Публічний реєстр
Звіт про здоров'я програмного забезпеченнясхема 0.27.0 · метрики 1.13.0 · 2026-07-25 07:28 UTC

Tnsor-Labs / brokoli

Brokoli — self-hosted data pipeline orchestration

Go · SvelteApache-2.0★ 1 зірка⑂ 0 форківз трав. 2026 р.Переглянути на GitHub ↗

Tnsor-Labs/brokoli має індекс здоров’я 53 зі 100, що відповідає смузі «Помірний». Найвищий показник — Engineering Quality (81/100), найнижчий — Community & Adoption (24/100). Останнє оновлення було 5 днів тому. Більшість нещодавньої роботи виконує один учасник.

53
загалом / 100
Помірний

Індекс здоров'я програмного забезпечення

Метрики згруповано у зважені категорії на шкалі 1–100. Загальна оцінка починається як їхнє середнє; коли публічні дані активують Політику юрисдикцій високого ризику, рейтинг коригується й отримує верхню межу 49 («Під ризиком»). Готовність до ШІ не входить до індексу.

53
Відмінний85-100Зразковий; відповідає практично всім перевіреним критеріям
Добрий70-84Здоровий; незначні прогалини
Помірний50-69Прийнятний, але з помітними прогалинами; рекомендовано перевірку
У зоні ризику30-49Суттєві слабкі місця; впровадження потребує обережності
Критичний1-29Серйозні проблеми (покинутий, єдиний мейнтейнер, без базової гігієни)
ЖиттєздатністьСпільнота тавпровадженняСталість таврядуванняІнженернаякістьБезпекаГотовність доШІ

Профіль оцінок

Кожна вісь — окрема категорія. Форма важить більше, ніж середнє: здоровий об'єкт заповнює всю фігуру, тоді як профіль із піками та провалами означає, що сила в одному вимірі маскує ризик в іншому.

Власність

Tnsor LabsОрганізація
0 підписників2 публічні репозиторіїз квіт. 2026 р.

За цим репозиторієм стоїть організація — спільна, підзвітна опіка, здатна пережити будь-якого окремого мейнтейнера.

Пакетні екосистеми

РеєстрПакетВерсіяЗавантажень / місВерсіїОстання публікація
Gogithub.com/Tnsor-Labs/brokoliv0.10.0-186 днів тому

Метрики за категоріями

Життєздатність

Чи живий проєкт — чи пишеться код і чи виходять релізи?

74Добрий · 22% загального індексу
Як обчислюється оцінка
36/36Свіжість push — останній push 5 дн. тому
18/36Ритм комітів — 26/52 тижнів із комітами
18/18Обсяг комітів — 285 комітів за останній рік
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Використані вхідні дані
commits_last_year285
human_commit_share1
days_since_last_push5
active_weeks_last_year26
Як обчислюється оцінка
27/27Випускає релізи — опубліковано 1 релізів
36/36Свіжість релізів — останній реліз 6 дн. тому
12.6/27Ритм релізів — ритм невідомий (єдиний реліз)
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Використані вхідні дані
releases_count1
latest_release_tagv0.10.0
releases_from_tagsні
days_since_latest_release6
mean_days_between_releases

Спільнота та впровадження

Чи має проєкт користувачів, завантаження, увагу та влаштовані умови для контриб’юторів?

24Критичний · 18% загального індексу
Як обчислюється оцінка
0/60Зірки — 1 зірок
0/25Форки — 0 форків
0/15Спостерігачі — 0 спостерігачів
Використані вхідні дані
forks0
stars1
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Як обчислюється оцінка
22.5/22.5README
22.5/22.5Ліцензія — визнана ліцензія (Apache-2.0)
0/18Настанови CONTRIBUTING
0/13.5Кодекс поведінки
0/7.2Шаблон issue
0/6.3Шаблон PR
Використані вхідні дані
has_readmeтак
has_licenseтак
has_contributingні
has_issue_templateні
has_code_of_conductні
has_pull_request_templateні

Сталість та врядування

Чи переживе проєкт своїх людей — бас-фактор, реактивність, хто за ним стоїть і як супроводжуються пакети?

49У зоні ризику · 24% загального індексу
Як обчислюється оцінка
9/54Бас-фактор — на 1 контриб’ютор(ів) припадає половина всіх комітів
0/22.5Розподіл комітів — головний контриб’ютор — автор 100% комітів
1.4/13.5Широта контриб’юторів — 1 контриб’юторів
6/10OpenSSF Scorecard: Contributors — project has 2 contributing companies or organizations -- score normalized to 6
Використані вхідні дані
bus_factor1
contributors_sampled1
top_contributor_share1
Як обчислюється оцінка
23.4/46.8Вирішення issue — закрито 50% issue
38.2/38.3Прийняття PR — злито 1/1 вирішених PR
0/15OpenSSF Scorecard: Code-Review — Found 0/28 approved changesets -- score normalized to 0
Використані вхідні дані
merged_prs1
open_issues1
closed_issues1
issue_closed_ratio0,5
closed_unmerged_prs0

Власність та опіка

34У зоні ризику
Як обчислюється оцінка
30/30Підтримка власника — у власності організації
0/20Верифікований домен
0/25Охоплення власника — 0 підписників у Tnsor-Labs
4.1/25Послужний список — 2 публічних репозиторіїв, вік облікового запису ~0 р.
Використані вхідні дані
followers0
owner_typeOrganization
is_verified
owner_loginTnsor-Labs
public_repos2
account_age_days109

Супровід пакетів

100Відмінний
Як обчислюється оцінка
25/25Опубліковано й доступно — 1 пакет(ів) у go
35/35Свіжість публікацій — остання публікація 6 дн. тому
20/20Історія версій — 18 опублікованих версій
20/20Не застарілий — активний, не deprecated і не yanked
Використані вхідні дані
packagesgithub.com/Tnsor-Labs/brokoli
ecosystemsgo
any_deprecatedні
min_days_since_publish6

Інженерна якість

Чи наявні базові інженерні практики та документація?

81Добрий · 20% загального індексу
Як обчислюється оцінка
24/24Процеси CI — 4 процес(ів) CI
24/24Наявні тести
0/16Конфігурація лінтера
0/9.6Pre-commit-хуки
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 1 out of 1 merged PRs checked by a CI test -- score normalized to 10
Використані вхідні дані
has_ciтак
has_testsтак
has_editorconfigні
has_linter_configні
has_precommit_configні

Документація

100Відмінний
Як обчислюється оцінка
30/30README
25/25Каталог документації
15/15Сайт документації / домашня сторінка — https://brokoli.orkestri.site
10/10Опис репозиторію
10/10Теми — 15 тем
10/10Wiki
Використані вхідні дані
topicsdata-engineering, data-ops, data-pipeline, data-quality, etl, go, golang, open-source, orchestration, pipeline, self-hosted, single-binary, sqlite, visual-editor, workflow
has_wikiтак
homepagehttps://brokoli.orkestri.site
has_readmeтак
has_docs_dirтак
has_descriptionтак

Безпека

Чи міцні видимі практики безпеки й ланцюга постачання, без непослабленої пов’язаності з юрисдикціями високого ризику?

28Критичний · 16% загального індексу

Стан безпеки

28Критичний
Як обчислюється оцінка
6.8/7.5Binary-Artifacts — binaries present in source code
0/7.5Branch-Protection — branch protection not enabled on development/release branches
2.5/2.5CI-Tests — 1 out of 1 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/28 approved changesets -- score normalized to 0
1.5/2.5Contributors — project has 2 contributing companies or organizations -- score normalized to 6
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Ліцензія — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
5/5Packaging — packaging workflow detected
1.5/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 3
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 50 existing vulnerabilities detected
Використані вхідні дані
sourceopenssf_scorecard
checks_evaluated18
scorecard_versionv5.5.0
checks_inconclusive0
scorecard_aggregate2,8

Готовність до ШІ

Наскільки репозиторій оснащений для розробки та супроводу за участі ШІ-агентів? Незалежний, експериментальний бейдж — вага 0.0, тож він подається окремо і не впливає на загальний індекс здоров'я.

60Помірний · 0% загального індексу
Як обчислюється оцінка
0/45Інструкції для агентів — немає CLAUDE.md / AGENTS.md / правил редактора
0/15Машиночитана документація (llms.txt)
40/40Читабельна історія комітів — намір зазначено у 100 з 100 людських комітів (структурований заголовок або пояснювальний текст)
Використані вхідні дані
has_llms_txtні
legible_history_share1
agent_instruction_files
agent_instruction_max_bytes
Як обчислюється оцінка
12.6/18Розгортання однією командою — go.mod (домовленість інструментарію, без раннера задач)
22/22Автоматизовані тести
0/11Конфігурація лінтера / форматера
11/11Статична перевірка типів — ui/tsconfig.json
10/10Відтворюване середовище — lockfile
0/10Підтверджена практика роботи з агентами — серед останніх 100 комітів немає створених агентом
0/8Автоматизоване супроводження — автоматичних оновлень залежностей не виявлено
3/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 3
Використані вхідні дані
has_nixні
has_testsтак
lockfilesgo.sum, package-lock.json
has_dockerfileні
typed_languageтак
bootstrap_files
has_devcontainerні
has_linter_configні
typecheck_configsui/tsconfig.json
agent_commit_share0
toolchain_manifestsgo.mod
dependency_bot_commit_share0
Як обчислюється оцінка
45/45Типізований код — Go (статично типізована)
55/55Керовані розміри файлів — 0/185 файлів вихідного коду понад 60 КБ
Використані вхідні дані
primary_languageGo
largest_source_bytes57 127
source_files_sampled185
oversized_source_files0

Ключові факти

1зірок GitHub
1контриб'юторів
285комітів за останні 12 місяців
5днів від останнього пушу
1релізів
1бас-фактор
1відкритих issue
Go, npmпакетних екосистем

Попередження щодо збору даних

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Докладніше

OpenSSF Scorecard 2.8 / 10
2.8сукупно

Незалежна, не прив'язана до інструментів оцінка безпеки від відкритого проєкту OpenSSF Scorecard. Кожна перевірка винагороджує практику безпеки, а не інструмент конкретного постачальника. Перевірки, які Scorecard не зміг визначити, позначено н/д і виключено з оцінки безпеки (вони ніколи не зараховуються як нуль).Scorecard v5.5.0 · 2026-07-25 07:28 UTC

9Binary-Artifactsbinaries present in source code
0Branch-Protectionbranch protection not enabled on development/release branches
10CI-Tests1 out of 1 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/28 approved changesets -- score normalized to 0
6Contributorsproject has 2 contributing companies or organizations -- score normalized to 6
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
10Packagingpackaging workflow detected
3Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 3
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities50 existing vulnerabilities detected
Прямі залежності 19
РеєстрПакетОбмеження версіїМаніфест
Gogithub.com/go-chi/chi/v5v5.2.5go.mod
Gogithub.com/go-sql-driver/mysqlv1.9.3go.mod
Gogithub.com/golang-jwt/jwt/v5v5.3.1go.mod
Gogithub.com/google/uuidv1.6.0go.mod
Gogithub.com/gorilla/websocketv1.5.3go.mod
Gogithub.com/jackc/pgx/v5v5.9.1go.mod
Gogithub.com/robfig/cron/v3v3.0.1go.mod
Gogithub.com/spf13/cobrav1.10.2go.mod
Gogolang.org/x/cryptov0.49.0go.mod
Gogopkg.in/yaml.v3v3.0.1go.mod
Gomodernc.org/sqlitev1.37.1go.mod
npm@sodp/client^0.2.1ui/package.json
npm@types/prismjs^1.26.6ui/package.json
npmjs-yaml^4.1.1ui/package.json
npmprismjs^1.30.0ui/package.json
npmsvelte-spa-router^5.0.0ui/package.json
npmtimeline-arrows^4.8.0ui/package.json
npmvis-data^8.0.3ui/package.json
npmvis-timeline^8.5.0ui/package.json
Усі залежності не зібрано

Не вдалося зібрати розв'язаний набір залежностей для цього звіту: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Звіт у форматі JSON машиночитний
{
  "data": {
    "repo": {
      "topics": [
        "data-engineering",
        "data-ops",
        "data-pipeline",
        "data-quality",
        "etl",
        "go",
        "golang",
        "open-source",
        "orchestration",
        "pipeline",
        "self-hosted",
        "single-binary",
        "sqlite",
        "visual-editor",
        "workflow"
      ],
      "is_fork": false,
      "size_kb": 14515,
      "has_wiki": true,
      "homepage": "https://brokoli.orkestri.site",
      "languages": {
        "Go": 1069078,
        "CSS": 9087,
        "HTML": 1337,
        "Shell": 11345,
        "Svelte": 531137,
        "JavaScript": 85,
        "TypeScript": 36435
      },
      "pushed_at": "2026-07-20T03:18:58Z",
      "created_at": "2026-05-09T10:56:25Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-18T23:33:08Z",
      "description": "Brokoli — self-hosted data pipeline orchestration",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Go",
      "significant_languages": [
        "Go",
        "Svelte"
      ]
    },
    "owner": {
      "blog": null,
      "name": "Tnsor Labs",
      "type": "Organization",
      "login": "Tnsor-Labs",
      "company": null,
      "location": null,
      "followers": 0,
      "avatar_url": "https://avatars.githubusercontent.com/u/274098069?v=4",
      "created_at": "2026-04-06T19:38:03Z",
      "is_verified": null,
      "public_repos": 2,
      "account_age_days": 109
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.10.0",
          "kind": "minor",
          "published_at": "2026-07-18T23:45:22Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "ee0f93f72ddc44fab3a8b4b1df42aa6257f67aaf",
          "body": "…tence\n\nfix: persist JWT token and attach auth headers to initial fetch calls",
          "is_bot": false,
          "headline": "Merge pull request #3 from Tnsor-Labs/fix/jwt-auth-headers-and-persis…",
          "author_name": "Pitch dev",
          "author_login": "hc12r",
          "committed_at": "2026-07-18T23:33:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "18ccbc706bc0e9f56051bd81c2abe46a9037ae91",
          "body": null,
          "is_bot": false,
          "headline": "lint: fix lint issues in code",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-07-18T23:27:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eca1268c90d52ce80425f74bb2d96bfad4e7190c",
          "body": "Closes #2",
          "is_bot": false,
          "headline": "fix: persist JWT token and attach auth headers to initial fetch calls",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-07-18T23:21:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e579ecf88f7007cb811e8788ffa9bcfedab45342",
          "body": null,
          "is_bot": false,
          "headline": "brand: redesign — bold TL monogram, drop decorative nodes",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-05-09T11:26:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dfd5f9c7824990bbc0dec9c8ff209e071770c891",
          "body": null,
          "is_bot": false,
          "headline": "brand: add Tnsor-Labs logo system — mark, wordmark, favicon, palette",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-05-09T11:21:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7844b2f23d9a45c6e0234e0efb11c579e0a6ee57",
          "body": null,
          "is_bot": false,
          "headline": "docs: rename Enterprise to Brokoli Cloud, highlight free tier",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-05-09T11:13:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8d85587d59d2acb99188adefefb01070d9a8b8fe",
          "body": null,
          "is_bot": false,
          "headline": "docs: remove enterprise comparison table and API reference section",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-05-09T11:10:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d99ebef24a2aa8ace72f99c4e1ba2f4b86e5e43d",
          "body": null,
          "is_bot": false,
          "headline": "docs: trim README — remove comparison table and architecture section",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-05-09T11:07:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9d6e5bf7151bd18042b0dd33fc0ac879dbde9a43",
          "body": "Add shield badges (release, stars, license, activity), a tight\none-paragraph project description, and 15 GitHub repository topics\nto improve search and discoverability.",
          "is_bot": false,
          "headline": "docs: improve README with badges and discoverability",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-05-09T11:03:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c1cf36f7f1c4acc98d0c239d3afd5660ce9ef8ff",
          "body": "…/go-vet/prettier",
          "is_bot": false,
          "headline": "chore(tooling): add Prettier for frontend + pre-commit hook for gofmt…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-05-09T08:52:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5505dc9ca03af9d95a421bf2a576af281c51e415",
          "body": "- Add nodePortConfig and canConnect() to dag.ts — source nodes have no\n  input port, sink/notify nodes have no output port, join accepts exactly\n  2 inputs, migrate is fully standalone\n- NodeCard conditionally renders ports based on portConfig; migrate nodes\n  display a \"standalone\" sub-label\n- Pipe\n[…]\n which rejects bad edge types\n  at the backend level; \"has source\" check now counts dbt and migrate;\n  disconnected-node check skips migrate nodes\n- Add dbt and notify to the TypeScript NodeType union",
          "is_bot": false,
          "headline": "feat(editor): enforce semantic connection rules in pipeline editor",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-05-09T08:44:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8c7c5195da61d7fefd59d95238a23567b8008e66",
          "body": "Connections now store URI-scheme references (env://, vault://, k8s://,\nencrypted://) instead of raw encrypted passwords. The secrets.Chain\nresolver dispatches to the matching backend at execution time; plaintext\nexists only in worker memory for the duration of one pipeline run.\n\n- pkg/secrets: Resol\n[…]\n/ refs\n- API: create/update accept password_ref, responses mask encrypted refs\n  as encrypted://********, never return plaintext\n- 10 unit tests including namespace isolation, injection, and traversal",
          "is_bot": false,
          "headline": "security(connections): credential references — never store secrets in DB",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-16T06:31:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d3c7bf74642d3294fde7f6177c3c975e0b046cad",
          "body": "Captures the reasoning behind SODP, plugin protocol/runtime/distribution,\nworker WebSocket, install UX, and the docs framework — so future work has\na durable record of what was considered and why.",
          "is_bot": false,
          "headline": "docs(adr): seed ADR log with 8 records of decisions to date",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-15T19:15:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8a2b19a58aa603981d864707d59f7943dcc35a21",
          "body": "Implements the Phase 1 runtime for a connector plugin system that\nlets Brokoli load custom source/sink node types from external\nbinaries without recompiling the core.\n\nMotivation: shipping a data orchestrator with four built-in\nconnection types (Postgres, MySQL, REST API, files) isn't a\ncompetitive \n[…]\n\nTenant isolation, secret injection from Vault, and plugin\nsandboxing are enterprise concerns by design — the core plugin\nsystem is OSS because a plugin ecosystem that requires a license\ndoesn't grow.",
          "is_bot": false,
          "headline": "feat(plugins): subprocess plugin protocol for pluggable connectors",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-14T20:45:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4df2fe281c9297b8b097aaf819cf39a8646ca25f",
          "body": "…rite\n\nTwo related quality-of-life fixes for the CLI and install story.\n\n1. `brokoli --version` now works.\n\nThe goreleaser config has always injected\n  -X main.version={{.Version}} -X main.commit={{.Commit}} -X main.date={{.Date}}\ninto the binary, but main.go never declared those package-level vars,\n[…]\n the live release on a fresh temp dir:\nplatform detected, v0.7.5 resolved from /releases/latest redirect,\ntarball downloaded with progress bar, extracted, installed, and\n`brokoli --help` runs cleanly.",
          "is_bot": false,
          "headline": "feat(cli): --version flag wired through ldflags + full install.sh rew…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-14T04:16:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f8fa72567a5c6d7459897247db32ba330650853f",
          "body": "…ule shape\n\nThe \"Data Quality\" pipeline template in Pipelines.svelte shipped with a\nrename rule in the shape\n\n  { type: \"rename\", old_name: \"hire_date\", new_name: \"start_date\" }\n\nbut the backend TransformRule expects\n\n  { type: \"rename\", mapping: { hire_date: \"start_date\" } }\n\n…so the deserializer s\n[…]\nion test that locks in a clear error for the\nOLD broken shape — if someone pastes the pre-fix template back in,\nthey get a loud \"rename_columns requires mapping\" error instead of a\nsilent passthrough.",
          "is_bot": false,
          "headline": "fix(ui): Data Quality template's rename rule uses the real TransformR…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-13T21:31:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "494d76348d4eff5c49de3bb33c5f7953da8f0f7f",
          "body": "…phans in multi-tenant mode\n\nTwo paired fixes that eliminate a class of \"I created it but can't see\nit\" bug that bit every enterprise self-hosted deployment:\n\n1) api/users.go: add UserPostCreateHook\n\nThe OSS /api/auth/users admin endpoint creates a row in `users` but\ndoesn't know anything about orgs\n[…]\nended up with an empty\norg_id, the 4 pipelines in the DB all had org_id=\"\", and the UI\nshowed \"0 pipelines\" with \"Build your first pipeline\" empty state.\nThe test pair locks in both halves of the fix.",
          "is_bot": false,
          "headline": "fix(api): UserPostCreateHook + requirePipelineOrg — prevent silent or…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-13T20:14:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1cee5dd4fd26f9c8868f738d62e327b4ff3200b4",
          "body": "…on realtime updates\n\nPipelines.svelte's loadPipelines() was flipping loading=true on every\ncall. The SODP dashboard tripwire then fired loadPipelines() on every\nrun state change, so the whole list re-rendered as a skeleton for the\nduration of the REST refetch. Visually identical to a forced page\nre\n[…]\nes.\n\nDashboard.svelte already did this right (applySnapshot never touches\nloading). PipelineRuns.svelte already did this right (reloadRunList\nnever touches loading). Only Pipelines.svelte had the bug.",
          "is_bot": false,
          "headline": "fix(ui): silent mode for tripwire refetches — stop flashing skeleton …",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-13T18:28:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c9aa590a056f32de8c1a10c38605d85e58e3379b",
          "body": "The UI hardcoded \"dashboard.default\" in 5 places. In OSS open-mode\nevery user's org is \"default\" so it silently worked. In multi-tenant\nEE the user's org is their JWT's org_id (e.g. 019d6b80-…) and the\nbridge updates dashboard.{org_id}. The UI was watching a key that\nnever received deltas — so pipel\n[…]\n/auth/me\n(the backend already puts it in the JWT claims — the UI just wasn't\nparsing it).\n\nCall sites updated: App.svelte, Dashboard.svelte, Pipelines.svelte,\nPipelineRuns.svelte, RunIndicator.svelte.",
          "is_bot": false,
          "headline": "fix(ui): derive dashboard SODP key from auth user's org_id",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-13T06:12:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9a3aa28201d4887fbf27936c5972e3d4b160cf8a",
          "body": null,
          "is_bot": false,
          "headline": "docs: changelog entry for v0.7.1",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-13T05:30:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "15911a5e59c8ffdc259165bf68d8bbccba77dbae",
          "body": "The SSRF guard blocked relative /api/samples/... URLs once resolved\nagainst BROKOLI_SERVER_URL, because in k8s/docker deployments the\nserver hostname resolves to a private cluster IP. Workers couldn't\nfetch sample data from the API they were already authenticated to.\n\nTrack whether the URL originate\n[…]\n and skip the SSRF check in that\ncase only. Absolute URLs with private IPs are still blocked.\n\nAlso removes a dead HasPrefix check that ran after the URL had already\nbeen rewritten to an http:// form.",
          "is_bot": false,
          "headline": "fix(fetchers): allow SSRF guard to trust self-references in k8s/docker",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-13T05:16:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "347fe3646691e515bd5df534a7063cd497adea32",
          "body": "… check\n\nThe API server generates a persistent JWT signing secret at the path\n`.brokoli-jwt-secret` (relative to its CWD) on first start when no\nBROKOLI_JWT_SECRET env var is set. The file is plain credential\nmaterial, never meant to be committed, and lands at one of two paths\ndepending on which dir\n[…]\nunanchored above this line) does. Verified locally with\n`git check-ignore -v .brokoli-jwt-secret api/.brokoli-jwt-secret` —\nboth paths now resolve through the new rule and disappear from\n`git status`.",
          "is_bot": false,
          "headline": "chore: gitignore .brokoli-jwt-secret to unblock goreleaser dirty-tree…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T22:43:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d6f112baeada82fb0f278f0103e36937d38e093f",
          "body": "…ference\n\n@sodp/client@0.2.1 references WebSocket.OPEN as a bare global inside\nSodpClient.send(), even when a custom WebSocket implementation is passed\nvia the constructor's WebSocket option:\n\n  send(type, streamId, body) {\n      if (!this.ws || this.ws.readyState !== WebSocket.OPEN)\n          retur\n[…]\nen upstream ships a fix in 0.2.2 or later, the polyfill block in the\ntest script and this entry in WORKAROUNDS.md can both be deleted in a\nsingle commit (same workflow as the previous closed entries).",
          "is_bot": false,
          "headline": "fix(ci): polyfill globalThis.WebSocket to bypass @sodp/client bare re…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T22:38:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4d8d32905b273017bb6aa0531d51adfb2fd8eab6",
          "body": "TestCrossLanguage_SodpClient was failing on the GitHub Actions runner\nwith:\n\n  FATAL: Error: [SODP] No WebSocket implementation found.\n  Pass `{ WebSocket }` from the `ws` npm package in Node.js < 21.\n\n@sodp/client reads `globalThis.WebSocket` which only exists natively on\nNode 21+. CI runs an older\n[…]\nal Node 24 verified with the native path (still works); the ws\nfallback path verified by deleting globalThis.WebSocket and running an\ninline import('ws') resolution. No behavior change on modern Node.",
          "is_bot": false,
          "headline": "fix(ci): cross-language test falls back to ws package on Node < 21",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T22:26:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2cfbe20bfd397e572fdc5a23f76f168d3a551b54",
          "body": "Pure whitespace + comment-list normalization produced by `./lint.sh --fix`\non the files touched by the SODP migration series. No semantic changes:\n\n  • api/handlers_misc.go      — JSON-literal column alignment in\n                                dashboardHandler's writeJSON(...) map\n  • pkg/sodp/brid\n[…]\n                           struct field column alignment\n  • pkg/sodp/session.go       — Session struct field-comment column alignment\n\n`gofmt -l` is now clean repo-wide; `go vet ./...` is also clean.",
          "is_bot": false,
          "headline": "style: gofmt — re-align comment blocks, constant tables, struct columns",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T22:13:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "85b8b46382493ff57a70d9d06cae4bb1c03cb38e",
          "body": "  • docs/realtime.md — new architecture document covering the SODP\n    components (server, bridge, sodp.ts adapter, EventBus distributed\n    bridge), the state key namespace (runs.{id} / runs.{id}.nodes.{node}\n    / runs.{id}.logs / dashboard.{org}), the wire format with all 13\n    frame types, tena\n[…]\n, server concurrent-write race.\n  • README.md — Monitoring & Alerts bullet now mentions SODP and links\n    to docs/realtime.md. Architecture section adds pkg/sodp/ and docs/\n    to the directory tree.",
          "is_bot": false,
          "headline": "docs: realtime architecture, CHANGELOG, README link",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T21:51:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2a8e8adef0f053e71620dee11ad0243c498a021f",
          "body": "web/dist/index.html points at the new bundle hashes produced by the\nSODP UI refactor build. The hashed asset files themselves\n(web/dist/assets/index-*.js, index-*.css) are gitignored — only\nindex.html is tracked, and it changes each rebuild because the\ncontent-addressed asset URLs change.",
          "is_bot": false,
          "headline": "chore(web): refresh embedded UI bundle reference",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T21:51:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "69528911b5e4ffb8f55c76a25d9cc9e29c513ef3",
          "body": "The previous flat-grid calendar:\n\n  • Required scrolling for any range over ~30 days\n  • Marked any day with even one failure as solid red, hiding successes\n  • Showed two unrelated '12' numbers (date + run count) stacked\n\nNew design:\n\n  • GitHub-style horizontal layout: weeks as columns, weekdays a\n[…]\ns a proportional bar with success /\n    running / failed segments containing the actual counts inside, plus\n    a per-day success rate that's color-coded with the same thresholds\n    as the stats bar.",
          "is_bot": false,
          "headline": "feat(ui): Calendar — compact horizontal heatmap with mixed-outcome cells",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T21:51:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6d1e95eeb5c5db597c9b97748243940f226a5e0b",
          "body": "… modal\n\nBoth pages defined the modal state variable as 'showModal' but the\nempty-state handler set a phantom 'showCreateModal' that didn't exist.\nThe top-right '+ New Connection' / '+ New Variable' buttons worked;\nthe prominent center CTAs in the empty state did nothing on click.\nNow both pages call the proper openCreate() handler that initializes\nthe form and opens the modal.",
          "is_bot": false,
          "headline": "fix(ui): EmptyState CTAs on Connections and Variables open the create…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T21:51:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f43038c2da1155bd44afd642a681ad66b5d93a3f",
          "body": "The previous architecture forced an event-stream model on top of SODP's\nstate-sync protocol via a server-side _events array key, client-side\ndeduplication, and a liveRunStatuses store that the dashboard had to\nperiodically reconcile against the server's authoritative state. The\nimpedance mismatch be\n[…]\nmain.\n  • ws.ts — deleted. Pages call getSodpClient() from sodp.ts directly.\n\nThe bridge in pkg/sodp/bridge.go is updated separately to maintain\nthe dashboard.{org} snapshot key these pages now watch.",
          "is_bot": false,
          "headline": "refactor(ui): state-driven realtime — pages watch SODP state directly",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T21:51:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8d190e5068271fbe9e9a3d954ce2acfdc3fd182a",
          "body": "  • ui/package.json + package-lock.json — add @sodp/client@^0.2.1 as a\n    runtime dependency. Bundles transparently via vite; the embedded\n    UI build picks it up automatically.\n  • ui/src/lib/sodp.ts — singleton wrapper exposing getSodpClient() and\n    closeSodpClient(). The client is created laz\n[…]\ny App.svelte's reactive auth state — opened on login,\n    closed on logout — to prevent the SODP client from burning\n    exponential-backoff retries against /api/ws while no session\n    cookie exists.",
          "is_bot": false,
          "headline": "feat(ui): @sodp/client dependency and SodpClient singleton wrapper",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T21:51:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b489e15a18e3a6e56257989b14612652999c4a66",
          "body": "The previous dashboardHandler loaded only the last 3 runs per pipeline\nand the frontend then derived runs_today / success_rate / failed_24h /\nrunning_now by iterating that 6-entry sample. As soon as a workload\nexceeded the sample cap, the counters silently undercounted (observed:\n6 reported when the\n[…]\nrends and top_failing also iterate the full\nwindow, not the truncated sample.\n\nThe frontend Dashboard.svelte (refactored separately later in this\nseries) reads these fields directly from the response.",
          "is_bot": false,
          "headline": "fix(api): dashboard aggregates computed from full run window",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T21:51:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "13c05cf0547e1e1952609787c65512807dbafa0d",
          "body": "…User errors\n\nTwo unrelated bugs in api/users.go fixed in one pass since they touch\nthe same file.\n\n  • JWTAuth's WebSocket branch validated the token but called next.ServeHTTP\n    WITHOUT setting claims on the request context. The non-WebSocket branch\n    set claims correctly. Downstream WebSocket \n[…]\ns the actual validation\n    reason as a 400, only returning 409 for genuine UNIQUE violations.\n    users_create_error_test.go covers the new sentinels and the response\n    shapes for both error paths.",
          "is_bot": false,
          "headline": "fix(api): propagate JWT claims into WebSocket context, surface Create…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T21:51:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "79bab739a0b0310efc3929bb519dcd5b90808d78",
          "body": "  • Delete handlers_ws.go (the old in-memory Hub) entirely — its\n    responsibilities move to pkg/sodp.Server which handles tenant\n    isolation, rate limiting, frame size limits, and per-key fanout.\n  • api/server.go now creates a sodp.Server, wires the engine event\n    channel through pkg/sodp.Bri\n[…]\nributed path with three\n    tests: ForwardsToSODP (bus event → dashboard delta), OrgScopedChannel\n    (per-org dashboard isolation), MalformedEventDoesNotCrash (subscriber\n    survives a bad message).",
          "is_bot": false,
          "headline": "feat(api): replace WebSocket Hub with SODP server",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T21:51:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7a55fa626d4c6d60e776c572b88ba710a311de42",
          "body": "  • WORKAROUNDS.md — live list of any in-tree workarounds caused by gaps\n    in @sodp/client. Currently empty (all closed) — entries get added when\n    we hit a client bug and removed when upstream releases the fix.\n  • FEEDBACK_0.2.0.md — original feedback round on @sodp/client@0.1.1.\n    7 issues \n[…]\nd of [value]. Fixed in 0.2.1.\n  • FEEDBACK_0.2.2.md — request for prefix watching (WATCH 'runs.*'),\n    needed by the state-driven UI to discover dynamic key namespaces\n    without an index key. Open.",
          "is_bot": false,
          "headline": "docs(sodp): WORKAROUNDS tracking + SODP team feedback files",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T21:51:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "286382fa9de93c08628a2d2ba558ab0c8842617f",
          "body": "  • integration_test.go — 12 tests using a real httptest server and a\n    gorilla/websocket client: HELLO, WATCH/STATE_INIT, DELTA fanout, full\n    run lifecycle through the bridge, multi-client broadcast, disconnect\n    cleanup, invalid keys, heartbeat echo, CALL mutations, watcher receives\n    del\n[…]\nlity, meta.source semantics (init vs delta), applyOps array\n    operations, the ws.ts baseline pattern, and state.set round-trip.\n    Skipped automatically when node or @sodp/client are not available.",
          "is_bot": false,
          "headline": "test(sodp): integration, resume, and cross-language test suites",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T21:51:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5a86e3eacea889b8b0b15df6faced2b0e51dbf92",
          "body": "In-process Go implementation of the State-Oriented Data Protocol (SODP)\nv0.1 — a binary, msgpack-framed WebSocket protocol for streaming state\ndeltas to subscribers.\n\nReplaces the prior in-memory WebSocket Hub. The new package provides:\n\n  • frame.go    — 13-frame wire format (HELLO/WATCH/STATE_INIT\n[…]\ntests covering frames, delta, state store, ring\n                  buffer, fanout, sessions, eviction, body decoders, bridge\n\nDesigned to interoperate with the upstream @sodp/client TypeScript library.",
          "is_bot": false,
          "headline": "feat(sodp): SODP protocol implementation in pkg/sodp",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T21:51:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "12d2aa8c094f802fcf6961e70428d075618ff80a",
          "body": "Required by the new pkg/sodp package which implements SODP v0.1\n(MessagePack-framed binary protocol for state synchronization). Pulled\nin as a direct dependency; no other consumers.",
          "is_bot": false,
          "headline": "deps: add github.com/vmihailenco/msgpack/v5 for SODP wire format",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T21:51:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dc100fead6bea6c77b70c49e88ccbadcb664d956",
          "body": "  Fixes 7 findings from the CI security scan (gosec):\n\n  - G112 (CWE-400) Slowloris: added ReadHeaderTimeout 10s to http.Server\n  - G124 (CWE-614) Insecure cookie: logout cookie sets Secure + SameSite=Lax\n  - G115 (CWE-190) Integer overflow: bounds check before int->uint32 cast\n    in arrow_transfer\n[…]\nip newlines from URL path in logger\n  - G704 (CWE-918) SSRF: isBlockedHost/validateExternalURL blocks cloud\n    metadata endpoints and private IP ranges in REST fetcher and\n    connection test handler",
          "is_bot": false,
          "headline": "security: fix gosec HIGH and MEDIUM findings",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T14:46:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f9d4065c30ea33427ce83b1dc40d95928210b721",
          "body": "- GET /runs/{id}/logs and /logs/export now accept ?node_id= and ?level=\n  query parameters for server-side filtering. Level is validated against\n  the known enum (debug/info/warning/error); invalid values are ignored.\n- Fixed double-header write in HealthHandler (WriteHeader was called\n  before writeJSON which calls WriteHeader again).",
          "is_bot": false,
          "headline": "feat(api): log filtering by node_id and level, fix health handler",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T14:43:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7705dde4648ce3585c6facc4ed5e84a5f12609df",
          "body": "Usage:\n  ./lint.sh              # check only, exits non-zero if anything is wrong\n  ./lint.sh --fix        # auto-apply gofmt, then verify\n  ./lint.sh --check      # same as no args (explicit for CI)\n\nIgnores _archive/ and web/dist/ (vendored UI output).",
          "is_bot": false,
          "headline": "chore: add lint.sh for gofmt + go vet with --fix and --check modes",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T14:28:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f9570fa9821a3521054c3989d97ee0e21c356f95",
          "body": "- Dependency system: rich dependency_rules, trigger mode, cycle detection,\n  smart delete resolver\n- CLI section: login, dev, run --follow, whoami, import/export\n- API reference: dependency endpoints, log filtering query params,\n  delete resolve modes\n- Configuration: CLI credentials, BROKOLI_MAX_CONCURRENT_RUNS env var\n- Architecture: updated cmd/ description",
          "is_bot": false,
          "headline": "docs: update README with dependencies, CLI, log filtering, YAML changes",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T14:28:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0fa5463be3e6c4e3489d571c62a0192dd163dd5d",
          "body": "…ghts\n\nThe regex-based syntax highlighter was injecting <span class=\"hl-key\">\nHTML fragments that rendered as visible text (hl-key\">name) instead of\ncolored spans. Root cause: the @html directive wasn't reliably rendering\nthe generated HTML across Svelte 5 builds.\n\nFixed by removing the broken highl\n[…]\ncodeText} instead of {@html highlightedCode}. The YAML is\nalready readable in monospace — clean rendering beats broken coloring.\n\nAlso removed the dead CSS classes (.hl-key, .hl-colon, .hl-str, etc.).",
          "is_bot": false,
          "headline": "fix(ui): YAML viewer shows clean text instead of broken syntax highli…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T14:28:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e8b41468841c94f44d5de376027892e053c15042",
          "body": "New commands:\n- brokoli login: interactive authentication (server, username, password\n  prompt with hidden input). Stores JWT token in ~/.brokoli/config.json\n  with 0600 permissions. All subsequent commands auto-read credentials.\n- brokoli logout: clears stored credentials.\n- brokoli whoami: shows c\n[…]\nver/token from ~/.brokoli/config.json when\n  --server/--api-key aren't explicitly set.\n- Reports blocked runs with reason instead of hanging.\n\nDependencies: added golang.org/x/term for password input.",
          "is_bot": false,
          "headline": "feat(cli): login/logout/whoami, dev mode with file watcher, run --follow",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T14:28:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5f57bb5df3e914ce664c393bf1f32bac9e502929",
          "body": "Import improvements:\n- Validates node types against known enum (rejects unknown types early)\n- Validates required config fields per node type (url for source_api,\n  path for source_file, query for source_db, etc.)\n- Validates edge endpoints reference existing node IDs\n- Rejects self-referencing edge\n[…]\nld for forward compatibility\n- Includes tags in export (was missing)\n\nTests added: StripsInternalKeys, IncludesVersion, ValidatesEdges,\nValidatesNodeType, ValidatesNodeConfig, AutoLayout, SelfRefEdge.",
          "is_bot": false,
          "headline": "feat(yaml): validate on import, auto-layout, strip internals on export",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T14:28:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "97a97aacbe80f8b9b375c283f6d09d91f4557891",
          "body": "- GET /runs/{id}/logs and /logs/export now accept ?node_id= and ?level=\n  query parameters for server-side filtering. Level is validated against\n  the known enum (debug/info/warning/error); invalid values are ignored.\n- Fixed double-header write in HealthHandler (WriteHeader was called\n  before writeJSON which calls WriteHeader again).",
          "is_bot": false,
          "headline": "feat(api): log filtering by node_id and level, fix health handler",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-12T14:28:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7e57b4caa64d8134664ea07059f705d0391f6bb3",
          "body": "  Whitespace alignment in struct tag comments and a trailing blank line,\n  flagged by gofmt after the dependency hardening pass.",
          "is_bot": false,
          "headline": "style: gofmt fixes",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-11T18:18:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "71efa7db159c108bdaf9b7493175568378f2d404",
          "body": "…scade\n\nThis is a hardening pass over the pipeline dependency feature covering both\na multi-tenant security audit and a code-quality rewrite. The two sets of\nchanges touch the same files and ship together.\n\n== Tenant isolation (security audit) ==\n\nFour cross-tenant leaks were found in the initial de\n[…]\ng-scoped.\n- api/dependency_cascade_test.go: transitive cascade (linear + diamond),\n  decouple-only-direct, invalid ?resolve= value.\n\nFull suite (14 packages) passes under go test ./... -count=1 -race.",
          "is_bot": false,
          "headline": "refactor(deps): tenant isolation + batched queries + transactional ca…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-11T18:08:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7c96a707a5d93eb91c2a9ccf4586f3ff2721f599",
          "body": "- DependencyPicker component wires into the Pipeline Editor settings panel:\n  per-rule state/mode/freshness editors, legacy depends_on strings render\n  as dashed chips that can be promoted to first-class rules\n- DeletePipelineDialog catches 409 from the delete API and offers\n  decouple vs cascade ac\n[…]\nadge gains a 'blocked' state (amber) and the RunStatus union\n  picks up the new value\n- Request helper now attaches .status and .body to thrown errors so\n  callers can branch on 409 without re-parsing",
          "is_bot": false,
          "headline": "feat(ui): dependency picker, conflict-aware delete, graph page",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-11T17:22:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "281860c081d010d57bc5270eb8b306f0c9a17d31",
          "body": "- Create/Update reject dependency cycles with a path-aware 400\n- DELETE /pipelines/{id}?resolve=abort|cascade|decouple:\n  - abort (default): 409 Conflict with the dependent list\n  - cascade: delete this pipeline and all transitive dependents\n  - decouple: strip the reference from each dependent, then delete\n- GET /pipelines/{id}/deps enriched with per-rule state/mode/freshness\n- GET /pipelines/{id}/dependents (reverse lookup)\n- GET /pipelines/dependency-graph (full org graph for visualization)",
          "is_bot": false,
          "headline": "feat(api): dependency cycle detection and delete resolver",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-11T17:22:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4ea633f20271ee2a785ec4f928d0c58f5f4cbcd4",
          "body": "- CheckDependencies(store, pipe, now) evaluates state + freshness window\n  and is called from every trigger path (scheduled, manual, webhook)\n- Unsatisfied gates persist a visible Run with status=blocked and the\n  blocker list as the error, instead of silently skipping\n- DetectDependencyCycle() with\n[…]\nnes\n  when an upstream run reaches a terminal state\n- Scheduler now delegates to RunPipeline (blocked-run creation is central)\n- Removes the obsolete deps.go/deps_test.go superseded by dependencies.go",
          "is_bot": false,
          "headline": "feat(engine): cross-pipeline dep enforcement and trigger-mode chaining",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-11T17:22:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "371a2271e3ead2204af6bf85ec7a133c846b12f1",
          "body": "- New dependency_rules JSON column on pipelines table (sqlite + postgres\n  auto-migration, coexists with legacy depends_on)\n- PipelinesDependingOn(id) interface method for reverse-graph traversal,\n  used by delete resolver and trigger-mode firing",
          "is_bot": false,
          "headline": "feat(store): persist dependency_rules and add reverse-lookup query",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-11T17:22:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "579d5dd2588f1177411a6e1dcf6c139c3c05cc92",
          "body": "Introduces a rich cross-pipeline dependency model that coexists with the\nlegacy depends_on []string field:\n- DependencyRule{PipelineID, State, WithinSec, Mode}\n- States: succeeded, completed, failed\n- Modes: gate (block), trigger (auto-fire)\n- Pipeline.EffectiveDependencies() merges legacy + rich rules (rich wins)\n- Self-dependency rejection in Validate()\n- RunStatusBlocked for runs that skip due to unsatisfied upstream deps",
          "is_bot": false,
          "headline": "feat(models): add DependencyRule type and blocked run status",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-11T17:22:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2cf4c90bbb18638cb48233749f9c3165c4d1746d",
          "body": "…eaking",
          "is_bot": false,
          "headline": "security: fix cross-tenant breach, CORS, rate limiting, HSTS, error l…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-08T00:21:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8b16c1b60bae23a1ec0b0e9536ba903600587cb3",
          "body": "…eaking\n\n  CRITICAL:\n  - C1: WorkspaceMiddleware validates user owns workspace before granting access\n    Prevents cross-tenant data breach via X-Workspace-ID header spoofing\n\n  HIGH:\n  - H1: CORS no longer defaults to wildcard — requires BROKOLI_CORS_ORIGINS\n  - H3: Login rate limit tightened to 3 \n[…]\neaders middleware adds HSTS, X-Frame-Options, CSP headers\n\n  LOW:\n  - L1: System info no longer exposes version, db_size, pipeline count\n  - L3: JSON decode errors no longer leak Go struct field names",
          "is_bot": false,
          "headline": "security: fix cross-tenant breach, CORS, rate limiting, HSTS, error l…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-08T00:18:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "318c4379a0a297212ed18782390090fa338e97eb",
          "body": null,
          "is_bot": false,
          "headline": "docs: Apache 2.0 license, update README, fix stale references",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-07T21:46:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "104873660c133fc20d6e258928b1fd5de230c591",
          "body": "… URLs",
          "is_bot": false,
          "headline": "docs: update README for current repo structure, new features, correct…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-07T21:33:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "49b4d263c4b56526acfb0c203d83ad9184809890",
          "body": null,
          "is_bot": false,
          "headline": "fix(ci): stage UI build output before GoReleaser to avoid dirty git",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-07T19:00:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5c2faea91f13a98f00dccf764cd99fbd66ca66eb",
          "body": null,
          "is_bot": false,
          "headline": "fix: commit favicon files to web/dist for clean goreleaser builds",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-07T18:52:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4d6e96ff5628204ca869ca5d20c7043e198a5a2d",
          "body": null,
          "is_bot": false,
          "headline": "fix: commit web/dist placeholder for go:embed in module consumers",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-07T18:50:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1feec50b4d02f8f662fbc2acfce4c04ab48fc383",
          "body": null,
          "is_bot": false,
          "headline": "fix: update goreleaser config for current repo structure",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-07T18:39:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "68df0e2c354bcefbbe38b3d56ebfc0b23ac2327b",
          "body": null,
          "is_bot": false,
          "headline": "fix(ci): create ui-dist.tar.gz in /tmp to avoid dirty git state",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-07T18:34:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ebed6ccda38dd1ee4ca6b0444629a26678e66a79",
          "body": null,
          "is_bot": false,
          "headline": "fix: update install.sh URLs to Tnsor-Labs/brokoli",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-07T18:28:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5500ed518c2bebed2d50ed706b3cc0e8ad86f22b",
          "body": null,
          "is_bot": false,
          "headline": "style: gofmt all Go files, fix CI workflows",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-07T18:18:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9a157b8acee2f0ff1476ebee8dea391b578dc14a",
          "body": null,
          "is_bot": false,
          "headline": "fix(ci): build UI before tests (go:embed requires web/dist)",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-07T18:12:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c06f3ca0117657af637b84effe78cddb1c0b0705",
          "body": null,
          "is_bot": false,
          "headline": "fix(ci): update workflow for current repo structure (broked → brokoli)",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-07T18:00:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "853ec423281e739409b94497ede2510343edda98",
          "body": "Release:\n- Updated for current repo structure (broked → brokoli)\n- Builds UI and uploads ui-dist.tar.gz to GitHub Release\n- Enterprise repo fetches this artifact instead of cloning OSS\n\nSecurity:\n- Added license compliance scanning (go-licenses)\n- Fails on GPL/AGPL/SSPL dependencies (incompatible with commercial)\n- License summary in GitHub Actions step summary",
          "is_bot": false,
          "headline": "ci: release workflow with UI artifact, license compliance scanning",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-07T17:56:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8cc2645b1cafdc31f387d53344ef730138bb7417",
          "body": "Worker API Store:\n- Workers persist execution data via HTTP (no direct DB access)\n- New server endpoints: node-runs, previews, DLQ, variables\n- Run ID consistency between server and worker\n\nEngine Logging Overhaul:\n- TraceID per run, SpanID per node attempt for distributed tracing\n- Per-attempt Node\n[…]\n view with syntax highlighting\n- Node-stats API for historical duration sparklines\n\nAPI:\n- GET /api/pipelines/{id}/node-stats — historical node durations\n- POST /api/auth/logout — clear session cookie",
          "is_bot": false,
          "headline": "feat: worker API store, distributed tracing, Gantt chart, cookie auth",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-07T16:09:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4c68efd78abdfa656d1a2b7023727a5a9d7caff8",
          "body": "Single Go module: github.com/Tnsor-Labs/brokoli\nBinary renamed: broked → brokoli\nUI source moved: broked-ui/ → ui/\nUI embed moved: broked/ui/ → web/\nMetrics prefix: broked_ → brokoli_\nDefault DB: broked.db → brokoli.db\nlocalStorage: broked-token → brokoli-token\n\nOld BrokoliSQL library code archived in _archive/.\n\nAll imports updated:\n  github.com/hc12r/broked/* → github.com/Tnsor-Labs/brokoli/*\n  github.com/hc12r/brokolisql-go/* → github.com/Tnsor-Labs/brokoli/*",
          "is_bot": false,
          "headline": "refactor: merge broked/ into root, rename broked → brokoli",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-06T20:25:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8d017585a0c1296b9180cc35aafa9edd68af776c",
          "body": "Layout: mobile bottom nav.\nNodeConfigPanel: dbt + notify config panels.\nPagination: simplified component.\nIcons: add dbt, notify, new status icons.\nGlobal CSS: new variables, responsive tweaks.",
          "is_bot": false,
          "headline": "style(ui): component polish, mobile nav, dbt/notify icons, pagination",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-06T19:53:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e413fb98a35fce555acc2ab1b22bece98d464a11",
          "body": "Pipelines: grid/list toggle, bulk actions, search.\nConnections/Variables: usage tracking display.\nNew API Integrations page.\nCalendar, Lineage, Settings, PipelineRuns improvements.",
          "is_bot": false,
          "headline": "feat(ui): pipeline list redesign, API integrations page, page polish",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-06T19:53:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "833f020022b4d661c919291bc145037146089a61",
          "body": "Auth: OAuth callback handling, onboarding state in localStorage.\nLogin: GitHub/Google/Keycloak OAuth buttons, setup mode detection.\nNew components: Breadcrumb, EmptyState, RunIndicator, Stepper.",
          "is_bot": false,
          "headline": "feat(ui): OAuth login flow, new components",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-06T19:53:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b53e52777af52306638cbb4bfcdd15253c249e1a",
          "body": "Replace static welcome hero with reactive onboarding:\n- Track connections, pipelines, runs from actual API data\n- Progress bar with percentage (0/3 → 3/3 complete)\n- Green checkmarks and strikethrough on completed steps\n- Welcome hero visible until all steps done (not just first pipeline)",
          "is_bot": false,
          "headline": "feat(ui): dynamic onboarding with progress bar and step tracking",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-06T19:53:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ee10d0b24ffab050c2eef8d95f6fd7b4df75219b",
          "body": "Remove empty hash from isLoginRoute check. Previously currentHash === \"\"\nbypassed the auth guard, showing the dashboard to unauthenticated users.",
          "is_bot": false,
          "headline": "fix(ui): onboarding screen visible without sign-in",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-06T19:53:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ac4d391556b6663cc8aae801e46ceaf8f75998a1",
          "body": "Add configurable timeout to REST fetcher.\nAdd pkg/common/id.go for ID generation utilities.",
          "is_bot": false,
          "headline": "feat(fetchers): REST fetcher timeout support, common ID generator",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-06T19:53:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "da0ddf963c093f76a813c539c21820143227339b",
          "body": "5 failed attempts in 15min triggers lockout.\nPassword validation: 10+ chars, uppercase, lowercase, digit.\nSuperAdmin/Admin/Editor/Viewer role hierarchy.\nExpand extension interfaces for auth hooks.",
          "is_bot": false,
          "headline": "feat(auth): account lockout, password policy, role enforcement",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-06T19:53:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b6ae39f0a930eb391df45fce797edffd92e8db50",
          "body": "New endpoints:\n- GET/POST pipelines/{id}/dlq, dlq/{id}/resolve\n- POST pipelines/{id}/webhook (external trigger)\n- POST pipelines/{id}/validate-nodes\n- GET pipelines/{id}/deps, pipelines/summary\n- GET connections/{id}/used-by, variables/{key}/used-by\n- GET search, lineage, dashboard, system/info\n- POST system/purge\n- GET runs/calendar, runs/{id}/nodes/{nodeId}/profile",
          "is_bot": false,
          "headline": "feat(api): DLQ, webhook triggers, search, lineage, system info, purge",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-06T19:53:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8f99adeeef6cbdc7c1b2a757c72bb695f2cff743",
          "body": "Add UsedByConnections, UsedByVariables for impact analysis.\nAdd dashboard aggregate query, search endpoint support.\nExpand both Postgres and SQLite stores.",
          "is_bot": false,
          "headline": "feat(store): connection/variable usage tracking, dashboard queries",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-06T19:53:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9251d310f0fd0c669c752108fb2c3a2a31cbd601",
          "body": "Add description field to connections, expand BuildURI.\nAdd organization model for multi-tenant support.\nAdd variable type metadata.",
          "is_bot": false,
          "headline": "feat(models): expand connection types, add org model, variable metadata",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-06T19:53:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "35124d468f062b3e3cc7659e4711ac12cd320c7b",
          "body": "Expand database engine with better error handling and query support.\nRunner improvements for pipeline execution.\nAdd database tests.",
          "is_bot": false,
          "headline": "feat(engine): database query improvements, runner enhancements",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-06T19:53:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1e758d839e44b2bf0726b966f44fa22e4ffb6b46",
          "body": "Add aliases: rename, filter, function, replace, drop, dedup, agg\n90 new transform test cases covering all rule types.",
          "is_bot": false,
          "headline": "feat(engine): transform rule short aliases, expand test coverage",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-06T19:53:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "75cd8a458c2b44c7c319952de6e71d9d13d12f88",
          "body": "dbt: run/test/build/seed/snapshot/compile/ls with JSON output parsing\nnotify: Slack and webhook with message templates ({{pipeline}}, {{run_id}}, {{rows}})\nBoth registered as NodeTypeDBT and NodeTypeNotify in models.",
          "is_bot": false,
          "headline": "feat(engine): add dbt and notify node types",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-06T19:53:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ab4e940ccb958a9b7e7c04a5c7ee3cdf9feafcde",
          "body": "… (9 tests)\n\n- api/security_test: permissions, workspace validation, error sanitization, password rules\n- engine/security_test: file path whitelist, path traversal, BROKOLI_DATA_DIRS\n- models/security_test: XSS prevention, slug validation, account status, sanitize\n- extensions/distributed_test: pub/sub, pattern matching, FIFO queue, concurrent access",
          "is_bot": false,
          "headline": "test: security suite (55 tests) + distributed EventBus/JobQueue tests…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-04T22:33:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c36a203a4d704c4b9d8fa150708477bcb1ed6bf4",
          "body": "- Hub.SetEventBus() wires Redis pub/sub for cross-pod broadcasting\n- StartDistributedBroadcasting() publishes local events and subscribes to remote events\n- Server auto-selects distributed mode when EventBus is available\n- UIOverride for enterprise UI injection\n- withSessionCookie fix: always write response body",
          "is_bot": false,
          "headline": "feat(api): WebSocket Hub distributed broadcasting via EventBus",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-04T22:33:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b21c987a4a5a869a24b456e1c465cfadf9251e31",
          "body": "- Logo redesigned: broccoli florets as pipeline nodes with connection lines\n- 3-color palette: teal (#0d9488), medium green (#16a34a), bright green (#22c55e)\n- Reads as both a broccoli AND a data pipeline graph\n- Updated in Sidebar, Login, and favicon\n- Old monochrome version backed up as favicon-mono.svg",
          "is_bot": false,
          "headline": "style: multicolor broccoli-as-DAG logo",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-04T22:33:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e0defe560ddb3ca44118d84ca4f0ef3a0539e9bb",
          "body": "…ators\n\n- PipelineRuns: Airflow-style run history grid (last 14 days, colored status squares)\n- PipelineRuns: collapsible grid (3 days default, expand to see all)\n- PipelineRuns: run summary bar (started, finished, duration, rows, nodes)\n- PipelineRuns: toolbar buttons icon-only on mobile (<768px)\n- Dashboard: timezone indicator on clock\n- PipelineRuns: formatFullTime shows timezone abbreviation (EDT, CEST, etc.)\n- Types: schedule_timezone added to Pipeline interface",
          "is_bot": false,
          "headline": "feat(ui): run history grid, mobile responsive toolbar, timezone indic…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-04T22:33:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b353ccea028d2a4e3dd59b3fdfc77881611fb9ee",
          "body": "- RunMode flag: all (default), api (HTTP only), scheduler (cron only), worker (executor only)\n- Worker mode drains engine events to EventBus for cross-pod WebSocket\n- Scheduler mode blocks without HTTP server\n- Purge endpoint scoped by org in multi-tenant mode\n- migrate command: SQLite<->Postgres with type conversion, verification, FK ordering",
          "is_bot": false,
          "headline": "feat(cmd): --mode flag (all/api/scheduler/worker), migrate command",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-04T22:33:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "999edb8ddd90b6adb78012694605a4b08816d0be",
          "body": "…eline timezone, WebSocket tenant isolation\n\n- RunPipelineAsync enqueues to JobQueue when set (distributed mode)\n- All timestamps now UTC (time.Now().UTC() everywhere)\n- Scheduler defaults to UTC, per-pipeline timezone via tzCronSchedule wrapper\n- Runner emits org_id on all events for WebSocket tenant isolation\n- Catch-up runs respect pipeline timezone",
          "is_bot": false,
          "headline": "feat(engine): RunPipelineAsync with JobQueue, UTC timestamps, per-pip…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-04T22:33:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c54a2b375cf50c616cfd9566a9b4cfb5b2cbf8f9",
          "body": "…tecture\n\n- EventBus: Publish/Subscribe/Close for cross-pod event distribution\n- JobQueue: Enqueue/Dequeue/Ack/Fail for distributed pipeline execution\n- In-memory defaults (channels) for single-binary mode\n- RunJob struct with pipeline_id, run_id, org_id, params, priority\n- Pattern matching for pub/sub subscriptions\n- Zero behavior change for open source — interfaces unused unless enterprise wires them",
          "is_bot": false,
          "headline": "feat(extensions): EventBus, JobQueue interfaces for distributed archi…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-04T22:33:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "28e59283544a778f79fb7d31fb80f37d41880635",
          "body": "…ormat\n\n- ParsePageParams extracts ?page=1&page_size=25 from query string\n- PaginateSlice returns PageResult envelope {total, page, pages, items}\n- List endpoints return array (no params) or PageResult (with ?page=)\n- Exported wrappers for enterprise handlers\n- OrgIDContextKey for cross-package org context sharing\n- ValidatePassword export for enterprise signup",
          "is_bot": false,
          "headline": "feat(api): server-side pagination with backward-compatible response f…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-04T22:33:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c2a9ac7df1234e6394a4636a1b816a844321fb54",
          "body": "…ostgres production-ready\n\n- Pipeline: pipeline_id (git-sync slug), source (ui/git), workspace_id, org_id, schedule_timezone\n- Event: org_id for WebSocket tenant isolation\n- Store: GetPipelineByPipelineID, PurgeRunsOlderThanByOrg, Count* methods\n- Store: PageParams/PageResult types for server-side p\n[…]\n: all missing tables created (connections, variables, workspaces, settings, etc.)\n- Postgres: workspace filtering fixed (was returning all records)\n- Postgres: proper TIMESTAMPTZ, BOOLEAN, JSONB types",
          "is_bot": false,
          "headline": "feat: pipeline_id, source, workspace/org fields, schedule timezone, P…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-04T22:33:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7b062e04356ec1742804863666ebefddb690fb93",
          "body": "… locking\n\n- TriggerRun now uses RunPipelineAsync (prevents client timeout duplicates)\n- sanitizeRunError strips connection strings and sensitive paths from errors\n- Git-managed pipelines reject UI edits with 403\n- Pipeline create auto-generates pipeline_id slug, sets workspace_id",
          "is_bot": false,
          "headline": "fix(api): async run triggers, error sanitization, git-source pipeline…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-04T22:33:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2a73d85e99d78fa7fff5f2e963e5c4e7c33e28b6",
          "body": "…sking, file path whitelist\n\n- Viewers blocked from write operations in open source (requirePerm fallback)\n- ValidateWorkspaceAccess() helper for cross-workspace protection\n- Connection secrets (Extra field) masked in list responses\n- WebSocket origin validation against BROKOLI_CORS_ORIGINS\n- Webhoo\n[…]\nimiting (1 per 10s)\n- User creation requires admin role after first user\n- File source/sink nodes restricted to allowed dirs (BROKOLI_DATA_DIRS)\n- XSS prevention in org/pipeline names (<>\"'& rejected)",
          "is_bot": false,
          "headline": "security: role-based permissions, workspace validation, connection ma…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-04T22:33:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8e9dd2bf2a0052406baa3019c6f6743d87140bc5",
          "body": "- App.svelte: hash-based SPA routing, reactive hashchange for layout switching\n- api.ts: 15s timeout, auto-logout on 401\n- auth.ts: token management, permission loading, httpOnly cookie fallback\n- license.ts: community edition stub (enterprise overrides this)\n- workspace.ts: default workspace stub\n- global.css: dark theme with teal accent, CSS variable design system\n- icons.ts: stroke-only SVG icon library",
          "is_bot": false,
          "headline": "feat(ui): app routing, auth lib, design system, and client libraries",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-03T23:47:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7a9c7779306cb064413b54ee162609a19c84e2bc",
          "body": "…omponents\n\n- GlobalSearch: Cmd+K overlay searching pipelines/connections/variables/pages\n- Pagination: reusable with page numbers, ellipsis, page size selector\n- VersionHistory: pipeline version list with rollback\n- Sidebar: stripped to free-tier nav (Dashboard through Settings)\n- Layout: clean shell without enterprise trial banner",
          "is_bot": false,
          "headline": "feat(ui): add GlobalSearch, Pagination, VersionHistory, and improve c…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-03T23:47:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fae59f16534d7d25426c4306ab760d3d29aaeb19",
          "body": "- Connections: CRUD with type badges, test connection, encryption\n- Variables: key-value store with secret masking, used-by tracking\n- Settings: 4 tabs (General, Users, API & CLI, Integrations)\n- Login: JWT auth with account lockout display, setup flow",
          "is_bot": false,
          "headline": "feat(ui): Connections, Variables, Settings, and Login pages",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-03T23:47:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c14537b97aaa75320c4da5e8b0000e395a90da34",
          "body": "- Dashboard: 5 KPI cards, 7-day interactive bar chart, 3-column overview grid\n- Pipelines: status/tag filters, sort, search, Ctrl+K hint, pagination, templates\n- PipelineEditor: visual DAG editor with condition nodes, undo/redo, version history\n- PipelineRuns: card-based run list with inline expand, Gantt timeline, data preview",
          "is_bot": false,
          "headline": "feat(ui): redesign Dashboard, Pipelines list, editor, and runs pages",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-03T23:47:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4dffc9ab58aafeb63487c683ce042e5816dfe79d",
          "body": "…rays\n\n- Quality rules: not_null, unique, range, regex, custom expression checks\n- crypto: AES-256-GCM encryption for connection secrets\n- ParseJSONData: handles array-of-objects, single object, and mixed arrays\n  (World Bank API format fix)",
          "is_bot": false,
          "headline": "feat: data quality rules, AES-256 encryption, JSON utils for mixed ar…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-03T23:47:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3202c6f1a995e6c93b49d73524aa3e407f7d7d0c",
          "body": "…bcommands\n\n- serve: conditional Platform/Team service startup via extensions\n- serve: UIOverride support for enterprise binary UI injection\n- runcmd: CLI pipeline execution (broked run <pipeline-id>)\n- testcmd: CLI pipeline assertions (broked assert <pipeline-id>)",
          "is_bot": false,
          "headline": "feat(cmd): update serve with extension lifecycle, add run and test su…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-03T23:47:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dcae327861b2c00a14e4040b4c5040013334843c",
          "body": "…r open-core\n\n- PlatformProvider: multi-tenant SaaS features (orgs, admin, tickets)\n- TeamProvider: RBAC, workspaces, permission middleware\n- No-op defaults for community edition\n- Existing interfaces: Auth, Audit, GitSync, License, Secrets, Notifier,\n  Contracts, PII, OpenLineage, NodeExecutor",
          "is_bot": false,
          "headline": "feat(extensions): add PlatformProvider and TeamProvider interfaces fo…",
          "author_name": "hc12r",
          "author_login": "hc12r",
          "committed_at": "2026-04-03T23:47:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 1,
      "commits_last_year": 285,
      "latest_release_at": "2026-07-18T23:45:22Z",
      "latest_release_tag": "v0.10.0",
      "releases_from_tags": false,
      "days_since_last_push": 5,
      "active_weeks_last_year": 26,
      "days_since_latest_release": 6,
      "mean_days_between_releases": null
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 50,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/Tnsor-Labs/brokoli",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/Tnsor-Labs/brokoli",
          "is_deprecated": false,
          "latest_version": "v0.10.0",
          "repository_url": "https://github.com/Tnsor-Labs/brokoli",
          "versions_count": 18,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-18T23:33:02Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 6
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 1,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": null,
      "open_issues_and_prs": 1
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "ui/tsconfig.json"
      ],
      "toolchain_manifests": [
        "go.mod"
      ],
      "largest_source_bytes": 57127,
      "source_files_sampled": 185,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "go.mod",
        "ui/package.json"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go",
        "npm"
      ],
      "dependencies": [
        {
          "name": "github.com/go-chi/chi/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.2.5"
        },
        {
          "name": "github.com/go-sql-driver/mysql",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.9.3"
        },
        {
          "name": "github.com/golang-jwt/jwt/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.3.1"
        },
        {
          "name": "github.com/google/uuid",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.6.0"
        },
        {
          "name": "github.com/gorilla/websocket",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.5.3"
        },
        {
          "name": "github.com/jackc/pgx/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.9.1"
        },
        {
          "name": "github.com/robfig/cron/v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.0.1"
        },
        {
          "name": "github.com/spf13/cobra",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.10.2"
        },
        {
          "name": "golang.org/x/crypto",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.49.0"
        },
        {
          "name": "gopkg.in/yaml.v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.0.1"
        },
        {
          "name": "modernc.org/sqlite",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.37.1"
        },
        {
          "name": "@sodp/client",
          "manifest": "ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.2.1"
        },
        {
          "name": "@types/prismjs",
          "manifest": "ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.26.6"
        },
        {
          "name": "js-yaml",
          "manifest": "ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.1.1"
        },
        {
          "name": "prismjs",
          "manifest": "ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.30.0"
        },
        {
          "name": "svelte-spa-router",
          "manifest": "ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.0.0"
        },
        {
          "name": "timeline-arrows",
          "manifest": "ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.8.0"
        },
        {
          "name": "vis-data",
          "manifest": "ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "^8.0.3"
        },
        {
          "name": "vis-timeline",
          "manifest": "ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "^8.5.0"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 1,
        "open_issues": 1,
        "closed_ratio": 0.5,
        "closed_issues": 1,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "hc12r",
          "commits": 285,
          "avatar_url": "https://avatars.githubusercontent.com/u/66696838?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "dependencies.yml",
        "release.yml",
        "security.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum",
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 9,
            "reason": "binaries present in source code",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "1 out of 1 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/28 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 6,
            "reason": "project has 2 contributing companies or organizations -- score normalized to 6",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 3,
            "reason": "dependency not pinned by hash detected -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "50 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "ee0f93f72ddc44fab3a8b4b1df42aa6257f67aaf",
        "ran_at": "2026-07-25T07:28:08Z",
        "aggregate_score": 2.8,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-20T03:19:00Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-18T23:33:03Z",
      "ci_last_conclusion": "FAILURE",
      "oldest_open_issues": [
        {
          "number": 1,
          "created_at": "2026-05-09T10:58:09Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/Tnsor-Labs/brokoli",
    "host": "github.com",
    "name": "brokoli",
    "owner": "Tnsor-Labs"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 53,
      "inputs": {
        "security": 28,
        "vitality": 74,
        "community": 24,
        "governance": 49,
        "engineering": 81
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 74,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 72,
            "inputs": {
              "commits_last_year": 285,
              "human_commit_share": 1,
              "days_since_last_push": 5,
              "active_weeks_last_year": 26
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "26/52 weeks with commits",
                "points": 18,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 26
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "285 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 285
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "good",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 76,
            "inputs": {
              "releases_count": 1,
              "latest_release_tag": "v0.10.0",
              "releases_from_tags": false,
              "days_since_latest_release": 6,
              "mean_days_between_releases": null
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "1 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 6 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "cadence unknown (single release)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "release_cadence_unknown",
                    "params": {}
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 24,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 1,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "1 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 49,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 16,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "moderate",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 62,
            "inputs": {
              "merged_prs": 1,
              "open_issues": 1,
              "closed_issues": 1,
              "issue_closed_ratio": 0.5,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "50% of issues closed",
                "points": 23.4,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 50
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "1/1 decided PRs merged",
                "points": 38.2,
                "status": "met",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 1,
                      "decided": 1
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/28 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 34,
            "inputs": {
              "followers": 0,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "Tnsor-Labs",
              "public_repos": 2,
              "account_age_days": 109
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "0 followers of Tnsor-Labs",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 0,
                      "login": "Tnsor-Labs"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "2 public repos, account ~0 yr old",
                "points": 4.1,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 2
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/Tnsor-Labs/brokoli"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 6
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 6 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "18 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 18
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 81,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "4 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "1 out of 1 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "topics": [
                "data-engineering",
                "data-ops",
                "data-pipeline",
                "data-quality",
                "etl",
                "go",
                "golang",
                "open-source",
                "orchestration",
                "pipeline",
                "self-hosted",
                "single-binary",
                "sqlite",
                "visual-editor",
                "workflow"
              ],
              "has_wiki": true,
              "homepage": "https://brokoli.orkestri.site",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://brokoli.orkestri.site",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "15 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 15
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "critical",
        "name": "Security",
        "value": 28,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "critical",
            "name": "Security posture",
            "note": null,
            "notes": [],
            "value": 28,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 18,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 0,
              "scorecard_aggregate": 2.8
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "binaries present in source code",
                "points": 6.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "1 out of 1 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/28 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 3",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "50 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 60,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "100 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 100,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 59,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum",
                "package-lock.json"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "ui/tsconfig.json"
              ],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "go.mod"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "go.mod (toolchain convention, no task runner)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "toolchain_convention",
                    "params": {
                      "files": "go.mod"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "ui/tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "ui/tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 57127,
              "source_files_sampled": 185,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/185 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 185,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-25T07:28:15.590806Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/t/Tnsor-Labs/brokoli.svg",
  "full_name": "Tnsor-Labs/brokoli",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Оцінки — це сигнали, а не гарантії. Вони відображають публічно видимі практики на GitHub — це не аудит коду й не гарантія безпеки.

Відсутні дані виключаються, а ваги перенормовуються — нуль за відсутність ніколи не ставиться. Методологія версіонована й відкрита: метрики v1.13.0, схема v0.27.0 — повна методологія · вікі метрик.

Як окремий результат виглядає на тлі всього реєстру: сукупна статистикаGo.