": "bare-url",
            "direct": false,
            "version": "2.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "bignumber.js",
            "direct": false,
            "version": "9.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "bintrees",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "body-parser",
            "direct": false,
            "version": "2.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "bowser",
            "direct": false,
            "version": "2.14.1",
            "ecosystem": "npm"
          },
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "bytes",
            "direct": false,
            "version": "3.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "call-bind-apply-helpers",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "call-bound",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "cjs-module-lexer",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "cliui",
            "direct": false,
            "version": "8.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "cluster-key-slot",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "color-convert",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "color-name",
            "direct": false,
            "version": "1.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "combined-stream",
            "direct": false,
            "version": "1.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "content-disposition",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "content-type",
            "direct": false,
            "version": "1.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "content-type",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "cookie",
            "direct": false,
            "version": "0.7.2",
            "ecosystem": "npm"
          },
          {
            "name": "cookie-signature",
            "direct": false,
            "version": "1.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "cors",
            "direct": false,
            "version": "2.8.6",
            "ecosystem": "npm"
          },
          {
            "name": "cross-spawn",
            "direct": false,
            "version": "7.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "data-uri-to-buffer",
            "direct": false,
            "version": "4.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "debug",
            "direct": false,
            "version": "4.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "delayed-stream",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "depd",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "dunder-proto",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "eastasianwidth",
            "direct": false,
            "version": "0.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "ee-first",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "emoji-regex",
            "direct": false,
            "version": "8.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "emoji-regex",
            "direct": false,
            "version": "9.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "encodeurl",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "end-of-stream",
            "direct": false,
            "version": "1.4.5",
            "ecosystem": "npm"
          },
          {
            "name": "es-define-property",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "es-errors",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "es-object-atoms",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "es-set-tostringtag",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "esbuild",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "escalade",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "escape-html",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "etag",
            "direct": false,
            "version": "1.8.1",
            "ecosystem": "npm"
          },
          {
            "name": "events-universal",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "eventsource",
            "direct": false,
            "version": "3.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "eventsource-parser",
            "direct": false,
            "version": "3.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "eventsource-parser",
            "direct": false,
            "version": "3.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "extend",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "fast-deep-equal",
            "direct": false,
            "version": "3.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "fast-fifo",
            "direct": false,
            "version": "1.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "fast-uri",
            "direct": false,
            "version": "3.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "fast-xml-builder",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "fast-xml-parser",
            "direct": false,
            "version": "5.7.3",
            "ecosystem": "npm"
          },
          {
            "name": "fetch-blob",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "finalhandler",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "foreground-child",
            "direct": false,
            "version": "3.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "form-data",
            "direct": false,
            "version": "4.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "formdata-polyfill",
            "direct": false,
            "version": "4.0.10",
            "ecosystem": "npm"
          },
          {
            "name": "forwarded",
            "direct": false,
            "version": "0.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "forwarded-parse",
            "direct": false,
            "version": "2.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "fresh",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "fsevents",
            "direct": false,
            "version": "2.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "function-bind",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "gaxios",
            "direct": false,
            "version": "7.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "gcp-metadata",
            "direct": false,
            "version": "8.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "generic-pool",
            "direct": false,
            "version": "3.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "get-caller-file",
            "direct": false,
            "version": "2.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "get-intrinsic",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "get-proto",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "glob",
            "direct": false,
            "version": "10.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "google-logging-utils",
            "direct": false,
            "version": "1.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "gopd",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "has-symbols",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "has-tostringtag",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "hasown",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "hasown",
            "direct": false,
            "version": "2.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "hono",
            "direct": false,
            "version": "4.12.26",
            "ecosystem": "npm"
          },
          {
            "name": "hpagent",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "http-errors",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "https-proxy-agent",
            "direct": false,
            "version": "7.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "iconv-lite",
            "direct": false,
            "version": "0.7.2",
            "ecosystem": "npm"
          },
          {
            "name": "import-in-the-middle",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "inherits",
            "direct": false,
            "version": "2.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "ip-address",
            "direct": false,
            "version": "10.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "ipaddr.js",
            "direct": false,
            "version": "1.9.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-fullwidth-code-point",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-promise",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "isexe",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "isomorphic-ws",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "jackspeak",
            "direct": false,
            "version": "3.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "jose",
            "direct": false,
            "version": "6.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "jose",
            "direct": false,
            "version": "6.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "jsep",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "json-bigint",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "json-schema-traverse",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "json-schema-traverse",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "json-schema-typed",
            "direct": false,
            "version": "8.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "jsonpath-plus",
            "direct": false,
            "version": "10.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "lodash.camelcase",
            "direct": false,
            "version": "4.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "long",
            "direct": false,
            "version": "5.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "lru-cache",
            "direct": false,
            "version": "10.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "math-intrinsics",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "media-typer",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "merge-descriptors",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "mime-db",
            "direct": false,
            "version": "1.52.0",
            "ecosystem": "npm"
          },
          {
            "name": "mime-db",
            "direct": false,
            "version": "1.54.0",
            "ecosystem": "npm"
          },
          {
            "name": "mime-types",
            "direct": false,
            "version": "2.1.35",
            "ecosystem": "npm"
          },
          {
            "name": "mime-types",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "minimatch",
            "direct": false,
            "version": "9.0.9",
            "ecosystem": "npm"
          },
          {
            "name": "minipass",
            "direct": false,
            "version": "7.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "module-details-from-path",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "ms",
            "direct": false,
            "version": "2.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "negotiator",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "node-domexception",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "node-fetch",
            "direct": false,
            "version": "2.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "node-fetch",
            "direct": false,
            "version": "3.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "oauth4webapi",
            "direct": false,
            "version": "3.8.6",
            "ecosystem": "npm"
          },
          {
            "name": "object-assign",
            "direct": false,
            "version": "4.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "object-inspect",
            "direct": false,
            "version": "1.13.4",
            "ecosystem": "npm"
          },
          {
            "name": "on-finished",
            "direct": false,
            "version": "2.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "once",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "openapi-types",
            "direct": false,
            "version": "12.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "openid-client",
            "direct": false,
            "version": "6.8.4",
            "ecosystem": "npm"
          },
          {
            "name": "package-json-from-dist",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "parseurl",
            "direct": false,
            "version": "1.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "path-expression-matcher",
            "direct": false,
            "version": "1.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "path-key",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "path-scurry",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "path-to-regexp",
            "direct": false,
            "version": "8.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "path-to-regexp",
            "direct": false,
            "version": "8.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "pg-int8",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "pg-protocol",
            "direct": false,
            "version": "1.15.0",
            "ecosystem": "npm"
          },
          {
            "name": "pg-types",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "pkce-challenge",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "postgres-array",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "postgres-bytea",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "postgres-date",
            "direct": false,
            "version": "1.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "postgres-interval",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "protobufjs",
            "direct": false,
            "version": "7.6.5",
            "ecosystem": "npm"
          },
          {
            "name": "proxy-addr",
            "direct": false,
            "version": "2.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "pump",
            "direct": false,
            "version": "3.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "qs",
            "direct": false,
            "version": "6.15.2",
            "ecosystem": "npm"
          },
          {
            "name": "range-parser",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "raw-body",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "require-directory",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "require-from-string",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "require-in-the-middle",
            "direct": false,
            "version": "8.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "rfc4648",
            "direct": false,
            "version": "1.5.4",
            "ecosystem": "npm"
          },
          {
            "name": "rimraf",
            "direct": false,
            "version": "5.0.10",
            "ecosystem": "npm"
          },
          {
            "name": "router",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "safer-buffer",
            "direct": false,
            "version": "2.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "send",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "serve-static",
            "direct": false,
            "version": "2.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "setprototypeof",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "shebang-command",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "shebang-regex",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "side-channel",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "side-channel-list",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "side-channel-list",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "side-channel-map",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "side-channel-weakmap",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "signal-exit",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "smart-buffer",
            "direct": false,
            "version": "4.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "socks",
            "direct": false,
            "version": "2.8.9",
            "ecosystem": "npm"
          },
          {
            "name": "socks-proxy-agent",
            "direct": false,
            "version": "8.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "statuses",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "stream-buffers",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "streamx",
            "direct": false,
            "version": "2.25.0",
            "ecosystem": "npm"
          },
          {
            "name": "string-width",
            "direct": false,
            "version": "4.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "string-width",
            "direct": false,
            "version": "5.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "strip-ansi",
            "direct": false,
            "version": "6.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "strip-ansi",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "strnum",
            "direct": false,
            "version": "2.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "systeminformation",
            "direct": false,
            "version": "5.31.13",
            "ecosystem": "npm"
          },
          {
            "name": "tar-fs",
            "direct": false,
            "version": "3.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "tar-stream",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "tdigest",
            "direct": false,
            "version": "0.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "teex",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "text-decoder",
            "direct": false,
            "version": "1.2.7",
            "ecosystem": "npm"
          },
          {
            "name": "toidentifier",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "tr46",
            "direct": false,
            "version": "0.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "tslib",
            "direct": false,
            "version": "2.8.1",
            "ecosystem": "npm"
          },
          {
            "name": "tsx",
            "direct": false,
            "version": "4.23.1",
            "ecosystem": "npm"
          },
          {
            "name": "tsx",
            "direct": false,
            "version": "^4.19.0",
            "ecosystem": "npm"
          },
          {
            "name": "type-is",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "typescript",
            "direct": false,
            "version": "6.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "typescript",
            "direct": false,
            "version": "^5.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "undici-types",
            "direct": false,
            "version": "7.16.0",
            "ecosystem": "npm"
          },
          {
            "name": "undici-types",
            "direct": false,
            "version": "7.24.6",
            "ecosystem": "npm"
          },
          {
            "name": "unpipe",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "unpipe",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "vary",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "web-streams-polyfill",
            "direct": false,
            "version": "3.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "webidl-conversions",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "whatwg-url",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "which",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "wrap-ansi",
            "direct": false,
            "version": "7.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "wrap-ansi",
            "direct": false,
            "version": "8.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "wrappy",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "xml-naming",
            "direct": false,
            "version": "0.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "xtend",
            "direct": false,
            "version": "4.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "y18n",
            "direct": false,
            "version": "5.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "yallist",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "yaml",
            "direct": false,
            "version": "2.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "yargs",
            "direct": false,
            "version": "17.7.3",
            "ecosystem": "npm"
          },
          {
            "name": "yargs-parser",
            "direct": false,
            "version": "21.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "zod-to-json-schema",
            "direct": false,
            "version": "3.25.1",
            "ecosystem": "npm"
          },
          {
            "name": "zod-to-json-schema",
            "direct": false,
            "version": "3.25.2",
            "ecosystem": "npm"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 433,
        "direct_count": 18,
        "indirect_count": 415
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 14,
        "merged_prs": 495,
        "open_issues": 0,
        "closed_ratio": 1,
        "closed_issues": 15,
        "closed_unmerged_prs": 38
      },
      "bus_factor": 1,
      "bot_contributors": 2,
      "top_contributors": [
        {
          "type": "User",
          "login": "ThoTischner",
          "commits": 485,
          "avatar_url": "https://avatars.githubusercontent.com/u/9863411?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "airgapped.yml",
        "auto-release.yml",
        "cla.yml",
        "codeql.yml",
        "connector-bundle-image.yml",
        "connector-install-it.yml",
        "connector-publish.yml",
        "dependabot-automerge.yml",
        "docker-publish.yml",
        "docs.yml",
        "federation-e2e.yml",
        "helm-integration.yml",
        "helm-release.yml",
        "hub-pages.yml",
        "integration.yml",
        "kubernetes-connector-it.yml",
        "labeler.yml",
        "mcp-registry-publish.yml",
        "npm-publish.yml",
        "release.yml",
        "scorecard.yml",
        "sdk-publish.yml",
        "security.yml",
        "tag-on-release.yml",
        "ui-smoke.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 3,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/16 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 3,
            "reason": "project has 1 contributing companies or organizations -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 15 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 9,
            "reason": "dependency not pinned by hash detected -- score normalized to 9",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 10,
            "reason": "SAST tool is run on all commits",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "11 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "888d55722bda5834210d8e9707107a41374ab619",
        "ran_at": "2026-07-25T23:49:09Z",
        "aggregate_score": 5.7,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": true,
      "has_security_policy": true,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-25T18:40:18Z",
      "oldest_open_prs": [
        {
          "number": 539,
          "created_at": "2026-07-06T20:56:02Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 541,
          "created_at": "2026-07-06T20:56:13Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 547,
          "created_at": "2026-07-13T20:55:32Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 549,
          "created_at": "2026-07-13T20:55:38Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 550,
          "created_at": "2026-07-13T20:55:43Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 551,
          "created_at": "2026-07-13T20:55:52Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 559,
          "created_at": "2026-07-21T09:26:54Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 560,
          "created_at": "2026-07-21T09:26:58Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 561,
          "created_at": "2026-07-21T09:27:00Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 562,
          "created_at": "2026-07-24T01:16:58Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 563,
          "created_at": "2026-07-24T01:16:58Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 564,
          "created_at": "2026-07-24T02:13:36Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 565,
          "created_at": "2026-07-25T09:36:52Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 566,
          "created_at": "2026-07-25T09:36:55Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-21T09:25:48Z",
      "ci_last_conclusion": "FAILURE",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/ThoTischner/observability-mcp",
    "host": "github.com",
    "name": "observability-mcp",
    "owner": "ThoTischner"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 67,
      "inputs": {
        "security": 62,
        "vitality": 80,
        "community": 50,
        "governance": 58,
        "engineering": 81
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 80,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 74,
            "inputs": {
              "commits_last_year": 529,
              "human_commit_share": 0.86,
              "days_since_last_push": 0,
              "active_weeks_last_year": 15
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "15/52 weeks with commits",
                "points": 10.4,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 15
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "529 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 529
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 15 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 84,
              "latest_release_tag": "v3.9.3",
              "releases_from_tags": false,
              "days_since_latest_release": 5,
              "mean_days_between_releases": 2.9
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "84 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 84
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~2.9 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 2.9
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 50,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 11,
            "inputs": {
              "forks": 1,
              "stars": 6,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "6 stars",
                "points": 11.3,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 6
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "1 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 55,
            "inputs": {
              "packages": [
                "@thotischner/observability-mcp"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 2001
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "2,001 downloads/month across npm",
                "points": 44,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 2001,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 58,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 13,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 82,
            "inputs": {
              "merged_prs": 495,
              "open_issues": 0,
              "closed_issues": 15,
              "issue_closed_ratio": 1,
              "closed_unmerged_prs": 38
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "100% of issues closed",
                "points": 46.8,
                "status": "met",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "495/533 decided PRs merged",
                "points": 35.5,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 495,
                      "decided": 533
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/16 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 54,
            "inputs": {
              "followers": 17,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "ThoTischner",
              "public_repos": 43,
              "account_age_days": 4265
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "17 followers of ThoTischner",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 17,
                      "login": "ThoTischner"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "43 public repos, account ~11 yr old",
                "points": 24,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 43
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 11
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "@thotischner/observability-mcp"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 5
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 5 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "42 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 42
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 81,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "25 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 25
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "topics": [
                "ai-agents",
                "anomaly-detection",
                "anthropic",
                "claude",
                "gateway",
                "helm",
                "kubernetes",
                "llm",
                "loki",
                "mcp",
                "mcp-server",
                "model-context-protocol",
                "monitoring",
                "observability",
                "prometheus",
                "sre"
              ],
              "has_wiki": true,
              "homepage": "https://www.npmjs.com/package/@thotischner/observability-mcp",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://www.npmjs.com/package/@thotischner/observability-mcp",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "16 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 16
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 62,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": null,
            "notes": [],
            "value": 57,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 18,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 0,
              "scorecard_aggregate": 5.7
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/16 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 15 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 9",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is run on all commits",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "11 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "good",
            "name": "Dependency advisories",
            "note": "Matched the npm:@thotischner/observability-mcp@3.9.3 runtime dependency closure — what installing the published package pulls in — 330 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:@thotischner/observability-mcp@3.9.3",
                  "assessed": 330
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 84,
            "inputs": {
              "source": "osv",
              "advisories": 2,
              "affected_packages": 2,
              "assessed_packages": 330,
              "unassessed_packages": 0,
              "affected_by_severity": "high 1, moderate 1",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "2 affected: brace-expansion 2.1.2 (high 7.5), @hono/node-server 1.19.15 (moderate 5.9)",
                "points": 8.7,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 2,
                      "packages": "brace-expansion 2.1.2 (high 7.5), @hono/node-server 1.19.15 (moderate 5.9)"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory has been public longer than 90 days",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "advisories_none_stale",
                    "params": {
                      "days": 90
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 330,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "excellent",
        "name": "AI Readiness",
        "value": 89,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "has_llms_txt": true,
              "legible_history_share": 1,
              "agent_instruction_files": [
                "CLAUDE.md",
                "docs/agent.md"
              ],
              "agent_instruction_max_bytes": 8032
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "CLAUDE.md, docs/agent.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "CLAUDE.md, docs/agent.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": "llms.txt present",
                "points": 15,
                "status": "met",
                "details": [
                  {
                    "code": "llms_txt_present",
                    "params": {}
                  }
                ],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "86 of 86 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 86,
                      "sampled": 86
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "excellent",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 88,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "package-lock.json"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [
                "Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "examples/agent/tsconfig.json",
                "examples/example-services/tsconfig.json",
                "mcp-server/tsconfig.json",
                "packages/sdk/tsconfig.json"
              ],
              "agent_commit_share": 0.76,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0.14
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "examples/agent/tsconfig.json, examples/example-services/tsconfig.json, mcp-server/tsconfig.json, packages/sdk/tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples/agent/tsconfig.json, examples/example-services/tsconfig.json, mcp-server/tsconfig.json, packages/sdk/tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "76 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 76,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "14 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 14,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 9",
                "points": 9,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 207571,
              "source_files_sampled": 313,
              "oversized_source_files": 1
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "1/313 source files over 60KB",
                "points": 54.8,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 313,
                      "oversized": 1
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "moderate",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": true,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-25T23:49:25.694062Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/t/ThoTischner/observability-mcp.svg",
  "full_name": "ThoTischner/observability-mcp",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Оцінки — це сигнали, а не гарантії. Вони відображають публічно видимі практики на GitHub — це не аудит коду й не гарантія безпеки.

Відсутні дані виключаються, а ваги перенормовуються — нуль за відсутність ніколи не ставиться. Методологія версіонована й відкрита: метрики v1.13.0, схема v0.27.0 — повна методологія · вікі метрик.

Як окремий результат виглядає на тлі всього реєстру: сукупна статистикаnpm.